Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
coralogix avatar

Cx Telemetry Querying

  • 1.8k installs
  • 113 repo stars
  • Updated August 4, 2026
  • coralogix/cx-cli

cx-telemetry-querying routes Coralogix investigations to the right telemetry pillar with cx CLI and reference-guided queries.

About

The cx-telemetry-querying skill is the entry point for Coralogix investigations deciding whether signal lives in logs, metrics, traces, or RUM before querying. Quick routing sends frontend errors to RUM, endpoint latency to metrics, service dependencies to traces, stack traces to logs, and infrastructure health to metrics alone. Ambiguous business questions follow a discovery workflow: search metrics by name, search-fields on logs and spans semantically, optionally search the codebase for metric registration or span attributes, then load pillar-specific references. Reference loading pairs dataprime-reference with logs-querying or spans-querying, promql-guidelines with metrics-querying, and adds rum-fields for frontend RUM. All cx logs, spans, metrics, dataprime, and search-fields commands are read-only and safe without --yes. search-fields needs Coralogix API key or OAuth on the active profile via cx profiles add. Fallback guidance pivots pillars when initial queries lack signal, such as traces after metrics show latency spikes. cx CLI examples include cx metrics search, cx search-fields with value mode, and cx logs query patterns from loaded references. Agents should never modify.

  • Routes investigations across logs, metrics, traces, and RUM pillars.
  • Discovery workflow searches metrics, fields, and codebase before querying.
  • Loads dataprime, promql, logs, spans, and RUM reference files per pillar.
  • cx query commands are read-only and safe in --read-only mode.
  • search-fields supports semantic and value search across logs and spans.

Cx Telemetry Querying by the numbers

  • 1,820 all-time installs (skills.sh)
  • +130 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #121 of 1,435 DevOps & CI/CD skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

cx-telemetry-querying capabilities & compatibility

Capabilities
pillar routing guide · discovery workflow · reference file loading · read only cx cli queries · fallback pivot guidance
Use cases
planning · orchestration
From the docs

What cx-telemetry-querying says it does

Use this skill as the entry point for any investigation, debugging, or data question
SKILL.md
All query commands (`cx logs`, `cx spans`, `cx metrics`, `cx dataprime`, `cx search-fields`) are read-only
SKILL.md
npx skills add https://github.com/coralogix/cx-cli --skill cx-telemetry-querying

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.8k
repo stars113
Security audit3 / 3 scanners passed
Last updatedAugust 4, 2026
Repositorycoralogix/cx-cli

How do I investigate a production issue using Coralogix logs, metrics, traces, or RUM?

Route production investigations to Coralogix logs, metrics, traces, or RUM with cx CLI and reference-guided queries.

Who is it for?

SREs and developers debugging production with Coralogix cx CLI telemetry data.

Skip if: Skip when no Coralogix profile or API credentials are configured.

When should I use this skill?

User investigates issues, checks error rates, queries logs, traces, metrics, or RUM data.

What you get

Pillar-selected cx queries with loaded reference syntax and discovery-validated fields.

  • DataPrime query strings
  • cx CLI commands

By the numbers

  • Targets logs and spans telemetry sources
  • Uses pipe-delimited DataPrime command pipelines

Files

SKILL.mdMarkdownGitHub ↗

Telemetry Querying Skill

Use this skill as the entry point for any investigation, debugging, or data question that may be answered from telemetry data. It helps you decide where the relevant signal lives (metrics, logs, traces, RUM) and tells you which reference files to load before querying.

Loading References

Before querying, load the reference files for the chosen pillar:

PillarLoad these files
Logsreferences/dataprime-reference.md + references/logs-querying.md
Spans / Tracesreferences/dataprime-reference.md + references/spans-querying.md
Metricsreferences/promql-guidelines.md + references/metrics-querying.md
RUM (frontend)references/dataprime-reference.md + references/logs-querying.md + references/rum-querying.md + references/rum-fields.md
DataPrime syntax onlyreferences/dataprime-reference.md

---

Safety

All query commands (cx logs, cx spans, cx metrics, cx dataprime, cx search-fields) are read-only and work in --read-only mode. They never modify data and can be run freely without --yes.

