Agent skill

Log Analysis

by 312362115 in 312362115/claude

日志分析技能:从日志中快速定位异常、统计错误分布、提取关键时间线. An agent skill from 312362115/claude.

MITAuto-check passed

Install Log Analysis

skills CLI
$ npx skills add 312362115/claude --skill log-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 312362115/claude log-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/log-analysis .claude/skills/log-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
log-analysis
GitHub stars
107
Token cost
~779 tokens
SKILL.md length
116 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

日志分析技能:从日志中快速定位异常、统计错误分布、提取关键时间线. An agent skill from 312362115/claude.

  • Works in 3 steps: 从结果倒推:用户看到的问题 → 直接原因 → 根本原因 → 时间相关性:问题开始时间前后,有没有部署/配置变更/流量突增? → 5 Whys:连续追问"为什么"直到找到根因
  • SKILL.md covers 分析流程, 第一步:识别日志格式, 第二步:定位异常 and 第三步:构建时间线, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Log Analysis is an agent skill from 312362115/claude. 日志分析技能:从日志中快速定位异常、统计错误分布、提取关键时间线。 支持各种日志格式(JSON、纯文本、结构化、非结构化)。 触发词:帮我看看日志、这段日志什么意思、找找报错、日志分析、error log。 触发场景:线上问题排查、错误日志分析、用户反馈复现、性能问题排查。 即使用户没有说"日志分析",只要给了一段日志让你看,都应触发此技能。

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The licence is MIT.

Example prompts

  • “/log-analysis”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 从结果倒推:用户看到的问题 → 直接原因 → 根本原因
  2. 时间相关性:问题开始时间前后,有没有部署/配置变更/流量突增?
  3. 5 Whys:连续追问"为什么"直到找到根因

What it can do on your machine

Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Log Analysis loads about 779 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 116 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~779

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 116 words, ~779 tokens.

Download SKILL.mdSave it as .claude/skills/log-analysis/SKILL.md (or your agent's skills folder).
name
log-analysis
description
日志分析技能:从日志中快速定位异常、统计错误分布、提取关键时间线。 支持各种日志格式(JSON、纯文本、结构化、非结构化)。 触发词:帮我看看日志、这段日志什么意思、找找报错、日志分析、error log。 触发场景:线上问题排查、错误日志分析、用户反馈复现、性能问题排查。 即使用户没有说"日志分析",只要给了一段日志让你看,都应触发此技能。
version
1.0.0
last_updated
2026-04-08
repository
https://github.com/312362115/claude

日志分析(Log Analysis)

日志是系统说的话。大部分时候它在说废话,但出问题时,答案就藏在那些废话里。


分析流程

拿到日志
  │
  ├─ 1. 识别日志格式和结构
  ├─ 2. 定位异常和错误
  ├─ 3. 构建时间线
  ├─ 4. 分析根因
  └─ 5. 给出结论和建议

第一步:识别日志格式

格式特征处理方式
JSON 结构化每行一个 JSON 对象解析 JSON,按字段筛选
标准日志格式[时间] [级别] [模块] 消息正则提取字段
纯文本无固定格式按关键词和时间戳模式匹配
堆栈跟踪Error + at file:line识别错误类型和调用栈

如果日志太长(>500 行),先问用户:

  • 大概什么时间段出的问题?
  • 有没有相关的错误关键词?
  • 受影响的用户/请求 ID?

第二步:定位异常

2.1 错误级别扫描

按优先级从高到低扫描:

FATAL / CRITICAL → ERROR → WARN → 异常模式(超时、重试、拒绝)
2.2 关键模式识别
模式关键词可能的问题
异常/错误Error, Exception, FATAL, panic代码错误
超时timeout, ETIMEDOUT, deadline exceeded网络/依赖慢
连接失败ECONNREFUSED, connection reset, ECONNRESET服务不可达
资源耗尽OOM, too many open files, pool exhausted资源泄漏
权限问题403, permission denied, unauthorized权限配置
数据问题null, undefined, NaN, invalid数据质量
重试/降级retry, fallback, circuit breaker依赖不稳定
2.3 统计错误分布
markdown
## 错误统计

| 错误类型 | 次数 | 首次出现 | 最后出现 |
|---------|------|---------|---------|
| ConnectionTimeout | 45 | 14:23:01 | 14:28:33 |
| NullPointerError | 3 | 14:25:12 | 14:25:14 |
| AuthTokenExpired | 12 | 14:20:00 | 14:30:00 |

第三步:构建时间线

将关键事件按时间排列,还原问题发生经过:

markdown
## 事件时间线

14:20:00  [正常] 服务启动,连接数据库成功
14:23:01  [异常] 首次出现 ConnectionTimeout,目标:redis:6379
14:23:15  [异常] ConnectionTimeout 频率上升,10s 内 15 次
14:24:00  [告警] Redis 连接池耗尽,开始排队
14:25:12  [错误] NullPointerError — getUserSession() 返回 null
          ↑ 因为 Redis 不可用,session 查询失败
14:25:30  [降级] 熔断器触发,Redis 请求直接返回 fallback
14:28:33  [恢复] Redis 连接恢复,ConnectionTimeout 消失
14:30:00  [正常] 错误率归零

第四步:分析根因

分析方法
  1. 从结果倒推:用户看到的问题 → 直接原因 → 根本原因
  2. 时间相关性:问题开始时间前后,有没有部署/配置变更/流量突增?
  3. 5 Whys:连续追问"为什么"直到找到根因
输出格式
markdown
## 根因分析

