All skills
google avatar

/cloud-logging-query-generation

@becc4b8
by googlegoogle/skills21k stars
1,698

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.

Use this Skill: https://skilld.dev/gh/google/skills/cloud-logging-query-generation

This session only. Nothing lands on disk.

referencesquery_compute_engine.md

≈4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Compute Engine (GCE) LQL queries

Table of contents

Base schema and structural patterns

Compute Engine logs are highly segmented depending on whether you are analyzing the VM's internal operating system, Google's infrastructure events, or user-driven API audit logs.

Core resource types

  • VM Instances (gce_instance): The most common resource type. Use this when analyzing a running VM (Guest OS), its boot console, or its lifecycle events.
  • Storage (gce_disk, gce_snapshot): Use for operations on persistent disks and snapshots.
  • Networking (gce_firewall_rule, gce_route, gce_network): Use for infrastructure-level network changes, NOT for traffic flow logs.
  • Groups (gce_instance_group, gce_instance_template): Use for Managed Instance Group (MIG) scaling, creation, and health checks.

Guest OS and application logs (Ops Agent)

When a user asks to search for "errors inside my VM", "syslog", "auth requests", or "app logs":

  • Target resource.type="gce_instance".
  • These are usually ingested via the Ops Agent.
  • Filter by log_id("syslog"), log_id("winevt.raw"), or the custom file log_id.
  • The raw log string is found in textPayload (unstructured) or jsonPayload (structured).

Boot and kernel logs (serial console)

When a VM is unbootable, crashing on startup, or experiencing kernel panics:

  • Target resource.type="gce_instance".
  • Filter by log_id("serialconsole.googleapis.com/serial_port_1_output").
  • Search within textPayload (for example, "kernel panic", "Out of memory").

Google infrastructure system events

When a VM is preempted, terminated by Google, or migrated during a host error:

  • Target resource.type="gce_instance".
  • Filter by log_id("cloudaudit.googleapis.com/system_event").
  • System events are NOT driven by users, so they are logged as system events. Use protoPayload.methodName (for example, "compute.instances.hostError", "compute.instances.preempted").

User activity audit logs

When a user asks "who deleted my VM", "who stopped the instance", or "when was this disk attached":

  • Target the relevant resource type (gce_instance, gce_disk, etc.).
  • Filter by log_id("cloudaudit.googleapis.com/activity").
  • Use protoPayload.methodName (for example, "v1.compute.instances.delete", "v1.compute.disks.attach").

Example queries

Activity audit logs for Compute Engine instances

Variables to replace: None

resource.type="gce_instance" AND
log_id("cloudaudit.googleapis.com/activity")

System logs (syslog) emitted by Compute Engine instances

Variables to replace: None

resource.type="gce_instance" AND
log_id("syslog")

Compute Engine firewall rule deletion

Variables to replace: None

resource.type="gce_firewall_rule" AND
log_id("cloudaudit.googleapis.com/activity") AND
SEARCH(protoPayload.methodName, "firewalls.delete")

Compute Engine VM authlogs

Variables to replace: None

resource.type="gce_instance" AND
log_id("authlog")

Compute Engine host error

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.serviceName="compute.googleapis.com" AND
(SEARCH(protoPayload.methodName, "compute.instances.hostError")
OR
operation.producer:"compute.instances.hostError") AND
log_id("cloudaudit.googleapis.com/system_event") AND
resource.labels.instance_id="<INSTANCE_ID>" AND
severity=INFO

Compute Engine host memory alert

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.serviceName="compute.googleapis.com" AND
(jsonPayload.methodName:"compute.instances.host_event_notify"
OR
operation.producer:"compute.instances.host_event_notify") AND
log_id("cloudaudit.googleapis.com/host_event_notify") AND
resource.labels.instance_id="<INSTANCE_ID>" AND
severity=CRITICAL

Compute Engine host migrated

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.serviceName="compute.googleapis.com" AND
(SEARCH(protoPayload.methodName, "compute.instances.migrateOnHostMaintenance")
OR
operation.producer:
"compute.instances.migrateOnHostMaintenance") AND
log_id("cloudaudit.googleapis.com/system_event") AND
resource.labels.instance_id="<INSTANCE_ID>" AND
severity=INFO

