Official agent skill

Loki Label Analyzer

by grafana in grafana/skills

Expert evaluator for Grafana Loki label strategy. An agent skill from grafana/skills.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Loki Label Analyzer

skills CLI
$ npx skills add grafana/skills --skill loki-label-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills loki-label-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-cloud/loki-label-analyzer .claude/skills/loki-label-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
loki-label-analyzer
GitHub stars
282
Token cost
~5.4k tokens
SKILL.md length
1,951 words
Files
5 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Expert evaluator for Grafana Loki label strategy. An agent skill from grafana/skills.

  • Works in 3 steps: Disclaimer (mandatory, first body… → Protected labels: Before recommending… → Cost Impact Analysis: Include when…
  • The user asks to evaluate
  • SKILL.md covers Core Concepts, Label Evaluation Framework, Evaluation Output Format and Recommended Common Labels, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Loki Label Analyzer is an agent skill from grafana/skills, published by the product's own GitHub organization. Expert evaluator for Grafana Loki label strategy. Audits, designs, and improves label schemas using cardinality scoring, access-pattern alignment, static vs. dynamic label rules, and consistency checks. Use when the user asks to evaluate, audit, design, or improve a Loki label strategy — or asks why their Loki queries are slow.

Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/cost-impact.md`, `references/disclaimer.md` and `references/log-line-optimization.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting. It works with Grafana. The licence is Apache-2.0.

When your agent uses it

  • The user asks to evaluate
  • Improve a Loki label strategy —
  • Asks why their Loki queries are slow

Example prompts

  • “/loki-label-analyzer”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Disclaimer (mandatory, first body section): Load references/disclaimer.md and paste its two paragraphs verbatim under a ### Disclaimer…
  2. Protected labels: Before recommending demote/drop for any label, load references/protected-labels.md. Never recommend dropping…
  3. Cost Impact Analysis: Include when Grafana Cloud usage metrics are available; if they are not, state what is missing and still give…

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are alloy, logql and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Loki Label Analyzer loads about 5.4k tokens when it runs, and up to ~8.4k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,951 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~5.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 1,951 words, ~5,429 tokens.

Download SKILL.mdSave it as .claude/skills/loki-label-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
loki-label-analyzer
description
Expert evaluator for Grafana Loki label strategy. Audits, designs, and improves label schemas using cardinality scoring, access-pattern alignment, static vs. dynamic label rules, and consistency checks. Use when the user asks to evaluate, audit, design, or improve a Loki label strategy — or asks why their Loki queries are slow.
license
Apache-2.0

Loki Label Strategy Evaluator

You are an expert in Grafana Loki label strategy. When asked to evaluate, audit, design, or improve a Loki label strategy — or when a user asks why their Loki queries are slow — use this guide to provide structured, actionable advice.


Core Concepts

Streams are the fundamental unit in Loki. Each unique combination of label key-value pairs creates a new stream. Too many streams = performance problems. Too few = broad, slow queries.

Cardinality = the number of unique values a label can have. High-cardinality labels (like pod, user_id, request_id) dramatically increase stream count and hurt performance — especially when those labels are not specified in every query.

The dual impact rule: High-cardinality labels hurt on both paths:

  • Ingestion path: More streams → larger index, higher storage costs
  • Query path: If a high-cardinality label exists but isn't in the query selector, Loki must scan ALL streams matching the other selectors — catastrophic for performance

The key question for any dynamic label: "Will this label be used in 9 out of 10 queries?" If no → it should NOT be a label — except platform / correlation labels (below).

Platform / correlation labels are exempt from drop recommendations. Never recommend dropping service_name, deployment_environment, or job when present. Bad cardinality on those keys is a value problem (stabilize identities); dropping the key breaks Grafana Cloud correlation, App O11y, alerts, and dashboards. Load references/protected-labels.md before any demote/label_keep advice.


Label Evaluation Framework

When auditing a label strategy, assess each label against these criteria.

