Agent skill

Dt Obs Logs

by Dynatrace in Dynatrace/dynatrace-for-ai

Log querying, filtering, pattern analysis, and error rate calculation.

Apache-2.0Auto-check passedDevOps & Cloud

Install Dt Obs Logs

skills CLI
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dynatrace/dynatrace-for-ai dt-obs-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-obs-logs .claude/skills/dt-obs-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dt-obs-logs
GitHub stars
163
Token cost
~2.4k tokens
SKILL.md length
818 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Log querying, filtering, pattern analysis, and error rate calculation.

  • Works in 3 steps: Log Searching → Log Filtering → Pattern Analysis
  • Searching application
  • SKILL.md covers What This Skill Covers, Use Cases, Key Concepts and Core Workflows, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dt Obs Logs is an agent skill from Dynatrace/dynatrace-for-ai. Log querying, filtering, pattern analysis, and error rate calculation. Use when searching application or infrastructure logs, analyzing error patterns, or correlating log data. Trigger: "show error logs", "search logs for keyword", "log error rate", "recent errors", "logs from last hour", "find log entries", "top error messages", "log patterns", "parse JSON logs", "logs by process group", "log trends over time", "log entry counts per minute". Do NOT use for explaining existing queries, product documentation…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Observability and Technical writing. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.

When your agent uses it

  • Searching application
  • Infrastructure logs
  • Analyzing error patterns
  • Correlating log data

Example prompts

  • “show error logs”
  • “search logs for keyword”
  • “log error rate”
  • “/dt-obs-logs”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Log Searching
  2. Log Filtering
  3. Pattern Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dt Obs Logs loads about 2.4k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 818 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 818 words, ~2,365 tokens.

Download SKILL.mdSave it as .claude/skills/dt-obs-logs/SKILL.md (or your agent's skills folder).
name
dt-obs-logs
description
Log querying, filtering, pattern analysis, and error rate calculation. Use when searching application or infrastructure logs, analyzing error patterns, or correlating log data. Trigger: "show error logs", "search logs for keyword", "log error rate", "recent errors", "logs from last hour", "find log entries", "top error messages", "log patterns", "parse JSON logs", "logs by process group", "log trends over time", "log entry counts per minute". Do NOT use for explaining existing queries, product documentation questions, distributed tracing or span analysis (use dt-obs-tracing).
license
Apache-2.0

Log Analysis Skill

Query, filter, and analyze Dynatrace log data using DQL for troubleshooting and monitoring.

What This Skill Covers

  • Fetching and filtering logs by severity, content, and entity
  • Searching log messages using pattern matching
  • Calculating error rates and statistics
  • Analyzing log patterns and trends
  • Grouping and aggregating log data by dimensions

Cross-source join required: If the query must combine logs with host attributes (OS type, hostname, IP address, cloud provider) → also read dt-dql-essentials/references/smartscape-topology-navigation.md before writing the query.


Use Cases

Use this skill when users want to:

  • Find specific log entries (e.g., "show me error logs from the last hour")
  • Filter logs by severity, process group, or content
  • Search logs for specific keywords or phrases
  • Calculate error rates or log statistics
  • Identify common error messages or patterns
  • Analyze log trends over time
  • Troubleshoot issues using log data

Key Concepts

Log Data Model
  • timestamp: When the log entry was created
  • content: The log message text
  • status: Log level (ERROR, FATAL, WARN, INFO, etc.)
  • dt.process_group.id: Associated process group entity
  • dt.process_group.detected_name: Resolves process group IDs to human-readable names
Query Patterns
  • fetch logs: Primary command for log data access
  • Time ranges: Use from:now() - <duration> for time windows
  • Filtering: Apply severity, content, and entity filters
  • Aggregation: Group and summarize log data
  • Pattern Detection: Use matchesPhrase() and contains() for content search
Common Operations
  • Severity filtering (single or multiple levels)
  • Content search (simple and full-text)
  • Entity-based filtering (process groups)
  • Time-series analysis (bucketing, sorting)
  • Error rate calculation
  • Pattern analysis (exceptions, timeouts, etc.)

Core Workflows

1. Log Searching

Find specific log entries by time, severity, and content.

Typical steps:

  1. Define time range
  2. Filter by severity (optional)
  3. Search content for keywords
  4. Select relevant fields
  5. Sort and limit results

Example:

dql
fetch logs, from:now() - 1h
| filter status == "ERROR"
| fields timestamp, content, process_group = dt.process_group.detected_name
| sort timestamp desc
| limit 100
2. Log Filtering

Narrow down logs using multiple criteria (severity, entity, content).

