
Find Traces
- 12 installs
- 59 repo stars
- Updated August 1, 2026
- axiomhq/cli
find-traces is a Claude skill that analyzes OpenTelemetry distributed traces stored in Axiom to find errors, latency issues and root causes via the Axiom CLI.
About
This skill analyzes OpenTelemetry distributed traces from Axiom to identify errors, latency issues and root causes. A developer uses it when investigating a trace ID, finding traces by criteria like errors, latency or service, or debugging distributed-system issues. It provides APL query templates for getting a trace by ID, finding error and slow traces, and critical-path analysis, plus an OTel field reference and guidance on correlating trace data back to source code.
- Analyzes OpenTelemetry distributed traces stored in Axiom
- Finds traces by ID, error, latency or service and does critical-path analysis
- Correlates trace data (scope.name, operation name) back to source code
Find Traces by the numbers
- 12 all-time installs (skills.sh)
- Ranked #383 of 550 CLI & Terminal skills by installs in the Skillselion catalog
- Data as of Aug 2, 2026 (Skillselion catalog sync)
find-traces capabilities & compatibility
requires an authenticated Axiom CLI/account
- Capabilities
- detect anomalies · explore dataset · axiom apl
- Works with
- datadog · grafana
- Use cases
- debugging · data analysis
- Runs
- Runs locally
- Pricing
- Bring your own API key
What find-traces says it does
Analyze OpenTelemetry distributed traces from Axiom. Use when investigating a trace ID, finding traces by criteria (errors, latency, service), or debugging distributed system issues.
OTel durations are in **nanoseconds**
npx skills add https://github.com/axiomhq/cli --skill find-tracesAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 12 |
|---|---|
| repo stars | ★ 59 |
| Last updated | August 1, 2026 |
| Repository | axiomhq/cli ↗ |
What it does
Investigate OpenTelemetry traces in Axiom to debug errors, latency and root causes in distributed systems.
Who is it for?
debugging errors, latency and root causes from OpenTelemetry traces stored in Axiom
Skip if: non-trace observability datasets or simple field lookups
When should I use this skill?
you are investigating a trace ID or finding traces by error, latency or service
What you get
Identified error and slow traces, critical-path spans and code locations behind distributed-system failures.
- error and slow trace listings
- critical-path span analysis
- code locations correlated to spans
By the numbers
- documents OTel duration conversions (1 s = 1,000,000,000 ns)
- includes an OTel field reference of ~10 fields
Files
Trace Analysis
Analyze OpenTelemetry distributed traces to identify errors, latency issues, and root causes.
Arguments
When invoked with a trace ID (e.g., /find-traces abc123...), it's available as $ARGUMENTS.
Trace Dataset Discovery
First, find trace datasets:
axiom dataset list -f jsonLook for datasets containing trace data (often named *traces*, *spans*, or otel-*).
Schema Discovery
Always verify field names first:
axiom query "['<trace-dataset>'] | getschema" --start-time -1hCommon Operations
Get Trace by ID
axiom query "['<dataset>']
| where trace_id == '<TRACE_ID>'
| sort by _time asc
| limit 100" --start-time -1h -f jsonFind Error Traces
axiom query "['<dataset>']
| where _time >= ago(1h)
| where error == true
| extend error = coalesce(ensure_field(\"error\", typeof(bool)), false)
| summarize
start_time = min(_time),
total_duration = max(duration),
span_count = count(),
error_count = countif(error),
services = make_set(['service.name']),
root_operation = arg_min(_time, name)
by trace_id
| sort by start_time desc
| limit 20" --start-time -1h -f jsonFind Slow Traces
axiom query "['<dataset>']
| where _time >= ago(1h)
| where duration >= 1000000000
| summarize
start_time = min(_time),
total_duration = max(duration),
span_count = count(),
services = make_set(['service.name'])
by trace_id
| sort by total_duration desc
| limit 20" --start-time -1h -f jsonFind Traces by Service
axiom query "['<dataset>']
| where _time >= ago(1h)