Cardinality Scoring
Label ExampleCardinalityVerdict
service_name / deployment_environment / jobAny✅ Keep key — remediate values if high-card (never drop)
env (prod/staging/dev)2–5 values✅ Good
level (info/warn/error)3–6 values✅ Good
namespace (K8s)Tens✅ Acceptable
instance / hostnameHundreds–thousands⚠️ Evaluate access patterns
podThousands + transient⚠️ Demote off index (structured metadata) — migrate selectors first
user_id, request_idUnbounded❌ Never use as label
Access Pattern Alignment

For each label, ask:

  • Is this label on the protected allowlist? If yes → Keep key; remediate values only (protected-labels.md)
  • Is this label used as a selector in most queries targeting these logs?
  • Does this label logically segment data in the way users think about it?
  • Would demoting this label break alerts, dashboards, LBAC, or correlation without a migration plan?
  • Would demoting this label force users to scan dramatically more data?
Static vs. Dynamic Label Values
  • Static labels (values don't change per log line, e.g., platform=linux, job=agent) add no cardinality cost relative to the query scope. Use freely for LBAC, exploration, and alert routing.
  • Dynamic labels (values change per log line) must be bounded. Keep possible values in the single digits or low tens.
Consistency Check
  • Are label names consistent across services? (case-sensitive — Level ≠ level)
  • Are label values normalized? (INFO, info, Info should all become info)
  • Is there a naming convention? (pick one: snake_case or camelCase — be consistent)

Evaluation Output Format

When auditing a label set, produce a report in the structure below.

Hard requirements before finalizing any audit report:

  1. Disclaimer (mandatory, first body section): Load references/disclaimer.md and paste its two paragraphs verbatim under a ### Disclaimer heading. An empty Disclaimer heading is a failed report — do not ship the audit until both paragraphs are present. Never paraphrase, summarize, or omit this text.
  2. Protected labels: Before recommending demote/drop for any label, load references/protected-labels.md. Never recommend dropping service_name, deployment_environment, or job when present — only value remediation. Include a Downstream dependency check covering alerts, dashboards, LBAC, and correlation.
  3. Cost Impact Analysis: Include when Grafana Cloud usage metrics are available; if they are not, state what is missing and still give qualitative A/B/C guidance. Load references/cost-impact.md and follow its Required report shape (scenario cards). Do not paste markdown tables or panel/query JSON into this section.

Report completion check: Before delivering, confirm (a) the output contains the substring Confidential Information of Raintank, Inc. immediately after ### Disclaimer, (b) Cost Impact Analysis uses scenario cards (A/B/C) with a Billing note opener and a bullet Measured baseline — not a scenario table and not panelId/targets JSON, and (c) no Action cell recommends dropping an allowlisted correlation label. If (a) is missing, paste from references/disclaimer.md and re-emit. If (b) fails, rewrite Cost Impact from references/cost-impact.md. If (c) fails, rewrite Actions per references/protected-labels.md.

## Loki Label Strategy Audit

### Disclaimer
[Paste BOTH paragraphs from references/disclaimer.md HERE — never leave this heading empty]

### Summary
[1-2 sentence overall assessment]

### Downstream dependency check
[Alerts / dashboards / LBAC / correlation that select on labels proposed for demote or rename — or "unknown; confirm with customer before cutover"]

### Label Analysis
| Label | Cardinality | Used in Queries? | Verdict | Action |
|---|---|---|---|---|
| service_name | High (UUID values) | Always | ✅ Keep key | Stabilize values to durable service identity — do not drop label |
| deployment_environment | Low | Often | ✅ Keep | — |
| job | Low–medium | Often | ✅ Keep | — |
| pod | Very High (transient)| Rarely | ⚠️ Demote | Move to structured metadata or embed; migrate selectors first |

### Estimated Impact
- Stream count reduction: [X streams → Y streams]
- Query performance: [describe improvement]
- Storage impact: [if log line changes are involved]
- Correlation impact: [none if allowlist preserved; call out if aliases need dual-write]

### Cost Impact Analysis
[Follow references/cost-impact.md Required report shape — do not invent a table]

**Billing note:** Label hygiene alone does not reduce billable ingest bytes.
Stream count and query cost improve; ingest $ drops only when volume is reduced.

