Agent skill

Cx Telemetry Querying

by coralogix in coralogix/cx-cli

A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…

Apache-2.0Auto-check passedDevOps & Cloud

Install Cx Telemetry Querying

skills CLI
$ npx skills add coralogix/cx-cli --skill cx-telemetry-querying -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coralogix/cx-cli cx-telemetry-querying --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coralogix/cx-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cx-telemetry-querying .claude/skills/cx-telemetry-querying && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cx-telemetry-querying
GitHub stars
121
Token cost
~2.6k tokens
SKILL.md length
1,170 words
Files
8 (incl. references)
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…

  • Works in 4 steps: Search Metrics → Search Log and Span Fields → Search the Codebase → …
  • Any question involving telemetry data: investigate an issue
  • SKILL.md covers Loading References, Safety, Quick Routing Guide and Discovery Workflow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cx Telemetry Querying is an agent skill from coralogix/cx-cli. Use this skill for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior", "understand a production incident", "query telemetry data", "look at logs", "search logs", "find errors", "find stack traces", "filter by severity", "check traces", "examine spans", "investigate request latency", "debug service-to-service calls", "look up a trace ID", "analyze RUM data", "query rum.events", "check frontend…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/dataprime-reference.md`, `references/logs-querying.md` and `references/metrics-querying.md`).

It sits in DevOps & Cloud, covering Observability, Debugging and Web performance. It works with Prometheus and JavaScript. The repository describes itself as: This is the Coralogix CLI. The licence is Apache-2.0.

When your agent uses it

  • Any question involving telemetry data: investigate an issue
  • Debug a problem
  • Find out why something is slow
  • Check error rates

Example prompts

  • “investigate an issue”
  • “debug a problem”
  • “find out why something is slow”
  • “/cx-telemetry-querying”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Search Metrics
  2. Search Log and Span Fields
  3. Search the Codebase
  4. Choose and Query

What it can do on your machine

Read from SKILL.md and the folder at commit c071372. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cx Telemetry Querying loads about 2.6k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 219 tokens; SKILL.md has 1,170 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~219
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coralogix/cx-cli at commit c071372, republished under its Apache-2.0 licence (© coralogix). 1,170 words, ~2,650 tokens.

Download SKILL.mdSave it as .claude/skills/cx-telemetry-querying/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
cx-telemetry-querying
description
Use this skill for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior", "understand a production incident", "query telemetry data", "look at logs", "search logs", "find errors", "find stack traces", "filter by severity", "check traces", "examine spans", "investigate request latency", "debug service-to-service calls", "look up a trace ID", "analyze RUM data", "query rum.events", "check frontend performance", "frontend errors", "Core Web Vitals", "JavaScript exceptions", "query metrics", "check CPU usage", "run a PromQL query", "check error rate", "look up a metric", "check memory usage", "how do I write a DataPrime query", "DataPrime syntax", or wants to answer questions using observability data from logs, metrics, traces, RUM, or APM.
metadata.version
0.2.1

Telemetry Querying Skill

Use this skill as the entry point for any investigation, debugging, or data question that may be answered from telemetry data. It helps you decide where the relevant signal lives (metrics, logs, traces, RUM) and tells you which reference files to load before querying.

Loading References

Before querying, load the reference files for the chosen pillar:

PillarLoad these files
Logsreferences/dataprime-reference.md + references/logs-querying.md
Spans / Tracesreferences/dataprime-reference.md + references/spans-querying.md
Metricsreferences/promql-guidelines.md + references/metrics-querying.md
RUM (frontend)references/dataprime-reference.md + references/rum-querying.md + references/rum-fields.md
DataPrime syntax onlyreferences/dataprime-reference.md

Safety

All query commands (cx logs, cx spans, cx metrics, cx dataprime, cx search-fields) are read-only and work in --read-only mode. They never modify data and can be run freely without --yes.


Quick Routing Guide

Use this table for obvious cases where one pillar is the clear first choice:

Question TypeFirst ChoiceFallback
UI behavior, page load, frontend errorsRUMTraces (if backend-related)
Endpoint latency, throughput, error ratesMetricsTraces (for per-request detail)
Service-to-service dependencies, request flowTracesLogs (for debug output)
Specific error messages, stack tracesLogsTraces (for request context)
Infrastructure health (CPU, memory, disk)Metrics-
Business events (purchases, signups)Depends - see Discovery Workflow-

For ambiguous questions (e.g., "How much money did users spend last week?"), the signal could live in any pillar. Follow the Discovery Workflow below.