| where ['service.name'] == '<SERVICE>'
| summarize
start_time = min(_time),
total_duration = max(duration),
span_count = count(),
error_count = countif(error == true)
by trace_id
| sort by start_time desc
| limit 20" --start-time -1h -f jsonError Spans in Trace
axiom query "['<dataset>']
| where trace_id == '<TRACE_ID>'
| where error == true
| project _time, ['service.name'], name, duration, ['status.message']" --start-time -1h -f jsonCritical Path Analysis
axiom query "['<dataset>']
| where trace_id == '<TRACE_ID>'
| project span_id, parent_span_id, ['service.name'], name, duration, error
| sort by duration desc" --start-time -1h -f jsonOTel Field Reference
| Field | Bracket? | Description |
|---|---|---|
trace_id | No | 32-char trace identifier |
span_id | No | 16-char span identifier |
parent_span_id | No | Parent span (empty for root) |
name | No | Operation name |
duration | No | Duration in nanoseconds |
kind | No | CLIENT, SERVER, INTERNAL, PRODUCER, CONSUMER |
error | No | Boolean error flag |
['service.name'] | Yes | Service identifier |
['status.code'] | Yes | OK, ERROR, or nil |
['status.message'] | Yes | Error description |
['scope.name'] | Yes | Instrumentation library |
Duration Conversion
OTel durations are in nanoseconds:
| Human | Nanoseconds | Filter |
|---|---|---|
| 1 ms | 1,000,000 | duration >= 1000000 |
| 100 ms | 100,000,000 | duration >= 100000000 |
| 1 s | 1,000,000,000 | duration >= 1000000000 |
Convert for display:
| extend duration_ms = duration / 1000000.0Custom Attributes
Non-standard span attributes are stored in attributes.custom map:
// Filter by custom attribute
| where ['attributes.custom']['user_id'] == "123"
// Aggregation requires explicit cast
| summarize count() by tostring(['attributes.custom']['tenant'])Without tostring(), aggregations fail with "grouping by field of type unknown".
Codebase Correlation
When working in a repository that matches the traced service, correlate trace data with source code to identify root causes.
Mapping Trace Data to Code
1. Extract package/module path from `['scope.name']`
- Contains the instrumentation library or package path
- Strip the module prefix to get the local path
- Example:
github.com/org/repo/pkg/auth→pkg/auth
2. Find code from operation name
- The
namefield often contains function names or HTTP routes - Search the codebase for matching handlers, functions, or endpoints
3. Trace the call chain
- Follow parent-child span relationships
- Map each span to its corresponding code location
- Identify where errors originate and propagate
Note: Codebase correlation is optional. Proceed with trace-only analysis if code is unavailable or doesn't match the traced services.
Output Format
When analyzing a trace, provide:
## Trace Summary
- **Trace ID:** <id>
- **Duration:** <human-readable>
- **Services:** <list>
- **Outcome:** success/failure
## Sequence of Events
1. <Service> - <operation> (<duration>)
2. <Service> - <operation> (<duration>) ⚠️ ERROR
...
## Error Analysis
<What failed, when, why>
## Root Cause
<Deepest error and explanation>
## Codebase Locations (if applicable)
- **Service:** <service.name>
- **Package:** <scope.name>
- **Files:** <specific files to investigate>
## Recommended Actions
1. <Specific action>
2. <What to investigate next>When NOT to Use
- Metrics analysis: Traces are for request flow; use logs/metrics skills for aggregated performance data
- Non-OTel data: This skill assumes OpenTelemetry field conventions (trace_id, span_id, etc.)
- Known trace structure: If you already have the query, run it directly without invoking this skill
- Alerting on trace patterns: Use Axiom Monitors for continuous alerting
APL Reference
For query syntax, invoke the axiom-apl skill which provides trace analysis patterns and duration unit guidance.
Related skills
FAQ
What can find-traces do with a trace ID?
It can fetch all spans for a trace, list error spans, and run critical-path analysis sorted by span duration.
In what unit are OTel durations stored?
Nanoseconds; the skill documents conversions such as 1 ms = 1,000,000 and 1 s = 1,000,000,000.