Alloy
grafana/skills
Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…
Configure Grafana Loki for log aggregation and analysis. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-logging --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops/observability/loki-logging .claude/skills/loki-logging && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .claude/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-loggingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-logging --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/devops/observability/loki-logging .agents/skills/loki-logging && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .agents/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-logging --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/devops/observability/loki-logging .cursor/skills/loki-logging && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .cursor/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BagelHole/DevOps-Security-Agent-Skills.git --path devops/observability/loki-logging--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-logging --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/devops/observability/loki-logging .gemini/skills/loki-logging && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .gemini/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-loggingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/devops/observability/loki-logging .github/skills/loki-logging && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .github/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills loki-logging --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/devops/observability/loki-logging .opencode/skills/loki-logging && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "loki-logging" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/devops/observability/loki-logging into .opencode/skills/loki-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loki-logging", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
loki-loggingConfigure Grafana Loki for log aggregation and analysis. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
Loki Logging is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Configure Grafana Loki for log aggregation and analysis. Set up Promtail for log collection, write LogQL queries, and integrate with Grafana for visualization. Use when implementing lightweight log aggregation, especially in Kubernetes environments.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Observability, Monitoring and alerting and Container orchestration. It works with Grafana and Kubernetes. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.
Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
helmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
grafana.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Loki Logging loads about 2.4k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 217 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 217 words, ~2,416 tokens.
.claude/skills/loki-logging/SKILL.md (or your agent's skills folder).Aggregate and query logs with Grafana Loki, the Prometheus-inspired logging system.
Use this skill when:
┌─────────────┐ ┌──────────┐ ┌──────────┐
│ Application │────▶│ Promtail │────▶│ Loki │
└─────────────┘ └──────────┘ └──────────┘
│
▼
┌──────────┐
│ Grafana │
└──────────┘# docker-compose.yml
version: '3.8'
services:
loki:
image: grafana/loki:2.9.0
ports:
- "3100:3100"
volumes:
- ./loki-config.yaml:/etc/loki/local-config.yaml
- loki-data:/loki
command: -config.file=/etc/loki/local-config.yaml
promtail:
image: grafana/promtail:2.9.0
volumes:
- ./promtail-config.yaml:/etc/promtail/config.yaml
- /var/log:/var/log:ro
- /var/lib/docker/containers:/var/lib/docker/containers:ro
command: -config.file=/etc/promtail/config.yaml
grafana:
image: grafana/grafana:10.2.0
ports:
- "3000:3000"
volumes:
- grafana-data:/var/lib/grafana
- ./grafana/provisioning:/etc/grafana/provisioning
environment:
- GF_AUTH_ANONYMOUS_ENABLED=true
- GF_AUTH_ANONYMOUS_ORG_ROLE=Admin
volumes:
loki-data:
grafana-data:# loki-config.yaml
auth_enabled: false
server:
http_listen_port: 3100
common:
path_prefix: /loki
storage:
filesystem:
chunks_directory: /loki/chunks
rules_directory: /loki/rules
replication_factor: 1
ring:
kvstore:
store: inmemory
schema_config:
configs:
- from: 2020-10-24
store: boltdb-shipper
object_store: filesystem
schema: v11
index:
prefix: index_
period: 24h
storage_config:
boltdb_shipper:
active_index_directory: /loki/index
cache_location: /loki/cache
shared_store: filesystem
limits_config:
reject_old_samples: true
reject_old_samples_max_age: 168h
max_query_series: 5000
max_query_parallelism: 2
chunk_store_config:
max_look_back_period: 168h
table_manager:
retention_deletes_enabled: true
retention_period: 168h# promtail-config.yaml
server:
http_listen_port: 9080
grpc_listen_port: 0
positions:
filename: /tmp/positions.yaml
clients:
- url: http://loki:3100/loki/api/v1/push
scrape_configs:
# System logs
- job_name: system
static_configs:
- targets:
- localhost
labels:
job: varlogs
__path__: /var/log/*.log
# Docker container logs
- job_name: docker
docker_sd_configs:
- host: unix:///var/run/docker.sock
refresh_interval: 5s
relabel_configs:
- source_labels: ['__meta_docker_container_name']
regex: '/(.*)'
target_label: 'container'
- source_labels: ['__meta_docker_container_log_stream']
target_label: 'stream'
# Application logs with parsing
- job_name: application
static_configs:
- targets:
- localhost
labels:
job: application
__path__: /var/log/app/*.log
pipeline_stages:
- json:
expressions:
level: level
message: message
timestamp: timestamp
- labels:
level:
- timestamp:
source: timestamp
format: RFC3339# Using Helm
helm repo add grafana https://grafana.github.io/helm-charts
helm install loki grafana/loki-stack \
--namespace monitoring \
--create-namespace \
--set grafana.enabled=true \
--set promtail.enabled=trueapiVersion: apps/v1
kind: DaemonSet
metadata:
name: promtail
namespace: monitoring
spec:
selector:
matchLabels:
app: promtail
template:
metadata:
labels:
app: promtail
spec:
containers:
- name: promtail
image: grafana/promtail:2.9.0
args:
- -config.file=/etc/promtail/promtail.yaml
volumeMounts:
- name: config
mountPath: /etc/promtail
