cx-telemetry-querying
Use this skill for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior", "understand a production incident", "query telemetry data", "look at logs", "search logs", "find errors", "find stack traces", "filter by severity", "check traces", "examine spans", "investigate request latency", "debug service-to-service calls", "look up a trace ID", "analyze RUM data", "check frontend performance",
Security Assessment
About cx-telemetry-querying
This skill is the entry point for investigating, debugging, and answering data questions using Coralogix observability data through the cx CLI. It solves the routing problem of an incident or analysis question — deciding where the relevant signal lives across the four telemetry pillars (metrics, logs, traces/spans, and RUM) and which reference files to load before querying, so an agent can move efficiently from a vague symptom to a concrete query.
The skill provides a quick routing table mapping question types to a first-choice pillar and fallback, plus a discovery workflow for ambiguous cases that searches metrics, semantic log/span fields, and the codebase in parallel. It documents read-only cx commands — cx logs, cx spans, cx metrics, cx dataprime, cx search-fields — and emphasizes that all query commands are read-only and safe to run without confirmation. Companion references cover DataPrime syntax, PromQL guidelines, and per-pillar querying (logs, spans, metrics with instant vs. range queries and label discovery, and RUM fields), along with structured investigation workflows for HTTP errors, latency, and availability, plus retry logic and summarization guidance.
It targets SREs, platform engineers, and developers who use Coralogix and want an AI agent to drive telemetry investigations. Prerequisites include the cx CLI with a configured profile carrying a Coralogix API key or OAuth; the skill prompts the user to run cx profiles add when credentials are missing.
FAQ
Are the query commands safe to run?
Yes. The skill states that all query commands (cx logs, cx spans, cx metrics, cx dataprime, cx search-fields) are read-only and work in --read-only mode. They never modify data and can be run freely without --yes.
How does it decide which telemetry pillar to query?
It uses a quick routing table mapping question types (frontend errors, latency, service dependencies, stack traces, infrastructure health) to a first-choice pillar and fallback. For ambiguous questions it runs a discovery workflow searching metrics, log/span fields, and the codebase.
What credentials are required?
cx search-fields (and other commands) need a Coralogix API key or OAuth on the active profile. If credentials are missing, the skill prompts the user to run cx profiles add <name>.
What query languages does it use?
DataPrime for logs, spans, and RUM, and PromQL for metrics. Reference files (dataprime-reference.md, promql-guidelines.md) are loaded per pillar before querying.
How does it handle metric queries that return nothing?
It applies retry logic — broaden the name search, verify label names with get-labels, widen the time range or shorten the rate window, exclude empty labels, or try an alternative metric — up to a maximum of 5 attempts, each with a concrete improvement.
All Files
8 filesInstall cx-telemetry-querying
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
coralogix/cx-cli