Back to Skills

dt-obs-logs

Log querying, filtering, pattern analysis, and error rate calculation. Use when searching application or infrastructure logs, analyzing error patterns, or correlating log data. Trigger: "show error logs", "search logs for keyword", "log error rate", "recent errors", "logs from last hour", "find log entries", "top error messages", "log patterns", "parse JSON logs", "logs by process group", "log trends over time", "log entry counts per minute". Do NOT use for explaining existing queries, product d

120stars26forksUpdated 8/13/2026

Security Assessment

Safe(95/100)
Security Score95/100

About dt-obs-logs

The dt-obs-logs skill equips an agent to query, filter, and analyze Dynatrace log data using DQL (Dynatrace Query Language) for troubleshooting and monitoring. It addresses the common need to turn natural-language requests like "show error logs from the last hour" or "top error messages" into correct DQL, covering the log data model (timestamp, content, status, process-group fields) and the query patterns that fetch, filter, and aggregate logs.

The skill documents core workflows for log searching, multi-criteria filtering, and pattern analysis, each with typical steps and worked DQL examples. It explains key functions for filtering (filter status, in(), contains(), matchesPhrase()), entity operations (resolving process-group IDs to human-readable names), aggregation (count(), countIf(), by:{}, bin() time bucketing), and field operations (fields, fieldsAdd, conditional if()). It provides ready patterns for content search, error-rate calculation over time buckets, finding the most common errors, process-group-specific filtering, and parsing structured JSON log lines with parse content, "JSON:log". A cross-source note points to a topology-navigation reference when logs must be joined with host attributes.

It targets Dynatrace users — SREs, platform and application engineers, and support staff — who investigate incidents through logs. Use it for finding specific entries, calculating error rates, identifying recurring error patterns, analyzing trends over time, and parsing JSON-formatted logs. The skill is read-only query guidance and explicitly excludes explaining existing queries, product documentation questions, and tracing/span analysis.

FAQ

What query language does this skill use?

Dynatrace Query Language (DQL). The primary command is fetch logs, with time windows expressed as from:now() - <duration>, followed by filter, summarize, and field pipeline stages.

Can it calculate error rates?

Yes. It provides a pattern that buckets logs by time with bin(timestamp, 5m), counts total and error logs with count() and countIf(), and computes error_rate as a percentage.

How does it search log message content?

Use contains(content, "keyword") for simple substring search or matchesPhrase(content, "exact phrase") for full-text phrase search.

When should I not use this skill?

Do not use it for explaining existing queries, product documentation questions, or distributed tracing / span analysis (that is covered by dt-obs-tracing). For joining logs with host attributes, also consult the smartscape topology-navigation reference.

Can it parse structured logs?

Yes. It uses parse content, "JSON:log" to extract fields from JSON-formatted log lines, then references parsed fields (e.g. log[level], log[msg]) for filtering and aggregation.

Install dt-obs-logs

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill