All skills
google avatar

/cloud-logging-query-generation

@becc4b8
by googlegoogle/skills21k stars
1,698

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.

Use this Skill: https://skilld.dev/gh/google/skills/cloud-logging-query-generation

This session only. Nothing lands on disk.

referencesquery_cloud_storage.md

≈494 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cloud Storage (GCS) LQL queries

Base schema and structural patterns

Google Cloud Storage (GCS) telemetry is entirely driven by Cloud Audit Logs. GCS utilizes Audit Logs to track everything from bucket provisioning (administrative) to file downloads (data access).

Core resource type

  • Buckets (gcs_bucket): All GCS logs are bound to the bucket resource type. Filter explicitly using resource.labels.bucket_name="<BUCKET_NAME>" to scope queries to a specific bucket.

Audit log routing

GCS logs split cleanly along the standard Cloud Audit Log paradigm:

  • Admin Activity: Use log_id("cloudaudit.googleapis.com/activity") to query control-plane mutations. This captures administrative operations like storage.buckets.create, storage.buckets.delete, and IAM policy modifications.
  • Data Access: Use log_id("cloudaudit.googleapis.com/data_access") to query object-level file interactions, like file uploads (storage.objects.create) or file reads (storage.objects.get).

Operation targeting

  • Combine resource isolation with protoPayload.methodName (for example: protoPayload.methodName="storage.objects.delete") to locate precise user or system actions.

Example queries

All audit logs for GCS buckets

Variables to replace: None

resource.type="gcs_bucket" AND
logName:"cloudaudit.googleapis.com"

GCS bucket deletion logs

Variables to replace: None

resource.type="gcs_bucket" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="storage.buckets.delete"

GCS bucket logs

Variables to replace: <BUCKET_NAME>

resource.type="gcs_bucket" AND
resource.labels.bucket_name="<BUCKET_NAME>"

GCS bucket creation logs

Variables to replace: None

resource.type="gcs_bucket" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="storage.buckets.create"

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill is designed to generate Logging Query Language (LQL) queries for Google Cloud Logging from natural language input. It provides comprehensive reference guides, syntax rules, and examples for various Google Cloud services. No security issues were detected.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/cloud-logging-query-generation