
Log Analysis
- 26 installs
- 40 repo stars
- Updated August 4, 2026
- akillness/skills-template
Log Analysis is an agent skill that reads application and web-server logs to identify errors, performance issues, and security anomalies during debugging or incident response.
About
Log Analysis is a skill that inspects application and web-server logs to surface errors, slow requests, and anomalous access patterns. A developer uses it when debugging an issue, checking system health, or investigating an incident. It provides read-only grep and awk recipes for Apache, Nginx, application, and JSON log formats and a report template.
- Ready-made grep/awk recipes for Apache, Nginx, application, and JSON logs
- Covers error, performance, traffic, and security-pattern analysis
- Read-only by design with a fixed analysis-report output format
Log Analysis by the numbers
- 26 all-time installs (skills.sh)
- Ranked #376 of 596 Debugging skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
log-analysis capabilities & compatibility
- Capabilities
- log analysis · incident response · error debugging · pattern detection
- Use cases
- debugging · security audit
What log-analysis says it does
Analyze application logs to identify errors, performance issues, and security anomalies.
Handles various log formats including Apache, Nginx, application logs, and JSON logs.
Perform read-only operations only
npx skills add https://github.com/akillness/skills-template --skill log-analysisAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 26 |
|---|---|
| repo stars | ★ 40 |
| Last updated | August 4, 2026 |
| Repository | akillness/skills-template ↗ |
What it does
Grep and awk application, Nginx, and Apache logs to find errors, slow requests, and suspicious access during an incident.
Who is it for?
Debugging errors, investigating incidents, and spotting suspicious access in Apache/Nginx/application/JSON logs.
Skip if: Setting up monitoring/alerting infrastructure or modifying log files.
When should I use this skill?
You are debugging an issue, monitoring system health, or investigating an outage from existing log files.
What you get
A structured log-analysis report with error counts, patterns, and recommended actions.
- Log analysis report with summary, error table, and recommended actions
By the numbers
- 5-step analysis flow (locate, error, pattern, performance, security)
Files
Log Analysis
When to use this skill
- Error debugging: analyze the root cause of application errors
- Performance analysis: analyze response times and throughput
- Security audit: detect anomalous access patterns
- Incident response: investigate the root cause during an outage
Instructions
Step 1: Locate Log Files
# Common log locations
/var/log/ # System logs
/var/log/nginx/ # Nginx logs
/var/log/apache2/ # Apache logs
./logs/ # Application logsStep 2: Search for Error Patterns
Common error search:
# Search ERROR-level logs
grep -i "error\|exception\|fail" application.log
# Recent errors (last 100 lines)
tail -100 application.log | grep -i error
# Errors with timestamps
grep -E "^\[.*ERROR" application.logHTTP error codes:
# 5xx server errors
grep -E "HTTP/[0-9.]+ 5[0-9]{2}" access.log
# 4xx client errors
grep -E "HTTP/[0-9.]+ 4[0-9]{2}" access.log
# Specific error code
grep "HTTP/1.1\" 500" access.logStep 3: Pattern Analysis
Time-based analysis:
# Error count by time window
grep -i error application.log | cut -d' ' -f1,2 | sort | uniq -c | sort -rn
# Logs for a specific time window
grep "2025-01-05 14:" application.logIP-based analysis:
# Request count by IP
awk '{print $1}' access.log | sort | uniq -c | sort -rn | head -20
# Activity for a specific IP
grep "192.168.1.100" access.logStep 4: Performance Analysis
Response time analysis:
# Extract response times from Nginx logs
awk '{print $NF}' access.log | sort -n | tail -20
# Slow requests (>= 1 second)
awk '$NF > 1.0 {print $0}' access.logTraffic volume analysis:
# Requests per minute
awk '{print $4}' access.log | cut -d: -f1,2,3 | uniq -c
# Requests per endpoint
awk '{print $7}' access.log | sort | uniq -c | sort -rn | head -20Step 5: Security Analysis
Suspicious patterns:
# SQL injection attempts
grep -iE "(union|select|insert|update|delete|drop).*--" access.log
# XSS attempts
grep -iE "<script|javascript:|onerror=" access.log
# Directory traversal
grep -E "\.\./" access.log
# Brute force attack
grep -E "POST.*/login" access.log | awk '{print $1}' | sort | uniq -c | sort -rnOutput format
Analysis report structure
# Log analysis report
## Summary
- Analysis window: YYYY-MM-DD HH:MM ~ YYYY-MM-DD HH:MM
- Total log lines: X,XXX
- Error count: XXX
- Warning count: XXX
## Error analysis
| Error type | Occurrences | Last seen |
|----------|-----------|----------|
| Error A | 150 | 2025-01-05 14:30 |
| Error B | 45 | 2025-01-05 14:25 |
## Recommended actions
1. [Action 1]
2. [Action 2]Best practices
1. Set time range: clearly define the time window to analyze 2. Save patterns: script common grep patterns 3. Check context: review logs around the error too (-A, -B options) 4. Log rotation: search compressed logs with zgrep as well
Constraints
Required Rules (MUST)
1. Perform read-only operations only 2. Mask sensitive information (passwords, tokens)
Prohibited (MUST NOT)
1. Do not modify log files 2. Do not expose sensitive information externally
References
Examples
Example 1: Basic usage
<!-- Add example content here -->
Example 2: Advanced usage
<!-- Add advanced example content here -->
N:log-analysis
D:Analyze application logs to identify errors, performance issues, and security anomalies. Use when...
G:logs analysis debugging monitoring grep
U[4]:
**Error debugging**: analyze the root cause of application errors
**Performance analysis**: analyze response times and throughput
**Security audit**: detect anomalous access patterns
**Incident response**: investigate the root cause during an outage
S[5]{n,action}:
1,Locate Log Files
2,Search for Error Patterns
3,Pattern Analysis
4,Performance Analysis
5,Security Analysis
Related skills
FAQ
Which log formats does it handle?
Apache, Nginx, generic application logs, and JSON logs.
Does it modify log files?
No, it performs read-only operations only and must not modify log files.