Log Dive for Openclaw

A unified log search engine that translates natural language queries into LogQL, ES DSL, or CloudWatch filter patterns across multiple backends.

tkuehnl
v0.1.3
Feb 22, 2026
0
1.7k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install log-dive

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install log-dive using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Log Dive?

Log Dive is a powerful observability tool designed to bridge the gap between complex log management systems and natural language interaction. By integrating directly with popular backends like Loki, Elasticsearch/OpenSearch, and AWS CloudWatch, this skill allows developers and SREs to query logs using plain English. It acts as an intelligent translation layer that converts user intent into high-performance technical queries.

As a core component of the Openclaw Skills ecosystem, Log Dive prioritizes security and efficiency. It operates on a read-only basis, ensuring that sensitive log data is never modified or deleted. The skill is specifically architected to handle incident response, performance monitoring, and cross-service correlation without requiring the user to master multiple query languages like LogQL or Elasticsearch Query DSL.

Log Dive Use Cases

  • Rapid incident triage by identifying unique error types and building chronological timelines of failures across services.
  • Performance investigation to find slow requests, database connection pool exhaustion, or downstream service timeouts.
  • Deployment verification by comparing error rates and log patterns before and after a release to flag new issues.
  • Discovery of available log sources, including Loki labels, Elasticsearch indices, and AWS CloudWatch log groups.

How Log Dive Works

  1. The skill first checks for configured backends by verifying environment variables for Loki, Elasticsearch, or AWS.
  2. When a user provides a natural language prompt, the agent translates it into the appropriate backend-specific query syntax.
  3. The skill optionally performs target discovery to identify the correct log groups, indices, or labels for the requested context.
  4. Search or tail commands are executed via localized scripts, retrieving a filtered subset of relevant log entries.
  5. The agent analyzes the raw output to identify error patterns, correlate events across services, and present a structured summary rather than a raw data dump.

Log Dive Setup

To get started with these Openclaw Skills, ensure your environment variables are configured for your specific backends:

# For Loki
export LOKI_ADDR="http://loki.internal:3100"

# For Elasticsearch
export ELASTICSEARCH_URL="https://es.internal:9200"

# For AWS CloudWatch
export AWS_REGION="us-east-1"

You must also have the following CLI tools installed: logcli, aws, curl, and jq. Verify your setup by running the backends check script: bash scripts/log-dive.sh backends.

Log Dive Data Schema & Taxonomy

Log Dive organizes log data and metadata into a structured format for analysis. The following table describes how results are presented:

Component Description
Backend Metadata Identifies the source (e.g., Loki) and the exact query used for transparency.
Error Summary Table A grouped view of error types, occurrence counts, and time range details.
Root Cause Analysis A numbered list providing a logical sequence of events and dependency chains.
Action Items Recommended next steps based on the patterns identified in the logs.

Log Dive Advanced Features

  • Multi-Backend Dispatcher: Search across all configured log sources with a single natural language command.
  • Live Tail Support: Stream live logs for a limited duration to observe real-time system behavior during incidents.
  • Discord v2 Delivery: Optimized for team communication with compact summaries and interactive components for incident response.
  • Intelligent Analysis: Automatically groups similar stack traces and identifies earliest failure points in a request chain.

SKILL.md


Loading

Related Openclaw Skills

Featured*