Code Review
aide-family/moon
Reviews code for correctness and potential bugs, pinpoints bug locations by file and line, and suggests concrete fixes.
ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.
$ npx skills add aspectrr/deer --skill log-aggregation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aspectrr/deer log-aggregation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .claude/skills/log-aggregation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .claude/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aspectrr/deer --skill log-aggregation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aspectrr/deer log-aggregation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .agents/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .agents/skills/log-aggregation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .agents/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aspectrr/deer --skill log-aggregation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aspectrr/deer log-aggregation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .cursor/skills/log-aggregation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .cursor/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aspectrr/deer.git --path deer-cli/internal/skill/defaults/log-aggregation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aspectrr/deer --skill log-aggregation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aspectrr/deer log-aggregation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .gemini/skills/log-aggregation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .gemini/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aspectrr/deer log-aggregationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aspectrr/deer --skill log-aggregation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .github/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .github/skills/log-aggregation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .github/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aspectrr/deer --skill log-aggregation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aspectrr/deer log-aggregation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .opencode/skills/log-aggregation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "log-aggregation" agent skill from https://github.com/aspectrr/deer/tree/main/deer-cli/internal/skill/defaults/log-aggregation into .opencode/skills/log-aggregation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "log-aggregation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
log-aggregationELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.
Log Aggregation is an agent skill from aspectrr/deer. ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup. Use when deploying ES clusters, building logstash pipelines, configuring beats, or debugging log aggregation issues.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Observability and Debugging. It works with Elasticsearch and Apache Kafka. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Log Aggregation loads about 1.4k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 231 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 231 words, ~1,381 tokens.
.claude/skills/log-aggregation/SKILL.md (or your agent's skills folder).# Overall cluster status
curl -s localhost:9200/_cluster/health?pretty
# Node-level stats
curl -s localhost:9200/_nodes/stats?pretty
# Shard allocation explanation (when yellow/red)
curl -s localhost:9200/_cluster/allocation/explain?pretty
# Index-level health
curl -s localhost:9200/_cat/indices?v&health=yellow
curl -s localhost:9200/_cat/indices?v&health=red# List indices with sizes
curl -s localhost:9200/_cat/indices?v&h=index,docs.count,store.size,pri,rep
# Create index with mapping
curl -X PUT localhost:9200/my-index -H 'Content-Type: application/json' -d '
{
"mappings": {
"properties": {
"@timestamp": { "type": "date" },
"message": { "type": "text" },
"host": { "type": "keyword" },
"level": { "type": "keyword" }
}
}
}'
# Delete index
curl -X DELETE localhost:9200/my-index
# Force merge (reduce segments)
curl -X POST "localhost:9200/my-index/_forcemerge?max_num_segments=1"curl localhost:9200/_cluster/health?prettycurl localhost:9200/_cat/shards?v&h=index,shard,_pri,state,node&s=statecurl -X POST localhost:9200/_cluster/allocation/explain?prettycurl localhost:9200/_cat/allocation?vcurl localhost:9200/_cluster/settings?include_defaults=true&flat_settings=true# /etc/logstash/pipeline/my-pipeline.conf
input {
kafka {
bootstrap_servers => "kafka:9092"
topics => ["logs"]
group_id => "logstash-consumer"
consumer_threads => 4
}
}
filter {
grok {
match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:msg}" }
}
date {
match => ["timestamp", "ISO8601"]
target => "@timestamp"
}
mutate {
remove_field => ["timestamp"]
}
}
output {
elasticsearch {
hosts => ["elasticsearch:9200"]
index => "logs-%{+YYYY.MM.dd}"
}
}# Check pipeline config syntax
/usr/share/logstash/bin/logstash --config.test_and_exit -f /etc/logstash/pipeline/my-pipeline.conf
# Watch logstash logs
journalctl -u logstash --no-pager -n 100 -f
# Check running pipelines
curl -s localhost:9600/_node/pipelines?pretty
# Logstash node stats
curl -s localhost:9600/_node/stats?pretty