**Measured baseline** (Grafana Cloud usage metrics):
- Active streams: [N]
- Billable ingest: [rate]
- Overage: [units or $]
- Top ingest contributor: [name + rate] (omit if unavailable)

**Scenario A — Label hygiene only (this audit)**
- Actions / stream impact / volume=$0 / overage unchanged

**Scenario B — A + approved debug/trace drop**
- Actions / volume % / $ or overage estimate / customer-approval guardrail

**Scenario C — B + log-line compaction**
- Actions / additional volume % / highest-value target

**Attribution gap:** [...]
**Caveats:** [...]

### Recommended Label Set
[Final recommended labels — must include service_name, deployment_environment, job when present]

### Migration Notes
[How to implement changes via Alloy/Agent pipeline stages; dual-write / selector updates for any demote or rename]

Every log source should consider these base labels — all low cardinality, high query value:

LabelPurpose
service_nameIdentifying the generating application (OTel service.name — required for Grafana Cloud correlation / App O11y)
deployment_environmentDeployment environment (OTel deployment.environment) — keep when present
jobCollector / OTel job (namespace/service.name pattern common on span metrics) — keep when present
app / serviceLegacy aliases only — prefer aligning to service_name; do not delete without a migration plan
envEnvironment shorthand (prod, staging, dev) when deployment_environment is absent
clusterMulti-cluster differentiation
regionGeographic region
levelLog severity — normalize to: info, warn, error, debug
team / squadOwnership (also useful for LBAC)
sourceLog origin type (file, k8s-events, journal, syslog, etc.)
classificationData sensitivity level — for LBAC policies

Always include allowlisted correlation labels in any label_keep list — see references/protected-labels.md.


Kubernetes Pod Logs

LabelDescription
service_nameStable service identity (OTel service.name) — keep; remediate UUID/ephemeral values
namespaceK8s namespace — delineates isolation boundaries
containerContainer name — low cardinality, differentiates log formats
workload{controller_kind}/{controller_name} e.g. ReplicaSet/payment-api — strongly recommended

Why workload beats app for K8s: Derived from {{controller_kind}}/{{controller_name}} — static values that never change like pod names do. Unlike app (which may aggregate multiple workload types), workload is precise and predictable. Users always know exactly what value to query. Still keep service_name for cross-signal correlation even when using workload.

Labels to demote in Kubernetes (not "never existed")

pod label ⚠️

  • Highly transient: pod names change on every restart/rollout
  • Very high cardinality: 5 pods × 2 containers = 10 streams; add pod → 10 × N streams
  • Users almost never query for a specific pod; they query for the workload
  • Solution: Use workload as the index label; store pod in structured metadata or embed in the log line. Migrate any alerts/dashboards that select on pod before demoting.

filename label (raw K8s path) ⚠️

  • K8s log paths contain pod UID: /var/log/pods/{namespace}_{pod}_{pod_id}/{container}/{rotation}.log
  • The pod_id component makes this unbounded
  • Solution: Normalize to /var/log/pods/{namespace}/{controller_name}/{container}.log or demote entirely after checking selectors
alloy
// Normalize K8s filename to remove pod UID
stage.replace {
 source = "filename"
 expression = "/var/log/pods/([^/]+)_[^_]+_[^/]+/([^/]+)/\\d+\\.log"
 replace = "/var/log/pods/$1/$2/current.log"
}

Host / VM / Bare Metal Labels

In addition to common labels, add:

LabelDescriptionNotes
instanceHostname of the machineCardinality = number of machines; acceptable for fixed infrastructure
filenameFull path to the file being tailedNormalize rotating filenames — strip date suffixes
alloy
// Remove date suffixes from rotating log file names
// /var/log/myapp/logfile-20230927.txt → /var/log/myapp/logfile.txt
stage.replace {
 source = "filename"
 expression = "-\\d{8}(\\.log|\\.txt)$"
 replace = "$1"
}

Journal Logs

When collecting via loki.source.journal, many labels are auto-discovered under __journal__*: boot_id, cap_effective, cmdline, comm, exe, gid, hostname, machine_id, pid, stream_id, systemd_cgroup, systemd_invocation_id, systemd_slice, systemd_unit, transport, uid

Almost all are high-cardinality. Keep instance (hostname) and unit (systemd_unit, e.g. nginx.service), plus any allowlisted correlation labels present on the stream (service_name, deployment_environment, job).