Discovery Workflow

When the answer could reside in multiple pillars, run discovery in parallel to find the best source.

Step 1: Search Metrics

Check if a relevant metric exists:

bash
cx metrics search --name '*transaction*'
cx metrics search --name '*payment*'
cx metrics search --name '*revenue*'
cx metrics search --description "total purchase amount"

If a matching metric is found, load references/promql-guidelines.md + references/metrics-querying.md and continue.

Step 2: Search Log and Span Fields

Use semantic field search to find relevant DataPrime paths:

bash
cx search-fields "transaction amount" --dataset logs
cx search-fields "payment total" --dataset spans
cx search-fields "purchase value" --dataset logs --limit 10

If you know a concrete value that should appear in the data but don't know which field holds it, use value search instead. It returns the matching field keys alongside sample values, which also lets you infer the field's type (string, numeric, enum, etc.):

bash
cx search-fields "payment_failed" -s value --dataset logs
cx search-fields "grpc.status.UNAVAILABLE" -s value --dataset spans
cx search-fields "eu-west-1" -s value --dataset all

Requirements: cx search-fields needs a Coralogix API key or OAuth on the active profile. If credentials are missing, prompt the user to run cx profiles add <name>.

If matching fields are found:

  • For logs: load references/dataprime-reference.md + references/logs-querying.md
  • For spans: load references/dataprime-reference.md + references/spans-querying.md
Step 3: Search the Codebase

When discovery results are ambiguous or you need to validate what a metric/field actually represents, search the codebase:

  • Look for metric registration code (e.g., prometheus.NewCounter, metrics.record)
  • Look for log statements that emit the field (e.g., logger.info("transaction", ...))
  • Look for span attributes (e.g., span.setAttribute("purchase.amount", ...))

This confirms the semantic meaning and helps you choose the right pillar.

Step 4: Choose and Query

Based on discovery results, pick the pillar with the clearest signal, load its reference files (see Loading References), then query.


Fallback and Pivoting

If your initial route yields no results, pivot to another pillar.

Example pivot paths:

  • Metrics empty → try traces (per-request data) or logs (event records)
  • Logs empty → try traces (structured span attributes) or metrics (aggregated counters)
  • Traces empty → try logs (text-based debug output)

Do not stop after one failed attempt. Try at least two pillars before concluding the data does not exist.


CLI Commands Reference

CommandPurposeWhen to Use
cx schemaOutput the full command tree as JSONDiscover all available commands and their flags
cx metrics search --name <pattern>Find metrics by nameFirst step for metrics discovery
cx metrics search --description <text>Semantic metric searchWhen you know what you want but not the name
cx search-fields "<text>" --dataset logsFind log fields by descriptionDiscovery for log-based questions
cx search-fields "<text>" --dataset spansFind span fields by descriptionDiscovery for trace-based questions
cx search-fields "<value>" -s value --dataset logsFind log fields that contain a known valueWhen you know a value but not which log field holds it — also reveals field type from the returned values
cx search-fields "<value>" -s value --dataset spansFind span fields that contain a known valueWhen you know a value but not which span attribute holds it
cx search-fields "<value>" -s value --dataset allSame, across logs and spansWhen you want to search across both logs and spans at once
cx spans "filter $l.serviceName == '<service>'" --limit 10Search spans by serviceWhen investigating a specific service
cx dataprime listList DataPrime commands/functionsWhen building log or span queries
cx dashboards search "<description>"Find existing dashboards by natural-language descriptionBefore creating a new dashboard — check if one already exists
cx dashboards query-search --description "<text>"Find dashboard widgets whose queries cover a topicDiscover how a topic is already being monitored
cx dashboards query-search --field "<field-path>"Find widgets that reference a specific fieldReuse existing PromQL/DataPrime patterns for a known field

Show full SKILL.md (408 more words)Show less

Examples

Example 1: Business Question (Ambiguous Source)

Question: "How much money did people spend on the platform last week?"

