Agent skill

Analyze Dotnet Agent Logs

by newrelic in newrelic/newrelic-dotnet-agent

Parse and diagnose New Relic .NET agent logs (newrelicagent.log) and profiler logs (NewRelic.Profiler.<pid.log) from a support ticket.

Apache-2.0Auto-check passedSales & Support

Install Analyze Dotnet Agent Logs

skills CLI
$ npx skills add newrelic/newrelic-dotnet-agent --skill analyze-dotnet-agent-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install newrelic/newrelic-dotnet-agent analyze-dotnet-agent-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/newrelic/newrelic-dotnet-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/analyze-dotnet-agent-logs .claude/skills/analyze-dotnet-agent-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyze-dotnet-agent-logs
GitHub stars
117
Token cost
~1.5k tokens
SKILL.md length
815 words
Files
8 (incl. scripts, references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Parse and diagnose New Relic .NET agent logs (newrelicagent.log) and profiler logs (NewRelic.Profiler.<pid.log) from a support ticket.

  • Works in 7 steps: Inventory. Run nrlog.py sessions on the… → Pick the session. Show the rows. When… → Slim it. Run nrlog.py extract --session… → …
  • Handed a log file
  • SKILL.md covers Hard rules, Workflow, The script and Changing this skill, plus 1 more section
  • Runs Python scripts from its folder; calls python

What it does

Analyze Dotnet Agent Logs is an agent skill from newrelic/newrelic-dotnet-agent. Parse and diagnose New Relic .NET agent logs (newrelicagent.log) and profiler logs (NewRelic.Profiler.<pid.log) from a support ticket. Use when handed a log file or a logs directory, or when asked why the agent is not reporting, not connecting, not instrumenting a library, or why custom instrumentation XML has no effect.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/collector-protocol.md`, `references/log-formats.md` and `references/playbooks.md`).

It sits in Sales & Support, covering Performance optimization and Customer support. It works with New Relic and .NET. The repository describes itself as: The New Relic .NET language agent. The licence is Apache-2.0.

When your agent uses it

  • Handed a log file
  • A logs directory
  • Asked why the agent is not reporting
  • Not instrumenting a library

Example prompts

  • “/analyze-dotnet-agent-logs”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Inventory. Run nrlog.py sessions on the file or directory. It
  2. Pick the session. Show the rows. When more than one session is in scope,
  3. Slim it. Run nrlog.py extract --session N. Read the slim file
  4. Read the level from the counts, not the banner. extract prints both
  5. Correlate the profiler. Point nrlog.py profiler at the directory
  6. Route. Take the engineer's symptom to
  7. Report. Short verdict in chat with the evidence lines quoted verbatim.

What it can do on your machine

Read from SKILL.md and the folder at commit aca7658. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyze Dotnet Agent Logs loads about 1.5k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 815 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from newrelic/newrelic-dotnet-agent at commit aca7658, republished under its Apache-2.0 licence (© newrelic). 815 words, ~1,469 tokens.

Download SKILL.mdSave it as .claude/skills/analyze-dotnet-agent-logs/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
analyze-dotnet-agent-logs
description
Parse and diagnose New Relic .NET agent logs (newrelic_agent_*.log) and profiler logs (NewRelic.Profiler.<pid>.log) from a support ticket. Use when handed a log file or a logs directory, or when asked why the agent is not reporting, not connecting, not instrumenting a library, or why custom instrumentation XML has no effect.

Analyze .NET agent logs

A support log is evidence, not prose. It is large, it holds more than one agent run, and it is written by a process you cannot interview. Work it in this order.

Hard rules

  • Work only from a slim file. nrlog.py extract writes one; every later step reads that.
  • Never Read, tail, or wide-grep a raw log. A customer log runs to hundreds of MB with single lines tens of KB wide, and those bytes stay in context for the rest of the session.
  • Lead with counts. sessions, payloads, and profiler all answer in summary form. Reach for a body only when a count has told you which body.
  • Keep analysis local. Log content goes to no artifact, no ticket comment, and no web request unless the engineer asks for that in the moment, and then only from a slim file.
  • Delegate to a subagent when the source file exceeds 50 MB, or when the answer needs a sweep across many sessions or many files. Give the subagent the exact question and the exact commands, and require a verdict back, not log content.

