All skills
google avatar

/cloud-logging-query-generation

@becc4b8
by googlegoogle/skills21k stars
1,698

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.

Use this Skill: https://skilld.dev/gh/google/skills/cloud-logging-query-generation

This session only. Nothing lands on disk.

referencesquery_bigquery.md

≈1.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

BigQuery LQL queries

Table of contents

Base schema and structural patterns

BigQuery telemetry fundamentally operates through Google Cloud Audit Logs. Unlike standard application logs, BigQuery execution telemetry relies on protoPayload.metadata structures rather than jsonPayload.

Core resource types

  • Projects (bigquery_project): The high-level anchor. This captures top-level job operations, project-wide auditing, and overarching query telemetry.
  • Datasets (bigquery_dataset): Captures table/data access operations and dataset configuration telemetry.
  • Data Transfer Service (bigquery_dts_run, bigquery_dts_config): Captures telemetry for scheduled data movement pipelines.

The metadata abstraction

When searching for "query execution", "query costs", "bytes billed", or "table data access", you must target the metadata object within the Audit Log protoPayload. Do NOT use jsonPayload or textPayload for BigQuery execution tracking.

  • Targeting Jobs / Executions: Search within protoPayload.metadata.jobChange.job (for example: protoPayload.metadata.jobChange.job.jobStats.queryStats.totalBilledBytes).
  • Targeting Data Reads: Search within protoPayload.metadata.tableDataRead.
  • Targeting Identity: All actors issuing BigQuery jobs will be recorded in protoPayload.authenticationInfo.principalEmail.

Example queries

BigQuery audit logs related to datasets or projects

Variables to replace: None

resource.type=("bigquery_dataset" OR "bigquery_project")
logName:"cloudaudit.googleapis.com"

Logs for queries that billed more than 1GB (1073741824 bytes)

Variables to replace: None

resource.type="bigquery_project"
protoPayload.metadata.jobChange.job.jobStats.queryStats.totalBilledBytes > 1073741824

BigQuery audit logs for a project

Variables to replace: None

resource.type="bigquery_project" AND
logName:"cloudaudit.googleapis.com"

BigQuery audit logs for a dataset

Variables to replace: None

resource.type="bigquery_dataset" AND
logName:"cloudaudit.googleapis.com"

BigQuery audit logs for BI Engine model

Variables to replace: None

resource.type="bigquery_biengine_model" AND
logName:"cloudaudit.googleapis.com"

BigQuery audit logs for a Data Transfer Service run.

Variables to replace: None

resource.type="bigquery_dts_run" AND
logName:"cloudaudit.googleapis.com"

BigQuery audit logs for a Data Transfer Service configuration.

Variables to replace: None

resource.type="bigquery_dts_config" AND
logName:"cloudaudit.googleapis.com"

BigQuery Data Transfer Service jobs

Variables to replace: None

resource.type="bigquery_project" AND
protoPayload.requestMetadata.callerSuppliedUserAgent=
"BigQuery Data Transfer Service" AND
protoPayload.methodName=("google.cloud.bigquery.v2.JobService.InsertJob" OR
"google.cloud.bigquery.v2.JobService.Query")

BigQuery transfer run logs

Variables to replace: <CONFIG_ID>, <RUN_ID>

resource.type="bigquery_dts_config" AND
labels.run_id="<RUN_ID>" AND
resource.labels.config_id="<CONFIG_ID>"

BigQuery dataset updates

Variables to replace: None

resource.type="bigquery_dataset" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="google.cloud.bigquery.v2.DatasetService.UpdateDataset"

BigQuery jobs completed

Variables to replace: None

resource.type="bigquery_project" AND
log_id("cloudaudit.googleapis.com/data_access") AND
protoPayload.methodName=("google.cloud.bigquery.v2.JobService.InsertJob"
OR "google.cloud.bigquery.v2.JobService.Query")

BigQuery quota exceeded

Variables to replace: None

resource.type=("bigquery_dataset" OR "bigquery_project")
AND
protoPayload.status.code=8 AND
severity>=WARNING

BigQuery query started

Variables to replace: None

resource.type="bigquery_project" AND
protoPayload.metadata.jobInsertion.reason:*

BigQuery concurrent load/extract jobs

Variables to replace: None

resource.type="bigquery_resource" AND
protoPayload.methodName="jobservice.insert" AND
protoPayload.serviceData.jobInsertRequest.resource.jobConfiguration.query.query:
"extract"

BigQuery audit logs for row access policy

Variables to replace: None

resource.type="bigquery_resource" AND
protoPayload.methodName="jobservice.insert" AND
protoPayload.serviceData.jobInsertRequest.resource.jobConfiguration.query.query:"ROW ACCESS POLICY"

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill is designed to generate Logging Query Language (LQL) queries for Google Cloud Logging from natural language input. It provides comprehensive reference guides, syntax rules, and examples for various Google Cloud services. No security issues were detected.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/cloud-logging-query-generation