- name: varlog
mountPath: /var/log
- name: varlibdockercontainers
mountPath: /var/lib/docker/containers
readOnly: true
volumes:
- name: config
configMap:
name: promtail-config
- name: varlog
hostPath:
path: /var/log
- name: varlibdockercontainers
hostPath:
path: /var/lib/docker/containers# All logs from a job
{job="application"}
# Filter by label
{job="application", level="error"}
# Multiple labels
{namespace="production", container="api"}
# Regex match
{job=~"app.*"}# Filter by content
{job="application"} |= "error"
# Exclude content
{job="application"} != "debug"
# Regex filter
{job="application"} |~ "user_id=[0-9]+"
# JSON parsing
{job="application"} | json | level="error"
# Line format
{job="application"} | json | line_format "{{.level}}: {{.message}}"# Count logs per second
count_over_time({job="application"}[5m])
# Rate of errors
rate({job="application", level="error"}[5m])
# Sum by label
sum by (level) (count_over_time({job="application"}[5m]))
# Top services by error count
topk(5, sum by (service) (count_over_time({level="error"}[1h])))# Average log line length
avg_over_time({job="application"} | unwrap line_length [5m])
# Percentile of numeric field
quantile_over_time(0.95, {job="application"} | json | unwrap response_time [5m])
# Error percentage
sum(rate({job="application", level="error"}[5m]))
/
sum(rate({job="application"}[5m])) * 100# promtail-config.yaml
pipeline_stages:
# Parse JSON logs
- json:
expressions:
level: level
message: msg
trace_id: trace_id
# Extract with regex
- regex:
expression: 'user_id=(?P<user_id>\d+)'
# Add labels from parsed fields
- labels:
level:
user_id:
# Modify timestamp
- timestamp:
source: timestamp
format: '2006-01-02T15:04:05.000Z'
# Filter logs
- match:
selector: '{level="debug"}'
action: drop
# Add static labels
- static_labels:
environment: production
# Modify log line
- template:
source: message
template: '{{ ToUpper .Value }}'# grafana/provisioning/datasources/loki.yaml
apiVersion: 1
datasources:
- name: Loki
type: loki
access: proxy
url: http://loki:3100
isDefault: false
jsonData:
maxLines: 1000{
"title": "Application Logs",
"type": "logs",
"datasource": "Loki",
"targets": [
{
"expr": "{job=\"application\"} | json",
"refId": "A"
}
],
"options": {
"showTime": true,
"showLabels": true,
"wrapLogMessage": true
}
}# loki-rules.yaml
groups:
- name: error_rates
interval: 1m
rules:
- record: job:log_errors:rate5m
expr: |
sum by (job) (rate({level="error"}[5m]))# loki-alerts.yaml
groups:
- name: log_alerts
rules:
- alert: HighErrorRate
expr: |
sum(rate({level="error"}[5m])) > 10
for: 5m
labels:
severity: critical
annotations:
summary: "High error rate in logs"
description: "Error rate is {{ $value }} errors/second"Problem: Loki consuming too much memory Solution: Reduce max_query_series, limit query time range
Problem: Promtail not shipping logs Solution: Check positions file, verify file paths, check label configuration
Problem: LogQL queries timing out Solution: Add more specific label filters, reduce time range
Problem: Logs being dropped Solution: Increase per_stream_rate_limit in limits_config
© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in devops/observability/loki-logging of BagelHole/DevOps-Security-Agent-Skills.
Open the folder on GitHubat commit 0365f57
Loki Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Loki Logging this skillBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Alloygrafana/skills | 281 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Opentelemetrygrafana/skills | 281 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Grafana Dashboardpando85/kaniop | 131 | — | ~987 | Automated safety check: Pass | AGPL-3.0 | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Implementing Runtime Security With Tetragonmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.1k | Automated safety check: Notes | Apache-2.0 |
grafana/skills
Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…
grafana/skills
Instrument any app with OpenTelemetry and ship metrics / logs / traces to Grafana Cloud or self-hosted Mimir / Loki / Tempo / Pyroscope.
pando85/kaniop
Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
mukul975/Anthropic-Cybersecurity-Skills
Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking…
sickn33/agentic-awesome-skills
Configure Grafana Loki for log aggregation and analysis. An agent skill from sickn33/agentic-awesome-skills.
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Set up metrics collection and visualization with Prometheus and Grafana.
BagelHole/DevOps-Security-Agent-Skills
Scan systems and dependencies for CVEs and security vulnerabilities.
Works with
Categories
Configure Grafana Loki for log aggregation and analysis. An agent skill from BagelHole/DevOps-Security-Agent-Skills. Loki Logging is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Configure Grafana Loki for log aggregation and analysis.
Loki Logging fits situations like: implementing lightweight log aggregation; especially in Kubernetes environments.
Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a claude-code`. Or copy the skill folder (devops/observability/loki-logging in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/loki-logging in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a codex`. Or copy the skill folder (devops/observability/loki-logging in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/loki-logging in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill loki-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/loki-logging, .gemini/skills/loki-logging, .github/skills/loki-logging and .opencode/skills/loki-logging in your project.
Going by SKILL.md and its folder, Loki Logging needs the command-line tools its instructions call (helm). Our summary lists: Docker.
SKILL.md names 1 domain. In commands or code: grafana.github.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Loki Logging is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Loki Logging: Alloy (grafana/skills, 281 stars), Opentelemetry (grafana/skills, 281 stars), Grafana Dashboard (pando85/kaniop, 131 stars) and Cloud Devops (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,148 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.
Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.