Compute Engine VM terminated/preempted

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.methodName=~"compute\.instances\.(guestTerminate|preempted)" AND
log_id("cloudaudit.googleapis.com/system_event") AND
resource.labels.instance_id="<INSTANCE_ID>"

Compute Engine VM terminated due to scratch disk creation failure

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.serviceName="compute.googleapis.com" AND
(protoPayload.methodName="compute.instances.scratchDiskCreationFailed"
OR
operation.producer:
"compute.instances.scratchDiskCreationFailed") AND
log_id("cloudaudit.googleapis.com/system_event") AND
resource.labels.instance_id="<INSTANCE_ID>" AND
severity=INFO

Compute Engine zone resource pool exhaustion (stockout)

Variables to replace: None

resource.type="gce_instance" AND
log_id("cloudaudit.googleapis.com/activity") AND
(protoPayload.methodName="v1.compute.instances.start" OR
protoPayload.methodName="v1.compute.instances.insert") AND
protoPayload.status.message=~"(ZONE_RESOURCE_POOL_EXHAUSTED|does not have enough resources|resource pool exhausted)" AND
severity>=WARNING

Compute Engine VM instance created

Variables to replace: <INSTANCE_NAME>

resource.type="gce_instance" AND
SEARCH(protoPayload.methodName, "compute.instances.insert") AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.request.name="<INSTANCE_NAME>"

Compute Engine VM instance deleted with name

Variables to replace: <INSTANCE_NAME>

resource.type="gce_instance" AND
SEARCH(protoPayload.methodName, "compute.instances.delete") AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.resourceName:"<INSTANCE_NAME>"

Compute Engine VM instance deleted with ID

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
SEARCH(protoPayload.methodName, "compute.instances.delete") AND
log_id("cloudaudit.googleapis.com/activity") AND
resource.labels.instance_id="<INSTANCE_ID>"

Compute Engine VM instance restarted

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.methodName=~"compute\.instances\.(start|stop|reset|automaticRestart|guestTerminate|instanceManagerHaltForRestart)" AND
(log_id("cloudaudit.googleapis.com/activity")
OR log_id("cloudaudit.googleapis.com/system_event")) AND
resource.labels.instance_id="<INSTANCE_ID>"

Compute Engine Shielded VM boot integrity failure

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
log_id("compute.googleapis.com/shielded_vm_integrity") AND
jsonPayload.earlyBootReportEvent.policyEvaluationPassed="false" AND
resource.labels.instance_id="<INSTANCE_ID>"

Compute Engine VM instance stopped by Guest OS

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
protoPayload.serviceName="compute.googleapis.com" AND
(SEARCH(protoPayload.methodName, "compute.instances.guestTerminate") OR
operation.producer:"compute.instances.guestTerminate") AND
log_id("cloudaudit.googleapis.com/system_event") AND
resource.labels.instance_id="<INSTANCE_ID>" AND
severity=INFO

Compute Engine Shielded VM boot file was blocked

Variables to replace: <INSTANCE_ID>

resource.type="gce_instance" AND
log_id("serialconsole.googleapis.com/serial_port_1_output") AND
textPayload:"Security Violation" AND
resource.labels.instance_id="<INSTANCE_ID>"

Persistent disk created

Variables to replace: <PERSISTENT_DISK_NAME>

resource.type="gce_disk" AND
SEARCH(protoPayload.methodName, "compute.disks.insert") AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.resourceName: "<PERSISTENT_DISK_NAME>"

Nodes added in sole-tenant node

Variables to replace: <NODE_GROUP_ID>

resource.type="gce_node_group" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName=~("compute.nodeGroups.addNodes"
OR "compute.nodeGroups.insert") AND
resource.labels.node_group_id="<NODE_GROUP_ID>" AND
severity=INFO

Autoscale events in sole-tenant node

Variables to replace: <NODE_GROUP_ID>

resource.type="gce_node_group" AND
log_id("cloudaudit.googleapis.com/system_event") AND
protoPayload.methodName=~("compute.nodeGroups.deleteNodes"
OR "compute.nodeGroups.addNodes") AND
resource.labels.node_group_id="<NODE_GROUP_ID>"