Approach:

  1. Search metrics: cx metrics search --name '*revenue*' and cx metrics search --name '*transaction*'
  2. Search log fields: cx search-fields "transaction amount" --dataset logs
  3. Search span fields: cx search-fields "payment total" --dataset spans
  4. If a metric like payment_total_usd exists, load metrics references and run a range query
  5. If only logs have the data, load logs references and use DataPrime aggregation
  6. If traces have purchase.amount attribute, load spans references
Example 2: Latency Question (Clear First Choice)

Question: "What's the average latency of the checkout route?"

Approach:

  1. First try metrics: cx metrics search --name '*checkout*latency*' or cx metrics search --name '*http*duration*'
  2. If a histogram metric exists, load metrics references and use histogram_quantile
  3. If no metric, fall back to traces: load spans references and aggregate span durations
Example 3: Frontend Performance (RUM)

Question: "Why is the dashboard page loading slowly for users?"

Approach:

  1. This is clearly a RUM question - load references/rum-querying.md + references/rum-fields.md + references/dataprime-reference.md
  2. Query web vitals and page load times with cx dataprime query --source rum.events '...'
  3. If RUM shows backend calls are slow, pivot to spans references for the API calls
Example 4: Error Investigation (Logs + Traces)

Question: "Why are users getting 500 errors on the payment endpoint?"

Approach:

  1. Check error rate metrics → load metrics references
  2. Search for error logs → load logs references
  3. Get traces for failed requests → load spans references
  4. Cross-reference: find trace IDs in logs, then fetch full traces for root cause

Beyond Investigation

Not every question is answered by querying data. If the user's intent is operational rather than investigative, route to the appropriate workflow skill:

User IntentRoute To
Reducing costs, checking usage, TCO policiescx-cost-optimization
Triaging a case, who got paged, case timelinecx-cases
SLO status, error budget, service-level targetscx-slos
Setting up monitoring, webhooks, notificationscx-observability-setup
Configuring parsing rules, enrichments, E2Mcx-data-pipeline
Access audit, API keys, user managementcx-platform-admin
Creating or managing dashboardscx-dashboards
Finding or searching existing dashboardscx-search-dashboard

Key Principles

  • Load references before querying: check the Loading References table first
  • Discover before querying: always run search/discovery to find the right source
  • Parallel discovery: for ambiguous questions, search metrics, logs, and spans concurrently
  • Validate with code: when unsure what a metric or field represents, check the codebase
  • Pivot on failure: if one pillar is empty, try another before giving up

© coralogix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/cx-telemetry-querying of coralogix/cx-cli.

  • SKILL.md
  • references/dataprime-reference.md
  • references/logs-querying.md
  • references/metrics-querying.md
  • references/promql-guidelines.md
  • references/rum-fields.md
  • references/rum-querying.md
  • references/spans-querying.md

Open the folder on GitHubat commit c071372

Compare with similar skills

Cx Telemetry Querying next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cx Telemetry Querying compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cx Telemetry Querying this skillcoralogix/cx-cli121—~2.6kAutomated safety check: PassApache-2.0
Prometheus Missing Data Troubleshootingprometheus/prometheus-mcp121—~587Automated safety check: PassApache-2.0
Redis Observabilityredis/agent-skills1662 repos~911Automated safety check: PassMIT
Logfire Instrumentationbasicmachines-co/basic-memory4.1k—~2.3kAutomated safety check: PassAGPL-3.0
Developing Funboost Mixinydf0509/funboost895—~2.1kAutomated safety check: PassNone
Release Reviewm4r1k/Eneru149—~1.9kAutomated safety check: PassMIT

Similar skills

  • Finds where a Prometheus metric stops existing, whether at the target, the scrape, relabeling or the query, using the tools of a connected Prometheus MCP server.

    121 GitHub stars~587 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Redis Observability

    redis/agent-skills

    Official

    Redis observability guidance — which metrics to monitor (memory, connections, hit ratio, ops/sec, rejected connections), which built-in commands to reach for during incident triage (SLOWLOG, INFO…

    166 GitHub starsUsed in 2 repos~911 tokens
    DevOps & CloudAuto-check passed
  • Logfire Instrumentation

    basicmachines-co/basic-memory

    Adds Pydantic Logfire tracing, logging and metrics to Python, JavaScript or TypeScript and Rust projects, with the correct setup order and library extras.