Workflow

  1. Inventory. Run nrlog.py sessions <path> on the file or directory. It accepts a rolled set and merges a run that spans siblings. A customer dump holds dozens of applications, so above 40 sessions it prints a per-file summary instead: pick a file with --file <name>, then add --all.
  2. Pick the session. Show the rows. When more than one session is in scope, ask the engineer which one before going further. A support question is almost always about one run, and the wrong run wastes the whole analysis. Session numbers are relative to the --file filter, so pass the same --file to every later command.
  3. Slim it. Run nrlog.py extract <path> --session N. Read the slim file from here on. When it reports more than a few MB, narrow with --level, --since, --until, or --grep and extract again. A 7-hour FINEST session slims to 125 MB, which is no more readable than the original.
  4. Read the level from the counts, not the banner. extract prints both stated log level and observed levels. They disagree whenever the level changed at runtime, which the agent records as The log level was updated to {new} from {previous}. Trust the observed counts. The level bounds every conclusion: INFO hides all collector payloads, and FINEST is the only level that shows a skipped wrapper.
  5. Correlate the profiler. Point nrlog.py profiler at the directory first. A dump routinely holds thousands of profiler logs, so above 8 files it groups them by signature: most are processes the .NET Framework allow-list rejected, which is expected noise, and the group carrying initialized is the short list worth reading. Then match one NewRelic.Profiler.<pid>.log to the session by pid and overlapping UTC range. When the ranges do not overlap the pid was reused and the files are unrelated, so say that rather than pairing them.
  6. Route. Take the engineer's symptom to references/playbooks.md. Answer from the slim file when no playbook fits.
  7. Report. Short verdict in chat with the evidence lines quoted verbatim. Long form to a markdown file beside the slim file. A ticket-ready block only when the engineer asks.

Every verdict names its evidence and its limit. "Consistent with X; not proven, because that path logs nothing" is a finished answer. A guess dressed as a finding is not.

Show full SKILL.md (242 more words)Show less

The script

scripts/nrlog.py, Python 3 standard library only. Run --help for flags.

CommandUse it to
sessionsList runs in a file or directory, with truncation and interleaving flags
extractWrite the slim, redacted, payload-stripped file for one session
payloadsIndex collector calls: time, endpoint, direction, size, status, request guid
bodyPrint one request or response body, so a payload enters context on purpose
decodeTurn a base64 distributed-trace payload into JSON
profilerSummarize a profiler log: init, config, extensions, XML failures, method count
instrumentedList the methods the profiler rewrote, for checking custom instrumentation

Launcher: python on Windows, python3 elsewhere.

Derived files land in nrlog-work/ beside the source log unless --out says otherwise. The source log is never modified.

Changing this skill

Regenerate the fixtures and re-run the checks before trusting an edit to nrlog.py:

python tests/make_fixtures.py && python tests/make_merge_fixtures.py

They cover a restart, a rolled sibling, a truncated session, interleaved pids, one pid hosting three app domains, a runtime level change, DEBUG payload lines, exception continuation lines, and a planted license key for the redaction check. Generated fixtures are gitignored.

References

  • references/log-formats.md - line layouts, level names, session identity, what each file is named and where it lives. Read before hand-parsing anything the script does not cover.
  • references/collector-protocol.md - endpoints, the healthy call sequence, connect request and response fields, positional array keys. Read when interpreting a payload or a response.
  • references/playbooks.md - eight symptoms, each with its verified signature, its verdict, and the next ask for the customer.

© newrelic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in .claude/skills/analyze-dotnet-agent-logs of newrelic/newrelic-dotnet-agent.

  • SKILL.md
  • references/collector-protocol.md
  • references/log-formats.md
  • references/playbooks.md
  • scripts/nrlog.py
  • tests/.gitignore
  • tests/make_fixtures.py
  • tests/make_merge_fixtures.py

Open the folder on GitHubat commit aca7658

Compare with similar skills

Analyze Dotnet Agent Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyze Dotnet Agent Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyze Dotnet Agent Logs this skillnewrelic/newrelic-dotnet-agent117—~1.5kAutomated safety check: PassApache-2.0
Analyzing .NET Performancedotnet/skills5.6k3 repos~3.1kAutomated safety check: PassMIT
MAUI PR Performance Analysisdotnet/maui23k—~2.4kAutomated safety check: PassMIT
.NET Trimming and Native AOTAaronontheweb/dotnet-skills1.2k—~2.9kAutomated safety check: PassMIT
Dotnet Debuggingnovotnyllc/dotnet-artisan232—~2.1kAutomated safety check: PassMIT
Asynkron Profilermanagedcode/dotnet-skills486—~1.7kAutomated safety check: PassMIT

Similar skills

  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    DevelopmentAuto-check passed
  • Official

    Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.

