Agent skill

Elasticsearch Logs

by automateyournetwork in automateyournetwork/netclaw

Search and analyse logs in an existing Elasticsearch cluster (8.x/9.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data.

Apache-2.0Auto-check passedBackend & APIs

Install Elasticsearch Logs

skills CLI
$ npx skills add automateyournetwork/netclaw --skill elasticsearch-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw elasticsearch-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/elasticsearch-logs .claude/skills/elasticsearch-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-logs
GitHub stars
676
Token cost
~1.5k tokens
SKILL.md length
694 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Search and analyse logs in an existing Elasticsearch cluster (8.x/9.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data.

  • Works in 2 steps: Use esql with STATS COUNT(*), or → Use search with "track_total_hits": true…
  • What errors did we see
  • SKILL.md covers The rule that matters most, Tools, Worked patterns and Empty is not the same as zero, plus 4 more sections
  • Needs ES_API_KEY and ES_PASSWORD

What it does

Elasticsearch Logs is an agent skill from automateyournetwork/netclaw. Search and analyse logs in an existing Elasticsearch cluster (8.x/9.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data. Use for "what errors did we see", "how many times did X happen", "show me logs from device Y", "which host logged the most". Read-only. Counting questions MUST go through ESQL or tracktotalhits — a bare search total silently caps at 10,000.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • What errors did we see
  • How many times did X happen
  • Show me logs from device Y
  • Which host logged the most

Example prompts

  • “what errors did we see”
  • “how many times did X happen”
  • “show me logs from device Y”
  • “/elasticsearch-logs”

Requirements

  • Docker
  • A credential in ES_API_KEY

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Use esql with STATS COUNT(*), or
  2. Use search with "track_total_hits": true in the query_body.

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ES_API_KEY
    • ES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Elasticsearch Logs loads about 1.5k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 694 words, ~1,455 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-logs/SKILL.md (or your agent's skills folder).
name
elasticsearch-logs
description
Search and analyse logs in an existing Elasticsearch cluster (8.x/9.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data. Use for "what errors did we see", "how many times did X happen", "show me logs from device Y", "which host logged the most". Read-only. Counting questions MUST go through ESQL or track_total_hits — a bare search total silently caps at 10,000.

Elasticsearch Logs

Read-only log search over an Elasticsearch cluster you already run. NetClaw installs no cluster and indexes nothing — this queries what is already there.

Server: elasticsearch-mcp (adopted, docker.elastic.co/mcp/elasticsearch, Apache-2.0, digest-pinned) · 5 tools · 1,094 tokens

The rule that matters most

A bare search total is capped at 10,000 and reads as if it were exact.

Elasticsearch stops counting at 10,000 and marks the total relation: "gte" — meaning at least. This server discards that qualifier and prints Total results: 10000. There is nothing in the response to tell you the number is a floor.

Measured against 10,075 real documents:

How you askWhat you get
search with no guardTotal results: 10000 — wrong
search with "track_total_hits": trueTotal results: 10075 — correct
esql STATS COUNT(*)10075 — correct

On a million-document index a bare search still says 10,000. The error is unbounded and invisible.

Therefore, for any question of the form "how many", "how often", "which is most", or any number a human will act on:

  1. Use esql with STATS COUNT(*), or
  2. Use search with "track_total_hits": true in the query_body.

search without that guard is for retrieving example documents only — never for counting. If you report a total that came from an unguarded search, you are reporting a number that may be arbitrarily wrong.

Tools

ToolUse it forRequired arguments
list_indiceswhat indices exist, and their document countsindex_pattern (use *)
get_mappingsfield names and types before writing a queryindex
searchretrieving matching documents (Query DSL)index, query_body
esqlcounting, aggregating, grouping, rankingquery
get_shardsshard health when results look incomplete—

Note the argument names are snake_case (query_body, index_pattern). Wrong names fail loudly with a deserialization error — they are not silently ignored.

Worked patterns

How many errors, by device — a counting question, so ESQL:

esql: FROM netclaw-syslog | WHERE severity == "error" | STATS n = COUNT(*) BY device | SORT n DESC

Show me examples of those errors — a retrieval question, so search:

search: index=netclaw-syslog
        query_body={"query":{"term":{"severity":"error"}}, "size":20, "track_total_hits":true}

What am I even working with — always start here on an unfamiliar cluster:

list_indices: index_pattern=*
get_mappings: index=<the one you picked>

Guessing field names is the most common cause of a query that returns nothing. A term query against a text field, or an aggregation on one, will not behave as expected — check the mapping first. Fields are commonly foo (analysed text) plus foo.keyword (exact); use .keyword for grouping, sorting, and exact matches.