### 现象
用户登录页报 500 错误

### 直接原因
getUserSession() 返回 null,后续代码未做空值处理导致 NullPointerError

### 根本原因
Redis 实例在 14:23 出现网络抖动(可能是运维变更),
导致连接超时 → 连接池耗尽 → session 查询失败 → 空值未处理 → 500

### 因果链
Redis 网络抖动 → 连接超时 → 连接池耗尽 → session 查询失败
→ 返回 null → 未做空值检查 → NullPointerError → 500 响应

第五步:结论和建议

markdown
## 结论

1. **根因**:Redis 网络抖动导致连接超时,session 查询失败
2. **影响面**:14:23-14:28 期间约 200 个请求受影响
3. **恢复方式**:Redis 连接自动恢复后问题消失

## 建议

### 短期(立即修复)
- getUserSession() 增加空值检查,返回 null 时走降级逻辑而非抛异常

### 中期(防止复发)
- Redis 连接池增加健康检查和自动重连机制
- 添加 Redis 连接状态监控告警

### 长期(提升韧性)
- session 查询增加本地缓存兜底
- 考虑 Redis Sentinel 或 Cluster 提高可用性

分析准则

  • 先全局后细节:先扫一遍日志全貌(错误分布、时间范围),再深入具体错误
  • 关注时间相关性:问题前后有什么变化?部署?配置?流量?
  • 区分因果和巧合:两个事件时间接近不代表有因果关系
  • 不猜测:日志里没有的信息就说"需要进一步确认",不编原因
  • 给可执行建议:不只是"加个日志",而是"在 src/services/auth.ts:45 的 getUserSession() 返回值后加空值检查"

© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/log-analysis of 312362115/claude.

Open the folder on GitHubat commit 2d4fa49

Compare with similar skills

Log Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Log Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Log Analysis this skill312362115/claude107—~779Automated safety check: PassMIT
Growth Logaffaan-m/ECC275k1 repos~1.7kAutomated safety check: PassMIT
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Investigating LogsPostHog/posthog40k—~2.1kAutomated safety check: PassCustom licence
Logging and Error Reporting for Warpwarpdotdev/warp65k1 repos~5.6kAutomated safety check: PassAGPL-3.0
Analyze Logsactivepieces/activepieces25k1 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Growth Log

    affaan-m/ECC

    Write growth log entries that extract reusable patterns from completed work — root cause, transferable rule, and a recognizable signal — instead of diary-style event narration, with a 4-8 sentence…

    275k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed
  • Investigating Logs

    PostHog/posthog

    Official

    Investigate logs in a PostHog project: verify a service or deployment is healthy, explain an error spike, triage an incident, or understand what a log stream is saying.

    40k GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed
  • Guides log level choices and when to raise a structured Sentry event instead of a plain log line in the Warp Rust codebase, keeping secrets out of logs.

    65k GitHub starsUsed in 1 repo~5.6k tokens
    DevelopmentAuto-check passed
  • Analyze Logs

    activepieces/activepieces

    Analyze application logs from the .evlog/logs/ directory. An agent skill from activepieces/activepieces.

    25k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • KubeSphere WizTelemetry Logging

    kubesphere/kubesphere

    Installs and configures WizTelemetry Logging for KubeSphere, with container log and optional disk log collection, dependency checks and the log query API.

    17k GitHub stars~2.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from 312362115/claude

All 20 skills in this repo
  • Diagram

    312362115/claude

    专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.

    107 GitHub stars~2.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Deep Research

    312362115/claude

    深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.

    107 GitHub stars~6.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Preview Md

    312362115/claude

    MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.

    107 GitHub stars~636 tokensUpdated 4 mo ago
    Auto-check passed
  • Writing

    312362115/claude

    通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.

    107 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Code Walkthrough

    312362115/claude

    代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.

    107 GitHub stars~1k tokensUpdated 4 mo ago
    Auto-check: notes
  • DB Review

    312362115/claude

    数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.

    107 GitHub stars~1.8k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Log Analysis

What does Log Analysis do?

日志分析技能:从日志中快速定位异常、统计错误分布、提取关键时间线. An agent skill from 312362115/claude. Log Analysis is an agent skill from 312362115/claude.

How do I install Log Analysis in Claude Code?

Run `npx skills add 312362115/claude --skill log-analysis -a claude-code`. Or copy the skill folder (skills/log-analysis in 312362115/claude) into .claude/skills/log-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Log Analysis in Codex?

Run `npx skills add 312362115/claude --skill log-analysis -a codex`. Or copy the skill folder (skills/log-analysis in 312362115/claude) into .agents/skills/log-analysis in your project. Codex loads it when a task matches its description.

Can I use Log Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill log-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/log-analysis, .gemini/skills/log-analysis, .github/skills/log-analysis and .opencode/skills/log-analysis in your project.

What does Log Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Log Analysis is instructions for the agent only.

Does Log Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Log Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Log Analysis use?

Log Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Log Analysis use?

About 779 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Log Analysis?

Skills that share tags, products or a category with Log Analysis: Growth Log (affaan-m/ECC, 275k stars), Clickhouse Logs Queries (supabase/supabase, 111k stars), Investigating Logs (PostHog/posthog, 40k stars) and Logging and Error Reporting for Warp (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Log Analysis?

312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.

Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.