Official agent skill

Cloud Logging Query Generation

by google in google/skills

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language.

OfficialApache-2.0Auto-check passedDevelopment

Install Cloud Logging Query Generation

skills CLI
$ npx skills add google/skills --skill cloud-logging-query-generation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills cloud-logging-query-generation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/cloud-logging-query-generation .claude/skills/cloud-logging-query-generation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-logging-query-generation
GitHub stars
21k
Token cost
~1.9k tokens
SKILL.md length
807 words
Files
23 (incl. references)
Skills in repo
145
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language.

  • Works in 4 steps: Strict syntax requirements → Common pitfalls → Output format and placeholders → …
  • You need to query log data
  • SKILL.md covers Core rules, Detailed reference, Service reference files and Query generation rules, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cloud Logging Query Generation is an agent skill from google/skills, published by the product's own GitHub organization. Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including reference files (for example `references/api_reference.md`, `references/query_app_engine.md` and `references/query_audit_logs.md`).

It sits in Development, covering SQL. It works with Google Cloud and SQL. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • You need to query log data
  • You are debugging issues
  • Query other databases

Example prompts

  • “Use the cloud-logging-query-generation skill to generate Logging Query Language (LQL) queries for Google Cloud Logging from natural language”
  • “/cloud-logging-query-generation”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Strict syntax requirements
  2. Common pitfalls
  3. Output format and placeholders
  4. Preferred fields

What it can do on your machine

Read from SKILL.md and the folder at commit 8a1ac05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Logging Query Generation loads about 1.9k tokens when it runs, and up to ~25k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 807 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~25k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 8a1ac05, republished under its Apache-2.0 licence (© google). 807 words, ~1,918 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-logging-query-generation/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.
name
cloud-logging-query-generation
description
Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.
metadata.version
1.0.0
metadata.category
CloudObservabilityAndMonitoring

Generate Logging Query Language queries

Use this skill to generate correct Logging Query Language (LQL) queries for Cloud Logging.

Core rules

  1. Strict syntax requirements:

    • Always use double quotes (") for string literals. Do not use single quotes (').
    • Write boolean operators in all capitals: AND, OR, NOT.
    • Always use parentheses to group terms and explicitly enforce precedence.
  2. Common pitfalls:

    • Instance ID vs. Instance Name: For the gce_instance resource type, do NOT compare instance names to instance IDs. Instance names are strings (for example, my-instance). Instance IDs are numeric. If you only have the name, then search by instance name, SEARCH("my-instance"), or use resource.labels.instance_name if that label is available for the resource.
    • Resource Type Accuracy: Do not guess resource types. You must look up the correct resource.type value in the service-specific reference files. For example, use internal_http_lb_rule for Internal HTTP(S) Load Balancer rules when filtering by forwarding rule name or region (instead of http_load_balancer).
  3. Output format and placeholders:

    • Output only the raw LQL query text. Do not include conversational filler. Do not wrap the query in markdown code blocks unless explicitly requested by the user. Valid LQL comments (using --) are allowed, and are the ONLY acceptable way to include explanations or warnings.
    • Never block on missing variables. If the user's request lacks specific identifiers (like a project ID, instance name, or IP address), do not ask them for clarification. If the variable is required for a functional query (like a log bucket name for a regional log), insert an uppercase placeholder string wrapped in angle brackets (for example, "<PROJECT_ID>"). CRITICALLY: If you include a placeholder for a variable the user omitted, it will act as an explicit filter that causes logs to be missed. Therefore, you MUST omit the entire filter/line containing the placeholder if the field is not strictly required. For example, completely omit resource.labels.instance_id="..." if the user didn't specify an instance, but you MUST include logName=".../projects/<PROJECT_ID>/..." with a placeholder if constructing a regional log bucket query where a project ID is strictly required.
  4. Preferred fields:

    • Include resource.type and log_id restrictions when the query targets specific Google Cloud services or resources. Global queries (for example, "latest error logs") do not require these restrictions.

Detailed reference

Refer to references/api_reference.md for LQL syntax rules, including Operators, NULL handling, SEARCH, and Regex.

Service reference files

Before generating a query, you MUST read the examples for the specific service. LQL schemas and resource.type values are service-specific. Do not stop reading after finding the Base Schema in the file. You must verify if there are specific requirements for state tracking (like previousState) or resource-specific log IDs detailed in the paragraphs or specific query examples below the schema block.

For the following services, read the exact file listed:

For Google Cloud services that aren't listed: If the service is not listed above, write the LQL query based on your general knowledge.

Show full SKILL.md (273 more words)Show less

Query generation rules

  1. Resource Types: Explicitly define the resource.type in your queries when focusing on specific services. For some queries, you may need to search across multiple types (for example, resource.type=("bigquery_project" OR "bigquery_dataset")).
  2. Audit and Admin Logs: If the user asks for audit logs, admin logs, API logs, or logs about who created, updated, deleted, read, or accessed a resource:
    • You MUST read references/query_audit_logs.md for the correct protoPayload schema paths and common examples.
    • If a specific example is not listed, guess the protoPayload.methodName by combining the service and verb. When guessing, you MUST use the scoped SEARCH() function (e.g., SEARCH(protoPayload.methodName, "compute.instances.insert")) instead of the exact match operator (=) to avoid version prefix mismatches. Do NOT use the colon operator (:) as it may cause substring false positives.
    • For generic API enable/disable events (e.g., a service was disabled), always use resource.type="audited_resource".
  3. Handling Unknown Schemas (Crucial): If the user asks to filter by a specific field or condition, and if you cannot find a matching example or schema in the reference files, then you must generate a query using global search.
    • Only specify jsonPayload.* or protoPayload.* field structures when you are certain of their exact name.
    • Use the SEARCH() function to find the keyword globally within the correct resource.type.
    • Mandatory LQL Comment: When delivering a query that uses SEARCH, you MUST add an LQL comment (using --) at the top of the query indicating you used a global keyword search because the exact schema wasn't in your references. Do NOT output conversational text, strictly adhere to the Output Format rule.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 22 other files (references) in skills/cloud/cloud-logging-query-generation of google/skills.

