Agent skill

Log Aggregation

by aspectrr in aspectrr/deer

ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.

MITAuto-check passedDevOps & Cloud

Install Log Aggregation

skills CLI
$ npx skills add aspectrr/deer --skill log-aggregation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer log-aggregation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/log-aggregation .claude/skills/log-aggregation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
log-aggregation
GitHub stars
405
Token cost
~1.4k tokens
SKILL.md length
231 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.

  • Works in 6 steps: Check health: curl… → Check unassigned shards: curl… → Get allocation explanation: curl -X POST… → …
  • Deploying ES clusters
  • SKILL.md covers When to Use, Elasticsearch, Logstash and Filebeat, plus 2 more sections
  • Calls curl

What it does

Log Aggregation is an agent skill from aspectrr/deer. ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup. Use when deploying ES clusters, building logstash pipelines, configuring beats, or debugging log aggregation issues.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Observability and Debugging. It works with Elasticsearch and Apache Kafka. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • Deploying ES clusters
  • Building logstash pipelines
  • Configuring beats
  • Debugging log aggregation issues

Example prompts

  • “/log-aggregation”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Check health: curl localhost:9200/_cluster/health?pretty
  2. Check unassigned shards: curl localhost:9200/_cat/shards?v&h=index,shard,_pri,state,node&s=state
  3. Get allocation explanation: curl -X POST localhost:9200/_cluster/allocation/explain?pretty
  4. Common causes: disk watermark exceeded, node down, replica count > data nodes
  5. Check disk: curl localhost:9200/_cat/allocation?v
  6. Check settings: curl localhost:9200/_cluster/settings?include_defaults=true&flat_settings=true

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Log Aggregation loads about 1.4k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 231 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 231 words, ~1,381 tokens.

Download SKILL.mdSave it as .claude/skills/log-aggregation/SKILL.md (or your agent's skills folder).
name
log-aggregation
description
ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup. Use when deploying ES clusters, building logstash pipelines, configuring beats, or debugging log aggregation issues.
version
1.0.0

Log Aggregation (ELK Stack)

When to Use

  • Deploying or configuring Elasticsearch clusters
  • Building Logstash pipelines (inputs, filters, outputs)
  • Configuring Filebeat/Metricbeat/Heartbeat shippers
  • Setting up Kibana dashboards and alerts
  • Debugging log flow from source to Elasticsearch
  • Diagnosing cluster health (red/yellow status)

Elasticsearch

Cluster Health
bash
# Overall cluster status
curl -s localhost:9200/_cluster/health?pretty

# Node-level stats
curl -s localhost:9200/_nodes/stats?pretty

# Shard allocation explanation (when yellow/red)
curl -s localhost:9200/_cluster/allocation/explain?pretty

# Index-level health
curl -s localhost:9200/_cat/indices?v&health=yellow
curl -s localhost:9200/_cat/indices?v&health=red
Index Management
bash
# List indices with sizes
curl -s localhost:9200/_cat/indices?v&h=index,docs.count,store.size,pri,rep

# Create index with mapping
curl -X PUT localhost:9200/my-index -H 'Content-Type: application/json' -d '
{
  "mappings": {
    "properties": {
      "@timestamp": { "type": "date" },
      "message": { "type": "text" },
      "host": { "type": "keyword" },
      "level": { "type": "keyword" }
    }
  }
}'

# Delete index
curl -X DELETE localhost:9200/my-index

# Force merge (reduce segments)
curl -X POST "localhost:9200/my-index/_forcemerge?max_num_segments=1"
Cluster Red/Yellow Diagnosis
  1. Check health: curl localhost:9200/_cluster/health?pretty
  2. Check unassigned shards: curl localhost:9200/_cat/shards?v&h=index,shard,_pri,state,node&s=state
  3. Get allocation explanation: curl -X POST localhost:9200/_cluster/allocation/explain?pretty
  4. Common causes: disk watermark exceeded, node down, replica count > data nodes
  5. Check disk: curl localhost:9200/_cat/allocation?v
  6. Check settings: curl localhost:9200/_cluster/settings?include_defaults=true&flat_settings=true

Logstash

Pipeline Configuration
ruby
# /etc/logstash/pipeline/my-pipeline.conf

input {
  kafka {
    bootstrap_servers => "kafka:9092"
    topics => ["logs"]
    group_id => "logstash-consumer"
    consumer_threads => 4
  }
}

filter {
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:msg}" }
  }
  date {
    match => ["timestamp", "ISO8601"]
    target => "@timestamp"
  }
  mutate {
    remove_field => ["timestamp"]
  }
}

output {
  elasticsearch {
    hosts => ["elasticsearch:9200"]
    index => "logs-%{+YYYY.MM.dd}"
  }
}
Debugging Pipelines
bash
# Check pipeline config syntax
/usr/share/logstash/bin/logstash --config.test_and_exit -f /etc/logstash/pipeline/my-pipeline.conf

# Watch logstash logs
journalctl -u logstash --no-pager -n 100 -f

# Check running pipelines
curl -s localhost:9600/_node/pipelines?pretty

# Logstash node stats
curl -s localhost:9600/_node/stats?pretty

# Common startup issues:
# - Config syntax errors (check with --config.test_and_exit)
# - JVM heap too low (check ES_JAVA_OPTS)
# - Pipeline worker failures (check logs for "exception")
Grok Debugging
  1. Extract sample log line from source
  2. Test pattern: /usr/share/logstash/bin/logstash -e 'filter { grok { match => { "message" => "YOUR_PATTERN" } } }'
  3. Use --config.debug to see pattern matching details
  4. Common patterns: %{IP}, %{HOSTNAME}, %{GREEDYDATA}, %{SYSLOGLINE}