---

Quick Routing Guide

Use this table for obvious cases where one pillar is the clear first choice:

Question TypeFirst ChoiceFallback
UI behavior, page load, frontend errorsRUMTraces (if backend-related)
Endpoint latency, throughput, error ratesMetricsTraces (for per-request detail)
Service-to-service dependencies, request flowTracesLogs (for debug output)
Specific error messages, stack tracesLogsTraces (for request context)
Infrastructure health (CPU, memory, disk)Metrics-
Business events (purchases, signups)Depends - see Discovery Workflow-

For ambiguous questions (e.g., "How much money did users spend last week?"), the signal could live in any pillar. Follow the Discovery Workflow below.

---

Discovery Workflow

When the answer could reside in multiple pillars, run discovery in parallel to find the best source.

Step 1: Search Metrics

Check if a relevant metric exists:

cx metrics search --name '*transaction*'
cx metrics search --name '*payment*'
cx metrics search --name '*revenue*'
cx metrics search --description "total purchase amount"

If a matching metric is found, load references/promql-guidelines.md + references/metrics-querying.md and continue.

Step 2: Search Log and Span Fields

Use semantic field search to find relevant DataPrime paths:

cx search-fields "transaction amount" --dataset logs
cx search-fields "payment total" --dataset spans
cx search-fields "purchase value" --dataset logs --limit 10

If you know a concrete value that should appear in the data but don't know which field holds it, use value search instead. It returns the matching field keys alongside sample values, which also lets you infer the field's type (string, numeric, enum, etc.):

cx search-fields "payment_failed" -s value --dataset logs
cx search-fields "grpc.status.UNAVAILABLE" -s value --dataset spans
cx search-fields "eu-west-1" -s value --dataset all

Requirements: cx search-fields needs a Coralogix API key or OAuth on the active profile. If credentials are missing, prompt the user to run cx profiles add <name>.

If matching fields are found:

  • For logs: load references/dataprime-reference.md + references/logs-querying.md
  • For spans: load references/dataprime-reference.md + references/spans-querying.md

Step 3: Search the Codebase

When discovery results are ambiguous or you need to validate what a metric/field actually represents, search the codebase:

  • Look for metric registration code (e.g., prometheus.NewCounter, metrics.record)
  • Look for log statements that emit the field (e.g., logger.info("transaction", ...))
  • Look for span attributes (e.g., span.setAttribute("purchase.amount", ...))

This confirms the semantic meaning and helps you choose the right pillar.

Step 4: Choose and Query

Based on discovery results, pick the pillar with the clearest signal, load its reference files (see Loading References), then query.

---

Fallback and Pivoting

If your initial route yields no results, pivot to another pillar.

Example pivot paths:

  • Metrics empty → try traces (per-request data) or logs (event records)
  • Logs empty → try traces (structured span attributes) or metrics (aggregated counters)
  • Traces empty → try logs (text-based debug output)

Do not stop after one failed attempt. Try at least two pillars before concluding the data does not exist.