Empty is not the same as zero

A query returning no hits means this query found nothing. It does not establish that the event did not occur. Before reporting "no errors", confirm:

  • the index actually holds data for the time range (list_indices doc counts, or an ESQL count with no filter)
  • the field names came from get_mappings, not from a guess
  • the time range matches how the data is actually timestamped

Say "no matching events in <index> for <range>" — not "no errors occurred".

Show full SKILL.md (241 more words)Show less

Boundaries — which backend answers

NetClaw has several log and metric backends. Pick by where the data lives, not by question shape:

BackendUse when
this skilllogs indexed in Elasticsearch / ELK
splunk-searchlogs in Splunk
datadog-logslogs in Datadog
gcp-cloud-loggingGoogle Cloud audit/platform logs
prometheus-monitoring / grafana-observabilitytime-series metrics, not logs
duckdb-analysisexported files on disk (CSV/Parquet/JSON), not a live store

If you do not know where the logs live, ask. Do not query every backend hoping one answers — an empty result from the wrong store is indistinguishable from an absence of events.

Read-only

All five tools read. There is no index, update, delete, or reindex verb in the manifest, so no write is reachable regardless of the credential. Prefer an Elasticsearch API key with read/view_index_metadata only — the server will happily use a superuser credential, and nothing in it needs one.

Configuration

VariableMeaning
ES_URLcluster URL as reached from inside the container — a cluster on this host is http://host.docker.internal:9200, not localhost
ES_API_KEYAPI key (preferred)
ES_USERNAME / ES_PASSWORDbasic auth alternative
ES_SSL_SKIP_VERIFYtrue to skip certificate verification (lab only)

Upstream status

This server is deprecated by Elastic and receives critical security updates only. It was adopted deliberately: its replacement, Agent Builder's MCP endpoint, is Enterprise-tier on self-managed, so the supported path is paywalled while this one is Apache-2.0, already published, and works against a free Basic cluster. The image is digest-pinned so a security-only update cannot change answers underneath you. See specs/096-elastic-logs/spec.md.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/elasticsearch-logs of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Elasticsearch Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Logs this skillautomateyournetwork/netclaw676—~1.5kAutomated safety check: PassApache-2.0
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch Authnaspectrr/deer405—~1.2kAutomated safety check: NotesMIT
Elasticsearch Authzaspectrr/deer405—~1.8kAutomated safety check: PassMIT
Elasticsearch File Ingestaspectrr/deer405—~684Automated safety check: PassMIT

Similar skills

  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Elasticsearch Logs

What does Elasticsearch Logs do?

Search and analyse logs in an existing Elasticsearch cluster (8.x/9.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data. Elasticsearch Logs is an agent skill from automateyournetwork/netclaw.x) — syslog, application logs, Zeek/Suricata exports, or any indexed event data.

When should I use Elasticsearch Logs?

Elasticsearch Logs fits situations like: what errors did we see; how many times did X happen; show me logs from device Y; which host logged the most.

How do I install Elasticsearch Logs in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill elasticsearch-logs -a claude-code`. Or copy the skill folder (workspace/skills/elasticsearch-logs in automateyournetwork/netclaw) into .claude/skills/elasticsearch-logs in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Logs in Codex?

Run `npx skills add automateyournetwork/netclaw --skill elasticsearch-logs -a codex`. Or copy the skill folder (workspace/skills/elasticsearch-logs in automateyournetwork/netclaw) into .agents/skills/elasticsearch-logs in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill elasticsearch-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-logs, .gemini/skills/elasticsearch-logs, .github/skills/elasticsearch-logs and .opencode/skills/elasticsearch-logs in your project.

What does Elasticsearch Logs need to run?

Going by SKILL.md and its folder, Elasticsearch Logs needs credentials named ES_API_KEY and ES_PASSWORD. Our summary lists: Docker; A credential in ES_API_KEY.

Does Elasticsearch Logs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Elasticsearch Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Logs use?

Elasticsearch Logs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Logs use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Elasticsearch Logs?

Skills that share tags, products or a category with Elasticsearch Logs: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), Elasticsearch Authn (aspectrr/deer, 405 stars) and Elasticsearch Authz (aspectrr/deer, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Logs?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.