Drop other non-allowlisted high-cardinality journal labels (not platform keys):

alloy
loki.process "journal_labels" {
 forward_to = [...]
 stage.label_keep {
 values = ["instance", "unit", "env", "cluster", "service_name", "deployment_environment", "job"]
 }
}

Structured Metadata

Structured metadata attaches key-value pairs to log entries without making them index labels. The ideal home for high-cardinality values users occasionally need.

Requires: Loki 2.9+, Grafana Agent/Alloy. Enable via limits_config:

yaml
limits_config:
 allow_structured_metadata: true

Good candidates for structured metadata (not labels):

  • pod — K8s pod name
  • node — K8s worker node
  • version / image / tag
  • trace_id / user_id
  • process_id
  • restarted — pod restart timestamp

Query structured metadata at query time without a parser:

logql
{service_name="payment-api"} | pod="payment-api-7f9d4b-xk2r9"

Show full SKILL.md (783 more words)Show less

Embedding Metadata in Log Lines

When structured metadata isn't available, embed high-cardinality values into the log line rather than using them as labels.

Method 1: stage.template (append to log line)
alloy
loki.process "embed_pod" {
 forward_to = [...]

 // For JSON logs
 stage.match {
 selector = "{} |~ \"^\\s*\\{\""
 stage.replace {
 expression = "\\}$"
 replace = ""
 }
 stage.template {
 source = "log_line"
 template = "{{ .Entry }},\"_pod\":\"{{ .pod }}\"}"
 }
 }

 // For text logs
 stage.match {
 selector = "{} !~ \"^\\s*\\{\""
 stage.template {
 source = "log_line"
 template = "{{ .Entry }} _pod={{ .pod }}"
 }
 }

 stage.output { source = "log_line" }
}

Result: ts=... msg="..." _pod=agent-logs-cqhfk

Query by aggregate (normal use):

logql
sum(count_over_time({workload="ReplicaSet/payment-api", level="error"}[1m]))

Query a specific pod (edge case debugging):

logql
{workload="ReplicaSet/payment-api", level="error"} |= `_pod=payment-api-3`
Method 2: stage.pack (JSON envelope)
alloy
loki.process "pack_pod" {
 forward_to = [...]
 stage.pack {
 labels = ["pod"]
 ingest_timestamp = false
 }
}

Packed result: {"_entry": "original log line", "pod": "agent-logs-cqhfk"}

Unpack at query time:

logql
{workload="ReplicaSet/payment-api", level="error"}
 |= `agent-logs-cqhfk`
 | unpack

Performance Bottleneck Diagnosis

When a user reports slow queries, identify where time is spent using Querier metrics.go logs.

Four Query Stages
StageMetricHigh Value MeansFix
Queuequeue_timeNot enough QueriersAdd Queriers or reduce parallelism
Indexchunk_refs_fetch_timeNeed more Index Gateway instancesScale index-gateways; check CPU
Storagestore_chunks_download_timeChunks too small OR storage bottleneckCheck avg chunk size: total_bytes / cache_chunk_req
Executionduration - chunk_refs_fetch_time - store_chunks_download_timeCPU-intensive regex, or too many tiny log linesReduce regex; add CPU; increase parallelism

Ideally, the majority of time is spent in Execution. If not, that indicates infrastructure or label design problems.

Checking Chunk Size
avg chunk size = total_bytes / cache_chunk_req

If the result is a few hundred bytes or kilobytes (instead of megabytes), chunks are too small. This means labels are over-splitting data into too many streams. Revisit cardinality — demote non-allowlisted high-card labels or stabilize protected-label values.