    23k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • .NET Trimming and Native AOT

    Aaronontheweb/dotnet-skills

    Guides making .NET libraries trimming-safe and Native-AOT compatible: the MSBuild properties, trimming attributes, warning codes and a playbook of safe patterns.

    1.2k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    232 GitHub stars~2.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Pyroscope

    grafana/skills

    Official

    Continuously profile applications with Grafana Pyroscope and read the result as flame graphs.

    282 GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from newrelic/newrelic-dotnet-agent

  • Angler Dotnet Release

    newrelic/newrelic-dotnet-agent

    Open an Angler PR that adds the latest .NET agent release to metricnames.txt.

    117 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Build Dotnet Agent

    newrelic/newrelic-dotnet-agent

    Build the New Relic .NET agent locally and validate that code changes compile.

    117 GitHub stars~871 tokensUpdated today
    Auto-check passed
  • Run Integration Tests

    newrelic/newrelic-dotnet-agent

    Run the New Relic .NET agent integration tests locally. An agent skill from newrelic/newrelic-dotnet-agent.

    117 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Update Dotty Docs

    newrelic/newrelic-dotnet-agent

    A skill your agent uses when the user mentions a Dotty PR, dotty (package/dependency) updates, or asks to update the .NET agent compatibility docs / net-agent-compatibility-requirements after tested…

    117 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Dotnet Unit Test Coverage

    newrelic/newrelic-dotnet-agent

    Mandatory unit-test and code-coverage rules for the .NET agent.

    117 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Triage Integration Test Failures

    newrelic/newrelic-dotnet-agent

    A skill your agent uses when a CI integration, unbounded, or container test job fails intermittently, passes on a rerun, fails identically across every matrix variant, or shows an infra-shaped error…

    117 GitHub stars~2.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Analyze Dotnet Agent Logs

What does Analyze Dotnet Agent Logs do?

Parse and diagnose New Relic .NET agent logs (newrelicagent.log) and profiler logs (NewRelic.Profiler.<pid.log) from a support ticket. Analyze Dotnet Agent Logs is an agent skill from newrelic/newrelic-dotnet-agent.log) from a support ticket.

When should I use Analyze Dotnet Agent Logs?

Analyze Dotnet Agent Logs fits situations like: handed a log file; A logs directory; asked why the agent is not reporting; not instrumenting a library.

How do I install Analyze Dotnet Agent Logs in Claude Code?

Run `npx skills add newrelic/newrelic-dotnet-agent --skill analyze-dotnet-agent-logs -a claude-code`. Or copy the skill folder (.claude/skills/analyze-dotnet-agent-logs in newrelic/newrelic-dotnet-agent) into .claude/skills/analyze-dotnet-agent-logs in your project. Claude Code loads it when a task matches its description.

How do I install Analyze Dotnet Agent Logs in Codex?

Run `npx skills add newrelic/newrelic-dotnet-agent --skill analyze-dotnet-agent-logs -a codex`. Or copy the skill folder (.claude/skills/analyze-dotnet-agent-logs in newrelic/newrelic-dotnet-agent) into .agents/skills/analyze-dotnet-agent-logs in your project. Codex loads it when a task matches its description.

Can I use Analyze Dotnet Agent Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add newrelic/newrelic-dotnet-agent --skill analyze-dotnet-agent-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyze-dotnet-agent-logs, .gemini/skills/analyze-dotnet-agent-logs, .github/skills/analyze-dotnet-agent-logs and .opencode/skills/analyze-dotnet-agent-logs in your project.

What does Analyze Dotnet Agent Logs need to run?

Going by SKILL.md and its folder, Analyze Dotnet Agent Logs needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Analyze Dotnet Agent Logs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyze Dotnet Agent Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyze Dotnet Agent Logs use?

Analyze Dotnet Agent Logs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyze Dotnet Agent Logs use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.9k tokens, read only when the agent opens those files.

What are the alternatives to Analyze Dotnet Agent Logs?

Skills that share tags, products or a category with Analyze Dotnet Agent Logs: Analyzing .NET Performance (dotnet/skills, 5.6k stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars), .NET Trimming and Native AOT (Aaronontheweb/dotnet-skills, 1.2k stars) and Dotnet Debugging (novotnyllc/dotnet-artisan, 232 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyze Dotnet Agent Logs?

newrelic (a GitHub organization) maintains it in newrelic/newrelic-dotnet-agent, which has 117 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.

Source: newrelic/newrelic-dotnet-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.