Manual snapshot taken

Variables to replace: <SNAPSHOT_NAME>

resource.type="gce_snapshot" AND
log_id("cloudaudit.googleapis.com/activity") AND
SEARCH(protoPayload.methodName, "compute.snapshots.insert") AND
protoPayload.resourceName:"<SNAPSHOT_NAME>"

Scheduled snapshot taken

Variables to replace: <PERSISTENT_DISK_NAME>

resource.type="gce_disk" AND
log_id("cloudaudit.googleapis.com/system_event") AND
protoPayload.methodName="ScheduledSnapshots" AND
protoPayload.response.operationType="createSnapshot" AND
protoPayload.response.targetLink="<PERSISTENT_DISK_NAME>"

Snapshot schedule created

Variables to replace: <SCHEDULE_NAME>

resource.type="gce_resource_policy" AND
log_id("cloudaudit.googleapis.com/activity") AND
SEARCH(protoPayload.methodName, "compute.resourcePolicies.insert") AND
protoPayload.request.name="<SCHEDULE_NAME>"

Snapshot schedule attached

Variables to replace: <PERSISTENT_DISK_NAME>, <SCHEDULE_NAME>

resource.type="gce_disk" AND
log_id("cloudaudit.googleapis.com/activity") AND
SEARCH(protoPayload.methodName, "compute.disks.addResourcePolicies") AND
protoPayload.request.resourcePolicys:"<SCHEDULE_NAME>" AND
protoPayload.resourceName:"<PERSISTENT_DISK_NAME>"

Quota exceeded

Variables to replace: None

resource.type="gce_instance" AND
SEARCH(protoPayload.methodName, "compute.instances.insert") AND
protoPayload.status.message:"QUOTA_EXCEEDED" AND
severity=ERROR

Query unhealthy instances in instance group

Variables to replace: <INSTANCE_GROUP_NAME>

resource.type="gce_instance_group" AND
resource.labels.instance_group_name="<INSTANCE_GROUP_NAME>" AND
jsonPayload.healthCheckProbeResult.healthState="UNHEALTHY"

Query instance group members within a time frame in UTC time format

Variables to replace: <END_TIME>, <INSTANCE_GROUP_NAME>, <START_TIME>

resource.type="gce_instance_group_manager" AND
resource.labels.instance_group_manager_name="<INSTANCE_GROUP_NAME>" AND
jsonPayload.@type=
"type.googleapis.com/compute.InstanceGroupManagerEvent" AND
jsonPayload.instanceHealthStateChange.detailedHealthState="HEALTHY" AND
timestamp >= "<START_TIME>" AND timestamp <= "<END_TIME>"

Instances added to instance group

Variables to replace: <INSTANCE_GROUP_NAME>

resource.type="gce_instance_group" AND
SEARCH(protoPayload.methodName, "compute.instanceGroups.addInstances") AND
log_id("cloudaudit.googleapis.com/activity") AND
resource.labels.instance_group_name="<INSTANCE_GROUP_NAME>"

Instances removed from instance group

Variables to replace: <INSTANCE_GROUP_NAME>

resource.type="gce_instance_group" AND
SEARCH(protoPayload.methodName, "compute.instanceGroups.removeInstances") AND
log_id("cloudaudit.googleapis.com/activity") AND
resource.labels.instance_group_name="<INSTANCE_GROUP_NAME>"

Instance template set or updated

Variables to replace: <INSTANCE_GROUP_MANAGER>

resource.type="gce_instance_group_manager" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName=
"v1.compute.instanceGroupManagers.setInstanceTemplate" AND
resource.labels.instance_group_manager_name="<INSTANCE_GROUP_MANAGER>"

Firewall logs

Variables to replace: <INSTANCE_NAME>

resource.type="gce_subnetwork" AND
log_id("compute.googleapis.com/firewall") AND
jsonPayload.instance.vm_name="<INSTANCE_NAME>"

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill is designed to generate Logging Query Language (LQL) queries for Google Cloud Logging from natural language input. It provides comprehensive reference guides, syntax rules, and examples for various Google Cloud services. No security issues were detected.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/cloud-logging-query-generation