# Common startup issues:
# - Config syntax errors (check with --config.test_and_exit)
# - JVM heap too low (check ES_JAVA_OPTS)
# - Pipeline worker failures (check logs for "exception")/usr/share/logstash/bin/logstash -e 'filter { grok { match => { "message" => "YOUR_PATTERN" } } }'--config.debug to see pattern matching details%{IP}, %{HOSTNAME}, %{GREEDYDATA}, %{SYSLOGLINE}# /etc/filebeat/filebeat.yml
filebeat.inputs:
- type: log
enabled: true
paths:
- /var/log/*.log
- /var/log/syslog
fields:
env: production
service: myapp
fields_under_root: true
output.elasticsearch:
hosts: ["elasticsearch:9200"]
index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"
setup.ilm.enabled: false
setup.template.name: "filebeat"
setup.template.pattern: "filebeat-*"# Test config
filebeat test config -c /etc/filebeat/filebeat.yml
# Test output connectivity
filebeat test output -c /etc/filebeat/filebeat.yml
# Check status
systemctl status filebeat
# View logs
journalctl -u filebeat --no-pager -n 100
# Run in foreground with debug
filebeat -e -d "*"# Check Kibana status
curl -s localhost:5601/api/status
# Create index pattern via API
curl -X POST localhost:5601/api/saved_objects/index-pattern -H 'Content-Type: application/json' -H 'kbn-xsrf: true' -d '
{
"attributes": {
"title": "logs-*",
"timeFieldName": "@timestamp"
}
}'When testing in a deer sandbox:
kafka_stub=true to get Redpanda at localhost:9092es_stub=true to get Elasticsearch at localhost:9200verify_pipeline_output to confirm data flows throughlocalhost:9200 in sandboxlocalhost:9092 in sandboxkafka_stub=true, es_stub=truerpk topic produce <topic> --brokers localhost:9092verify_pipeline_output with the target index© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in deer-cli/internal/skill/defaults/log-aggregation of aspectrr/deer.
Open the folder on GitHubat commit e4f9845
Log Aggregation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Log Aggregation this skillaspectrr/deer | 405 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Code Reviewaide-family/moon | 253 | — | ~815 | Automated safety check: Pass | None | |
| Motel Debugkitlangton/motel | 298 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Codex Session Debuggingweave-os/router | 5.6k | — | ~4.5k | Automated safety check: Warn | Apache-2.0 | |
| Gcloud Usagefcakyon/claude-codex-settings | 1.2k | — | ~871 | Automated safety check: Pass | Apache-2.0 | |
| Dspy Debugging ObservabilityOmidZamani/dspy-skills | 124 | 1 repos | ~2.1k | Automated safety check: Warn | MIT |
aide-family/moon
Reviews code for correctness and potential bugs, pinpoints bug locations by file and line, and suggests concrete fixes.
kitlangton/motel
Debug applications with motel, a local OpenTelemetry ingest and query server.
weave-os/router
Correlates a Codex CLI session's local transcript with a model router's production logs to explain why a reply rendered the way it did.
fcakyon/claude-codex-settings
This skill should be used when user asks about "GCloud logs", "Cloud Logging queries", "Google Cloud metrics", "GCP observability", "trace analysis", or "debugging production issues on GCP".
OmidZamani/dspy-skills
A skill your agent uses for debugging DSPy programs, inspecthistory, tracing LLM calls, custom callbacks, observability, monitoring, and cost tracking.
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
aspectrr/deer
Enable, configure, and query Elasticsearch security audit logs.
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
aspectrr/deer
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.
aspectrr/deer
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
aspectrr/deer
Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.
aspectrr/deer
Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.
Works with
Categories
ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup. Log Aggregation is an agent skill from aspectrr/deer. ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.
Log Aggregation fits situations like: deploying ES clusters; building logstash pipelines; configuring beats; debugging log aggregation issues.
Run `npx skills add aspectrr/deer --skill log-aggregation -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/log-aggregation in aspectrr/deer) into .claude/skills/log-aggregation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aspectrr/deer --skill log-aggregation -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/log-aggregation in aspectrr/deer) into .agents/skills/log-aggregation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill log-aggregation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/log-aggregation, .gemini/skills/log-aggregation, .github/skills/log-aggregation and .opencode/skills/log-aggregation in your project.
Going by SKILL.md and its folder, Log Aggregation needs the command-line tools its instructions call (curl).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Log Aggregation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Log Aggregation: Code Review (aide-family/moon, 253 stars), Motel Debug (kitlangton/motel, 298 stars), Codex Session Debugging (weave-os/router, 5.6k stars) and Gcloud Usage (fcakyon/claude-codex-settings, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.
Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.