Typical steps:

  1. Fetch logs with time range
  2. Apply severity filters
  3. Filter by entity (process_group)
  4. Apply content filters
  5. Format and sort output

Example:

dql
fetch logs, from:now() - 2h
| filter in(status, {"ERROR", "FATAL", "WARN"})
| summarize count(), by: {dt.process_group.id, dt.process_group.detected_name}
| fieldsAdd process_group = dt.process_group.detected_name
| sort `count()` desc
3. Pattern Analysis

Identify patterns, trends, and anomalies in log data.

Typical steps:

  1. Fetch logs with time range
  2. Add pattern detection fields
  3. Aggregate by entity or time
  4. Calculate statistics and ratios
  5. Sort by frequency or rate

Example:

dql
fetch logs, from:now() - 2h
| filter status == "ERROR"
| fieldsAdd
    has_exception = if(matchesPhrase(content, "exception"), true, else: false),
    has_timeout = if(matchesPhrase(content, "timeout"), true, else: false)
| summarize
    count(),
    exception_count = countIf(has_exception == true),
    timeout_count = countIf(has_timeout == true),
    by: {process_group = dt.process_group.detected_name}

Key Functions

Filtering
  • filter status == "ERROR" - Filter by status level
  • in(status, {"ERROR", "FATAL", "WARN"}) - Multi-status filter (use curly braces for literal sets)
  • contains(content, "keyword") - Simple substring search
  • matchesPhrase(content, "exact phrase") - Full-text phrase search
Entity Operations
  • dt.process_group.detected_name - Get human-readable process group name
  • filter process_group == "service-name" - Filter by specific entity
Aggregation
  • count() - Count all log entries
  • countIf(condition) - Conditional count
  • by: {dimension} - Group by entity or time bucket
  • bin(timestamp, 5m) - Time bucketing for trends
Field Operations
  • fields timestamp, content, status - Select specific fields
  • fieldsAdd name = expression - Add computed fields
  • if(condition, true_value, else: false_value) - Conditional logic

Common Patterns

Simple substring search:

dql
fetch logs, from:now() - 1h
| filter contains(content, "database")
| fields timestamp, content, status

Full-text phrase search:

dql
fetch logs, from:now() - 1h
| filter matchesPhrase(content, "connection timeout")
| fields timestamp, content, process_group = dt.process_group.detected_name
Error Rate Calculation

Calculate error rates over time:

dql
fetch logs, from:now() - 2h
| summarize
    total_logs = count(),
    error_logs = countIf(status == "ERROR"),
    by: {time_bucket = bin(timestamp, 5m)}
| fieldsAdd error_rate = (error_logs * 100.0) / total_logs
| sort time_bucket asc
Top Error Messages

Find most common errors:

dql
fetch logs, from:now() - 24h
| filter status == "ERROR"
| summarize error_count = count(), by: {content}
| sort error_count desc
| limit 20
Process Group-Specific Logs

Filter logs by process group:

dql
fetch logs, from:now() - 1h
| fieldsAdd process_group = dt.process_group.detected_name
| filter process_group == "payment-service"
| filter status == "ERROR"
| fields timestamp, content, status
| sort timestamp desc
Show full SKILL.md (328 more words)Show less
Structured / JSON Log Parsing

Many applications emit JSON-formatted log lines. Use parse to extract fields instead of dumping raw content:

dql
fetch logs, from:now() - 1h
| filter status == "ERROR"
| parse content, "JSON:log"
| fieldsAdd level = log[level], message = log[msg], error = log[error]
| fields timestamp, level, message, error
| sort timestamp desc
| limit 50

Aggregate by a parsed field:

dql
fetch logs, from:now() - 4h
| filter status == "ERROR"
| parse content, "JSON:log"
| fieldsAdd message = log[msg]
| summarize error_count = count(), by: {message}
| sort error_count desc
| limit 20

Notes:

  • parse content, "JSON:log" creates a record field log — access nested values with log[key]
  • Filter logs with contains() before parse to reduce parsing overhead
  • Works with any JSON-structured field, not just content

Best Practices

  1. Always specify time ranges - Use from:now() - <duration> to limit data
  2. Apply filters early - Filter by severity and entity before aggregation
  3. Use appropriate search methods - contains() for simple, matchesPhrase() for exact
  4. Limit results - Add | limit 100 to prevent overwhelming output
  5. Sort meaningfully - Sort by timestamp for recent logs, by count for top errors
  6. Name entities - Use dt.process_group.detected_name or getNodeName() for human-readable output
  7. Use time buckets for trends - bin(timestamp, 5m) for time-series analysis