Problem: Query scans too many streams

  • Cause: High-cardinality labels exist but aren't specified in the query selector
  • Fix: Demote the label off the index after a migration check, or ensure queries always include it as a filter. Never demote allowlisted correlation labels — stabilize their values instead (protected-labels.md)

Problem: High post_filter_lines discard ratio (post_filter_lines << total_lines)

  • Cause: Insufficient label selectivity; query scans and discards most logs
  • Fix: Add labels matching user access patterns (level, workload, container, service_name)

Problem: Small chunks

  • Cause: Too many labels creating too many fine-grained streams
  • Fix: Demote high-cardinality non-allowlisted labels (e.g. pod) to consolidate streams; remediate protected-label values if they are the splitter
Query Optimization Quick Wins
  1. Add container or workload to narrow scope before line filters
  2. Add level label + always use it in queries (filters out 94%+ of logs when searching for errors)
  3. Demote pod off the index → reduces stream count by ~5× in typical K8s deployments (migrate selectors first)
  4. Replace regex line filters (|~) with exact filters (|=) where possible
  5. Keep service_name (and peers); if values are UUIDs/ephemeral, normalize to a stable identity — do not drop the key

Alloy / Agent Configuration Patterns

Normalize Log Level
alloy
loki.process "normalize_level" {
 forward_to = [...]
 stage.replace { source = "level"; expression = "(?i)I(nfo)?"; replace = "info" }
 stage.replace { source = "level"; expression = "(?i)W(arn(ing)?)?"; replace = "warn" }
 stage.replace { source = "level"; expression = "(?i)E(rr(or)?)?"; replace = "error" }
 stage.replace { source = "level"; expression = "(?i)D(ebug?)?"; replace = "debug" }
 stage.labels { values = { level = "" } }
}
Conditional Meta-Label Extraction
alloy
// Only extract when the relevant field is present — avoids unnecessary cardinality
loki.process "conditional_extraction" {
 forward_to = [...]
 stage.match {
 selector = "{app=\"loki\"} |= \"component\""
 stage.logfmt { mapping = { "component" = "" } }
 stage.labels { values = { component = "" } }
 }
}
Enforce Approved Label Set (always use as final stage)

Always include allowlisted correlation labels when present — never omit service_name, deployment_environment, or job from label_keep (protected-labels.md):

alloy
loki.process "enforce_labels" {
 forward_to = [loki.write.default.receiver]
 // ... other stages ...
 stage.label_keep {
 values = [
 "service_name", "deployment_environment", "job",
 "env", "cluster", "level", "namespace", "workload", "container",
 ]
 }
}
Soft Enforcement (inject "unknown" for missing labels)
alloy
stage.template {
 source = "team"
 template = "{{ if .Value }}{{ .Value }}{{ else }}unknown{{ end }}"
}
stage.labels { values = { team = "" } }

Log Line Optimization

Byte-level reductions (timestamps, ANSI, null JSON fields) for Scenario C savings — see references/log-line-optimization.md.


Security & LBAC

Grafana Enterprise Logs (GEL) supports Label-Based Access Control (LBAC). Any label can serve as an access control selector.

Best labels for LBAC:

  • classification — data sensitivity (public, restricted, confidential, top-secret)
  • source — controls which teams can see which log origins
  • team / squad — ownership-based access
  • env — environment-level restrictions

Static aggregate labels like owner=sysadmins or category=database are particularly effective: one label value gates access to many log files, rather than requiring a long allowlist of filenames or streams.


The 80/20 Rule

The most impactful improvements almost always come from these four changes:

  1. Demote pod off the index (structured metadata) — biggest stream reduction in K8s; migrate selectors first
  2. Add level as a label AND always specify it in queries — can eliminate 94%+ of scanned data when searching for errors
  3. Normalize label values — eliminates phantom duplicate streams from inconsistent casing; for service_name, stabilize UUID/ephemeral values (never drop the key)
  4. Normalize or demote filename in K8s — highly variable paths inflate stream count significantly

Focus on these before anything else. Never "fix" cardinality by dropping service_name, deployment_environment, or job.


Labels to Avoid — Quick Reference

LabelWhyAlternative
podTransient, high cardDemote: workload label + pod in structured metadata (migrate selectors)
user_idUnbounded — never valid as index labelKeep only in log content
request_id / trace_idUnbounded — never valid as index labelStructured metadata
filename (raw K8s path)Contains pod UIDNormalize or demote after selector check
Unnormalized levelINFO/info/Info = 3 streamsNormalize at collection time
UUID / ephemeral service_name valuesInflates streams; key is still requiredKeep key; map values to stable service identity
Any dynamically-named label keyCannot be boundedUse fixed keys with bounded values

Never drop: service_name, deployment_environment, job — see references/protected-labels.md.