---

CLI Commands Reference

CommandPurposeWhen to Use
cx schemaOutput the full command tree as JSONDiscover all available commands and their flags
cx metrics search --name <pattern>Find metrics by nameFirst step for metrics discovery
cx metrics search --description <text>Semantic metric searchWhen you know what you want but not the name
cx search-fields "<text>" --dataset logsFind log fields by descriptionDiscovery for log-based questions
cx search-fields "<text>" --dataset spansFind span fields by descriptionDiscovery for trace-based questions
cx search-fields "<value>" -s value --dataset logsFind log fields that contain a known valueWhen you know a value but not which log field holds it — also reveals field type from the returned values
cx search-fields "<value>" -s value --dataset spansFind span fields that contain a known valueWhen you know a value but not which span attribute holds it
cx search-fields "<value>" -s value --dataset allSame, across logs and spansWhen you want to search across both logs and spans at once
cx spans "filter $l.serviceName == '<service>'" --limit 10Search spans by serviceWhen investigating a specific service
cx dataprime listList DataPrime commands/functionsWhen building log or span queries
cx dashboards search "<description>"Find existing dashboards by natural-language descriptionBefore creating a new dashboard — check if one already exists
cx dashboards query-search --description "<text>"Find dashboard widgets whose queries cover a topicDiscover how a topic is already being monitored
cx dashboards query-search --field "<field-path>"Find widgets that reference a specific fieldReuse existing PromQL/DataPrime patterns for a known field

---

Examples

Example 1: Business Question (Ambiguous Source)

Question: "How much money did people spend on the platform last week?"

Approach: 1. Search metrics: cx metrics search --name '*revenue*' and cx metrics search --name '*transaction*' 2. Search log fields: cx search-fields "transaction amount" --dataset logs 3. Search span fields: cx search-fields "payment total" --dataset spans 4. If a metric like payment_total_usd exists, load metrics references and run a range query 5. If only logs have the data, load logs references and use DataPrime aggregation 6. If traces have purchase.amount attribute, load spans references

Example 2: Latency Question (Clear First Choice)

Question: "What's the average latency of the checkout route?"

Approach: 1. First try metrics: cx metrics search --name '*checkout*latency*' or cx metrics search --name '*http*duration*' 2. If a histogram metric exists, load metrics references and use histogram_quantile 3. If no metric, fall back to traces: load spans references and aggregate span durations

Example 3: Frontend Performance (RUM)

Question: "Why is the dashboard page loading slowly for users?"

Approach: 1. This is clearly a RUM question - load references/rum-querying.md + references/rum-fields.md + references/logs-querying.md + references/dataprime-reference.md 2. Query web vitals and page load times 3. If RUM shows backend calls are slow, pivot to spans references for the API calls

Example 4: Error Investigation (Logs + Traces)

Question: "Why are users getting 500 errors on the payment endpoint?"

Approach: 1. Check error rate metrics → load metrics references 2. Search for error logs → load logs references 3. Get traces for failed requests → load spans references 4. Cross-reference: find trace IDs in logs, then fetch full traces for root cause

---

Beyond Investigation

Not every question is answered by querying data. If the user's intent is operational rather than investigative, route to the appropriate workflow skill:

User IntentRoute To
Reducing costs, checking usage, TCO policiescx-cost-optimization
Incident triage, SLO breaching, who got pagedcx-incident-management
Setting up monitoring, webhooks, notificationscx-observability-setup
Configuring parsing rules, enrichments, E2Mcx-data-pipeline
Access audit, API keys, user managementcx-platform-admin
Creating or managing dashboardscx-dashboards
Finding or searching existing dashboardscx-search-dashboard

---

Key Principles

  • Load references before querying: check the Loading References table first
  • Discover before querying: always run search/discovery to find the right source
  • Parallel discovery: for ambiguous questions, search metrics, logs, and spans concurrently
  • Validate with code: when unsure what a metric or field represents, check the codebase
  • Pivot on failure: if one pillar is empty, try another before giving up

Related skills

How it compares

Use cx-telemetry-querying for Coralogix-native DataPrime syntax rather than generic PromQL or SQL log query patterns.

FAQ

Which pillar for frontend errors?

RUM first, with traces fallback if backend-related.

Are cx queries destructive?

No; all query commands are read-only even without --yes.

What if the question is ambiguous?

Run discovery: metrics search, search-fields, then codebase validation.

Is Cx Telemetry Querying safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

DevOps & CI/CDmonitoring

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.