Integration Points

  • Entity model: Uses dt.process_group.id for service correlation
  • Time series: Supports temporal analysis with bin() and time ranges
  • Content search: Full-text search capabilities via matchesPhrase()
  • Aggregation: Statistical analysis using summarize and conditional functions

Limitations & Notes

  • Log availability depends on OneAgent configuration and log ingestion
  • Full-text search (matchesPhrase) may have performance implications on large datasets
  • Entity names require proper OneAgent monitoring for resolution
  • Time ranges should be reasonable (avoid unbounded queries)

Troubleshooting

ProblemCauseSolution
No logs returnedMissing time range or too narrowWiden from: window; verify log ingestion is active
getNodeName() returns nullOneAgent not monitoring the entity or entity not yet resolvedVerify OneAgent is deployed and entity is discovered; use dt.process_group.detected_name as a reliable alternative
matchesPhrase() slow on large dataFull-text search without pre-filteringAdd filter status == "ERROR" before matchesPhrase()
Wrong field name log.levelCommon mistakeUse loglevel (no dot) for severity; see dt-dql-essentials
Empty content fieldLog line was empty or not ingestedCheck log source configuration in OneAgent
  • dt-dql-essentials - Core DQL syntax and query structure for log queries
  • dt-obs-tracing - Correlate logs with distributed traces using trace IDs
  • dt-obs-problems - Correlate logs with DAVIS-detected problems

© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dt-obs-logs of Dynatrace/dynatrace-for-ai.

Open the folder on GitHubat commit 4f9aa71

Compare with similar skills

Dt Obs Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dt Obs Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dt Obs Logs this skillDynatrace/dynatrace-for-ai163—~2.4kAutomated safety check: PassApache-2.0
Agentdock User Guideuvwt/agentdock1.2k—~1.6kAutomated safety check: PassApache-2.0
Cloudflareswyxio/skills176—~793Automated safety check: PassMIT
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Agentdock User Guide

    uvwt/agentdock

    当用户询问 AgentDock 是什么、如何使用、配置在哪里、不同平台或安装方式怎样修改配置并生效、如何重启或验证配置、如何发现并配置 Codex/Claude/Grok 等 Coding Agent 的 ACP,以及常见运行问题时使用;覆盖 macOS Desktop、Windows Desktop、Linux 服务、Docker 和直接运行二进制,不用于源码开发与贡献流程。

    1.2k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloudflare

    swyxio/skills

    Route an ambiguous or cross-product Cloudflare platform request to the appropriate product, documentation, or narrower local skill.

    176 GitHub stars~793 tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from Dynatrace/dynatrace-for-ai

All 33 skills in this repo
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    163 GitHub stars~3.9k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Alerting

    Dynatrace/dynatrace-for-ai

    End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    163 GitHub stars~4.2k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Ext Monitors

    Dynatrace/dynatrace-for-ai

    3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).

    163 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Problems

    Dynatrace/dynatrace-for-ai

    DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.

    163 GitHub stars~4.6k tokensUpdated 9 days ago
    Auto-check passed

Questions about Dt Obs Logs

What does Dt Obs Logs do?

Log querying, filtering, pattern analysis, and error rate calculation. Dt Obs Logs is an agent skill from Dynatrace/dynatrace-for-ai. Log querying, filtering, pattern analysis, and error rate calculation.

When should I use Dt Obs Logs?

Dt Obs Logs fits situations like: searching application; infrastructure logs; analyzing error patterns; correlating log data.

How do I install Dt Obs Logs in Claude Code?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-logs -a claude-code`. Or copy the skill folder (skills/dt-obs-logs in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-obs-logs in your project. Claude Code loads it when a task matches its description.

How do I install Dt Obs Logs in Codex?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-logs -a codex`. Or copy the skill folder (skills/dt-obs-logs in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-obs-logs in your project. Codex loads it when a task matches its description.

Can I use Dt Obs Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-obs-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-obs-logs, .gemini/skills/dt-obs-logs, .github/skills/dt-obs-logs and .opencode/skills/dt-obs-logs in your project.

What does Dt Obs Logs need to run?

SKILL.md names no scripts, command-line tools or credentials: Dt Obs Logs is instructions for the agent only.

Does Dt Obs Logs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dt Obs Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dt Obs Logs use?

Dt Obs Logs is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dt Obs Logs use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dt Obs Logs?

Skills that share tags, products or a category with Dt Obs Logs: Agentdock User Guide (uvwt/agentdock, 1.2k stars), Cloudflare (swyxio/skills, 176 stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Kubeshark Installer (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dt Obs Logs?

Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.