Cost Impact Analysis

Label hygiene alone does not cut billable ingest bytes ($0 direct). Volume savings come from enabled stage.drop / log-line cleanup. Load references/cost-impact.md when writing the report section: use its scenario-card shape, cite scalar metrics (optional short panel ID / PromQL), and never paste the agent-only reference table or panel JSON into the customer report.

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/grafana-cloud/loki-label-analyzer of grafana/skills.

  • SKILL.md
  • references/cost-impact.md
  • references/disclaimer.md
  • references/log-line-optimization.md
  • references/protected-labels.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Loki Label Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Loki Label Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Loki Label Analyzer this skillgrafana/skills282—~5.4kAutomated safety check: PassApache-2.0
Mz Release SignoffMaterializeInc/materialize6.4k—~7.2kAutomated safety check: PassCustom licence
Axiom Dashboard Builderopenclaw/clawhub9.5k—~4.9kAutomated safety check: PassMIT
Happy Infra Metrics and Grafanaslopus/happy24k—~2kAutomated safety check: NotesMIT
Syncmetapawurb/hotpath-rs1.9k—~1.2kAutomated safety check: NotesMIT
Optimize Slurm TopologyNVlabs/alpasim1.3k—~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Mz Release Signoff

    MaterializeInc/materialize

    Verify a release candidate on the Grafana dashboards and sign off in release.

    6.4k GitHub stars~7.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Queries live Prometheus metrics and manages Grafana dashboards as code for Happy's infrastructure, using the grafanactl CLI and the Grafana datasource proxy API.

    24k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Syncmeta

    pawurb/hotpath-rs

    Sync changes from the hotpath, hotpath-macros and hotpath-drain crates to their meta counterparts (hotpath-meta, hotpath-macros-meta and hotpath-drain-meta).

    1.9k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Optimize AlpaSim Slurm topology throughput using persistent local Prometheus/Grafana telemetry and run artifacts.

    1.3k GitHub stars~1.6k tokensUpdated 21 days ago
    DevOps & CloudAuto-check passed
  • Specifies how to instrument an opik-backend pipeline with per-stage OpenTelemetry metrics for throughput, latency, errors and queue delay by workspace.

    22k GitHub stars~3.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    282 GitHub stars~678 tokensUpdated yesterday
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    282 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    282 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    282 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    282 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    282 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Loki Label Analyzer

What does Loki Label Analyzer do?

Expert evaluator for Grafana Loki label strategy. An agent skill from grafana/skills. Loki Label Analyzer is an agent skill from grafana/skills, published by the product's own GitHub organization. Expert evaluator for Grafana Loki label strategy.

When should I use Loki Label Analyzer?

Loki Label Analyzer fits situations like: the user asks to evaluate; improve a Loki label strategy —; asks why their Loki queries are slow.

How do I install Loki Label Analyzer in Claude Code?

Run `npx skills add grafana/skills --skill loki-label-analyzer -a claude-code`. Or copy the skill folder (skills/grafana-cloud/loki-label-analyzer in grafana/skills) into .claude/skills/loki-label-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Loki Label Analyzer in Codex?

Run `npx skills add grafana/skills --skill loki-label-analyzer -a codex`. Or copy the skill folder (skills/grafana-cloud/loki-label-analyzer in grafana/skills) into .agents/skills/loki-label-analyzer in your project. Codex loads it when a task matches its description.

Can I use Loki Label Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill loki-label-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/loki-label-analyzer, .gemini/skills/loki-label-analyzer, .github/skills/loki-label-analyzer and .opencode/skills/loki-label-analyzer in your project.

What does Loki Label Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Loki Label Analyzer is instructions for the agent only.

Does Loki Label Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Loki Label Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Loki Label Analyzer use?

Loki Label Analyzer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Loki Label Analyzer use?

About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Loki Label Analyzer?

Skills that share tags, products or a category with Loki Label Analyzer: Mz Release Signoff (MaterializeInc/materialize, 6.4k stars), Axiom Dashboard Builder (openclaw/clawhub, 9.5k stars), Happy Infra Metrics and Grafana (slopus/happy, 24k stars) and Syncmeta (pawurb/hotpath-rs, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Loki Label Analyzer?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.