Skip to content
Back to skills

Query Cloudwatch Logs

ASecurity

Execute a CloudWatch Logs Insights query against log groups returned by discover_log_groups within an investigation window. Validates group existence, skips missing ones, returns structured findings.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
devops

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Perun-Engineering/sre-on-call --skill query_cloudwatch_logs --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Query Cloudwatch Logs?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Query Cloudwatch Logs
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/perun-engineering-query-cloudwatch-logs/badge)](https://www.skillsdirectory.com/skills/perun-engineering-query-cloudwatch-logs)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: query_cloudwatch_logs
description: Execute a CloudWatch Logs Insights query against log groups returned by discover_log_groups within an investigation window. Validates group existence, skips missing ones, returns structured findings.
tool: agents.cloudwatch_logs.tools:query_cloudwatch_logs
---
# When to use

Run **after** `discover_log_groups` — query only the real log group names it returned; never guess names here. Run an initial query, then if the results look suspicious — an error spike, an unexpected pattern, a gap — drill in with a focused follow-up call (a tighter window around the spike, an added filter, or a `stats … by bin()` to quantify it) rather than reporting the first pass as-is. When the first pass is ambiguous, gather don't guess: run a discriminating follow-up — re-query the most recent window or `stats count(*) by bin(...)` — to confirm whether the condition is still firing now versus already resolved, instead of reporting a stale first pass. Stop once you can explain the alert or your budget is spent.

# Inputs

- `log_group_names` (required): list of log groups to query. Non-existent groups are skipped, not failures.
- `query` (required): a CloudWatch Logs Insights query string. Common patterns:
  - `fields @timestamp, @message | filter @message like /ERROR/`
  - `fields @timestamp, @message | sort @timestamp desc | limit 50`
  - `stats count(*) by bin(5m) as period`
- `start_time`, `end_time` (required): ISO-8601 boundaries of the investigation window.

# Output

For each existing log group: matched events. The agent should highlight error patterns, spikes, and correlations across groups.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…