  • SKILL.md
  • references/api_reference.md
  • references/query_app_engine.md
  • references/query_audit_logs.md
  • references/query_bigquery.md
  • references/query_cloud_functions.md
  • references/query_cloud_observability.md
  • references/query_cloud_run.md
  • references/query_cloud_source_repositories.md
  • references/query_cloud_sql.md
  • references/query_cloud_storage.md
  • references/query_cloud_tasks.md
  • references/query_compute_engine.md
  • references/query_dataflow.md
  • references/query_dataproc.md
  • references/query_deployment_manager.md
  • references/query_gke.md
  • references/query_iam.md
  • references/query_networking.md
  • references/query_security.md
  • … and 3 more

Open the folder on GitHubat commit 8a1ac05

Compare with similar skills

Cloud Logging Query Generation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Logging Query Generation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Logging Query Generation this skillgoogle/skills21k—~1.9kAutomated safety check: PassApache-2.0
Smt E2E Dataflow DebuggingGoogleCloudPlatform/DataflowTemplates1.3k—~1.8kAutomated safety check: PassApache-2.0
Cxas Configurable DashboardsGoogleCloudPlatform/cxas-scrapi106—~1.8kAutomated safety check: PassApache-2.0
GCP Cloud SQLsickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMIT
Imaging Data CommonsK-Dense-AI/scientific-agent-skills48k1 repos~7.8kAutomated safety check: PassMIT
Cloud SQL Basicsdavila7/claude-code-templates32k—~810Automated safety check: PassMIT

Similar skills

  • Smt E2E Dataflow Debugging

    GoogleCloudPlatform/DataflowTemplates

    Debugs logical errors and data discrepancies in Dataflow templates by launching jobs via Terraform and comparing source (e.g.

    1.3k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Cxas Configurable Dashboards

    GoogleCloudPlatform/cxas-scrapi

    Author, validate, and manage Contact Center AI (CCAI) Insights Configurable Dashboards.

    106 GitHub stars~1.8k tokensUpdated today
    DatabasesAuto-check passed
  • GCP Cloud SQL

    sickn33/agentic-awesome-skills

    Provision Cloud SQL and Spanner databases. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.4k tokens
    DatabasesAuto-check passed
  • Imaging Data Commons

    K-Dense-AI/scientific-agent-skills

    Queries and downloads public cancer imaging data from NCI Imaging Data Commons.

    48k GitHub starsUsed in 1 repo~7.8k tokens
    DatabasesAuto-check passed
  • Cloud SQL Basics

    davila7/claude-code-templates

    Creates and manages Cloud SQL instances for MySQL, PostgreSQL, and SQL Server.

    32k GitHub stars~810 tokensUpdated today
    DatabasesAuto-check passed
  • Firebase

    ericrisco/rsc-harness

    A skill your agent uses when building on Firebase — Firestore data modeling, Security Rules, Auth and custom claims, Cloud Functions, Storage, modular Web/Admin SDK imports — including symptoms like…

    156 GitHub stars~3.3k tokensUpdated today
    DatabasesAuto-check passed

More from google/skills

All 145 skills in this repo
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated today
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Official

    Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.

    21k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Questions about Cloud Logging Query Generation

What does Cloud Logging Query Generation do?

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Cloud Logging Query Generation is an agent skill from google/skills, published by the product's own GitHub organization. Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language.

When should I use Cloud Logging Query Generation?

Cloud Logging Query Generation fits situations like: you need to query log data; you are debugging issues; query other databases.

How do I install Cloud Logging Query Generation in Claude Code?

Run `npx skills add google/skills --skill cloud-logging-query-generation -a claude-code`. Or copy the skill folder (skills/cloud/cloud-logging-query-generation in google/skills) into .claude/skills/cloud-logging-query-generation in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Logging Query Generation in Codex?

Run `npx skills add google/skills --skill cloud-logging-query-generation -a codex`. Or copy the skill folder (skills/cloud/cloud-logging-query-generation in google/skills) into .agents/skills/cloud-logging-query-generation in your project. Codex loads it when a task matches its description.

Can I use Cloud Logging Query Generation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill cloud-logging-query-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-logging-query-generation, .gemini/skills/cloud-logging-query-generation, .github/skills/cloud-logging-query-generation and .opencode/skills/cloud-logging-query-generation in your project.

What does Cloud Logging Query Generation need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloud Logging Query Generation is instructions for the agent only.

Does Cloud Logging Query Generation access the network?

SKILL.md names 1 domain. As links in the text: docs.cloud.google.com. This is read from the text; nothing was executed.

Is Cloud Logging Query Generation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Logging Query Generation use?

Cloud Logging Query Generation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Logging Query Generation use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to Cloud Logging Query Generation?

Skills that share tags, products or a category with Cloud Logging Query Generation: Smt E2E Dataflow Debugging (GoogleCloudPlatform/DataflowTemplates, 1.3k stars), Cxas Configurable Dashboards (GoogleCloudPlatform/cxas-scrapi, 106 stars), GCP Cloud SQL (sickn33/agentic-awesome-skills, 47k stars) and Imaging Data Commons (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Logging Query Generation?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 20,994 GitHub stars. The repository holds 145 skills in this directory. The repository was last updated on October 6, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.