    4.1k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • 当需要为 funboost 创建 Consumer 或 Publisher 的 Mixin 扩展类时使用。触发场景:添加监控、熔断、限流、链路追踪等横切关注点,编写自定义前置/后置处理钩子。关键词:mixin, consumeroverridecls, publisheroverridecls, ConsumerMixin, 自定义消费者, hook, 拦截器, 熔断器, 监控…

    895 GitHub stars~2.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Release Review

    m4r1k/Eneru

    Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0).

    149 GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Archestra Dev Observability

    archestra-ai/archestra

    A skill your agent uses when changing Archestra tracing, metrics, OpenTelemetry, Tempo, Grafana, Prometheus, LLM/MCP spans, observability labels, or local observability setup.

    4.4k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from coralogix/cx-cli

All 21 skills in this repo
  • Cx AI Center

    coralogix/cx-cli

    A skill your agent uses for any question or action about the user's AI/GenAI applications or agents — their behavior, prompts/responses, quality, hallucinations, guardrails, security, cost/tokens…

    121 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Alerts

    coralogix/cx-cli

    This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…

    121 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Coding Agents

    coralogix/cx-cli

    A skill your agent uses when the user asks about AI Center Coding Agents data, wants to reproduce or extend the Coding Agents dashboards, or asks questions about usage, cost, tokens, sessions…

    121 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Cost Optimization

    coralogix/cx-cli

    A skill your agent uses when the user asks to "check data usage", "list TCO policies", "reduce Coralogix costs", "optimize observability spend", "lower our logging bill", "data budget exceeded"…

    121 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Data Pipeline

    coralogix/cx-cli

    A skill your agent uses when the user asks to "set up parsing", "create parsing rule", "extract fields from logs", "regex extraction", "log parsing", "enrich logs", "add context to logs", "custom…

    121 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Cx Dashboards

    coralogix/cx-cli

    Build and deploy a Coralogix dashboard for a given service from its logs, spans, metrics, and service specs.

    121 GitHub stars~4.7k tokensUpdated 4 days ago
    Auto-check: warnings

Questions about Cx Telemetry Querying

What does Cx Telemetry Querying do?

A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…. Cx Telemetry Querying is an agent skill from coralogix/cx-cli.

When should I use Cx Telemetry Querying?

Cx Telemetry Querying fits situations like: any question involving telemetry data: investigate an issue; debug a problem; find out why something is slow; check error rates.

How do I install Cx Telemetry Querying in Claude Code?

Run `npx skills add coralogix/cx-cli --skill cx-telemetry-querying -a claude-code`. Or copy the skill folder (skills/cx-telemetry-querying in coralogix/cx-cli) into .claude/skills/cx-telemetry-querying in your project. Claude Code loads it when a task matches its description.

How do I install Cx Telemetry Querying in Codex?

Run `npx skills add coralogix/cx-cli --skill cx-telemetry-querying -a codex`. Or copy the skill folder (skills/cx-telemetry-querying in coralogix/cx-cli) into .agents/skills/cx-telemetry-querying in your project. Codex loads it when a task matches its description.

Can I use Cx Telemetry Querying in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coralogix/cx-cli --skill cx-telemetry-querying -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cx-telemetry-querying, .gemini/skills/cx-telemetry-querying, .github/skills/cx-telemetry-querying and .opencode/skills/cx-telemetry-querying in your project.

What does Cx Telemetry Querying need to run?

SKILL.md names no scripts, command-line tools or credentials: Cx Telemetry Querying is instructions for the agent only.

Does Cx Telemetry Querying access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cx Telemetry Querying safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cx Telemetry Querying use?

Cx Telemetry Querying is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cx Telemetry Querying use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Cx Telemetry Querying?

Skills that share tags, products or a category with Cx Telemetry Querying: Prometheus Missing Data Troubleshooting (prometheus/prometheus-mcp, 121 stars), Redis Observability (redis/agent-skills, 166 stars), Logfire Instrumentation (basicmachines-co/basic-memory, 4.1k stars) and Developing Funboost Mixin (ydf0509/funboost, 895 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cx Telemetry Querying?

coralogix (a GitHub organization) maintains it in coralogix/cx-cli, which has 121 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: coralogix/cx-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.