Filebeat

Configuration
yaml
# /etc/filebeat/filebeat.yml
filebeat.inputs:
  - type: log
    enabled: true
    paths:
      - /var/log/*.log
      - /var/log/syslog
    fields:
      env: production
      service: myapp
    fields_under_root: true

output.elasticsearch:
  hosts: ["elasticsearch:9200"]
  index: "filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"

setup.ilm.enabled: false
setup.template.name: "filebeat"
setup.template.pattern: "filebeat-*"
Debugging
bash
# Test config
filebeat test config -c /etc/filebeat/filebeat.yml

# Test output connectivity
filebeat test output -c /etc/filebeat/filebeat.yml

# Check status
systemctl status filebeat

# View logs
journalctl -u filebeat --no-pager -n 100

# Run in foreground with debug
filebeat -e -d "*"

Kibana

Setup
bash
# Check Kibana status
curl -s localhost:5601/api/status

# Create index pattern via API
curl -X POST localhost:5601/api/saved_objects/index-pattern -H 'Content-Type: application/json' -H 'kbn-xsrf: true' -d '
{
  "attributes": {
    "title": "logs-*",
    "timeFieldName": "@timestamp"
  }
}'

Deer Sandbox Integration

When testing in a deer sandbox:

  • Use kafka_stub=true to get Redpanda at localhost:9092
  • Use es_stub=true to get Elasticsearch at localhost:9200
  • Use both for full pipeline testing
  • After configuring logstash, use verify_pipeline_output to confirm data flows through
  • Point logstash output to localhost:9200 in sandbox
  • Point logstash kafka input to localhost:9092 in sandbox
Pipeline Verification Flow
  1. Create sandbox with kafka_stub=true, es_stub=true
  2. Edit logstash config to use localhost addresses
  3. Start logstash in sandbox
  4. Produce test data: rpk topic produce <topic> --brokers localhost:9092
  5. Call verify_pipeline_output with the target index
  6. Verify documents appeared in ES

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/log-aggregation of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Log Aggregation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Log Aggregation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Log Aggregation this skillaspectrr/deer405—~1.4kAutomated safety check: PassMIT
Code Reviewaide-family/moon253—~815Automated safety check: PassNone
Motel Debugkitlangton/motel298—~2.2kAutomated safety check: PassMIT
Codex Session Debuggingweave-os/router5.6k—~4.5kAutomated safety check: WarnApache-2.0
Gcloud Usagefcakyon/claude-codex-settings1.2k—~871Automated safety check: PassApache-2.0
Dspy Debugging ObservabilityOmidZamani/dspy-skills1241 repos~2.1kAutomated safety check: WarnMIT

Similar skills

  • Code Review

    aide-family/moon

    Reviews code for correctness and potential bugs, pinpoints bug locations by file and line, and suggests concrete fixes.

    253 GitHub stars~815 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Motel Debug

    kitlangton/motel

    Debug applications with motel, a local OpenTelemetry ingest and query server.

    298 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Correlates a Codex CLI session's local transcript with a model router's production logs to explain why a reply rendered the way it did.

    5.6k GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Gcloud Usage

    fcakyon/claude-codex-settings

    This skill should be used when user asks about "GCloud logs", "Cloud Logging queries", "Google Cloud metrics", "GCP observability", "trace analysis", or "debugging production issues on GCP".

    1.2k GitHub stars~871 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dspy Debugging Observability

    OmidZamani/dspy-skills

    A skill your agent uses for debugging DSPy programs, inspecthistory, tracing LLM calls, custom callbacks, observability, monitoring, and cost tracking.

    124 GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check: warnings
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed

Questions about Log Aggregation

What does Log Aggregation do?

ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup. Log Aggregation is an agent skill from aspectrr/deer. ELK Stack deployment, Logstash pipeline building, Filebeat configuration, and Kibana dashboard setup.

When should I use Log Aggregation?

Log Aggregation fits situations like: deploying ES clusters; building logstash pipelines; configuring beats; debugging log aggregation issues.

How do I install Log Aggregation in Claude Code?

Run `npx skills add aspectrr/deer --skill log-aggregation -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/log-aggregation in aspectrr/deer) into .claude/skills/log-aggregation in your project. Claude Code loads it when a task matches its description.

How do I install Log Aggregation in Codex?

Run `npx skills add aspectrr/deer --skill log-aggregation -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/log-aggregation in aspectrr/deer) into .agents/skills/log-aggregation in your project. Codex loads it when a task matches its description.

Can I use Log Aggregation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill log-aggregation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/log-aggregation, .gemini/skills/log-aggregation, .github/skills/log-aggregation and .opencode/skills/log-aggregation in your project.

What does Log Aggregation need to run?

Going by SKILL.md and its folder, Log Aggregation needs the command-line tools its instructions call (curl).

Does Log Aggregation access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Log Aggregation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Log Aggregation use?

Log Aggregation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Log Aggregation use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Log Aggregation?

Skills that share tags, products or a category with Log Aggregation: Code Review (aide-family/moon, 253 stars), Motel Debug (kitlangton/motel, 298 stars), Codex Session Debugging (weave-os/router, 5.6k stars) and Gcloud Usage (fcakyon/claude-codex-settings, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Log Aggregation?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.