Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问clear审计通过

log-analyzer日志分析器

Agent Skill

log-analyzer 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

461

周安装

19

GitHub Stars

26

下载量

150
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:log-analyzer(日志分析器)
来源仓库:https://github.com/curiouslearner/devkit
仓库路径:skills/log-analyzer
安装命令:
npx skills add https://github.com/curiouslearner/devkit --skill log-analyzer
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/curiouslearner/devkit --skill log-analyzer

简介

log-analyzer 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中根据关键词、任务场景或来源线索快速定位候选结果时使用。

  • 适用于系统故障排查与日志模式识别支持。
  • 可提取错误码含义、关联事件序列或推荐过滤规则。
  • 安装命令为 npx skills add https://github.com/curiouslearner/devkit --skill log-analyzer。
  • 若解析生产日志,应注意脱敏处理与访问权限控制。

SKILL.md

Log Analyzer Skill

Parse and analyze application logs to identify errors, patterns, and insights.

Instructions

You are a log analysis expert. When invoked:

  1. Parse Log Files:

- Identify log format (JSON, syslog, Apache, custom) - Extract structured data from logs - Handle multi-line stack traces - Parse timestamps and normalize formats

  1. Analyze Patterns:

- Identify error frequency and trends - Detect error spikes or anomalies - Find common error messages - Track error patterns over time - Identify correlation between events

  1. Generate Insights:

- Most frequent errors - Error rate trends - Performance metrics from logs - User activity patterns - System health indicators

  1. Provide Recommendations:

- Root cause analysis - Suggested fixes for common errors - Logging improvements - Monitoring suggestions

Log Format Detection

JSON Logs

{
  "timestamp": "2024-01-15T10:30:00.000Z",
  "level": "error",
  "message": "Database connection failed",
  "service": "api",
  "userId": "12345",
  "error": {
    "code": "ECONNREFUSED",
    "stack": "Error: connect ECONNREFUSED..."
  }
}

Standard Format (Combined)

192.168.1.1 - - [15/Jan/2024:10:30:00 +0000] "GET /api/users HTTP/1.1" 500 1234 "-" "Mozilla/5.0..."

Application Logs

2024-01-15 10:30:00 ERROR [UserService] Failed to fetch user: User not found (ID: 12345)
  at UserService.getUser (user-service.js:45:10)
  at async API.handler (api.js:23:5)

Analysis Patterns

Error Frequency Analysis

## Top 10 Errors (Last 24h)

1. **Database connection timeout** (1,234 occurrences)
   - First seen: 2024-01-15 08:00:00
   - Last seen: 2024-01-15 10:30:00
   - Peak: 2024-01-15 09:15:00 (234 errors in 1 min)
   - Affected services: api, worker
   - Impact: High

2. **User not found** (567 occurrences)
   - Pattern: Regular distribution
   - Likely cause: Normal user behavior
   - Impact: Low

3. **Rate limit exceeded** (345 occurrences)
   - Source IPs: 192.168.1.100, 10.0.0.50
   - Pattern: Burst traffic
   - Impact: Medium

Timeline Analysis

## Error Timeline

08:00 - Normal operations (5-10 errors/min)
09:00 - Database connection errors spike (200+ errors/min)
09:15 - Peak error rate (234 errors/min)
09:30 - Database connection restored
10:00 - Return to normal (8-12 errors/min)

## Correlation
- Traffic increased 300% at 09:00
- Database CPU at 95% during incident
- Connection pool exhausted

Performance Metrics

## Response Times (from logs)

**Average**: 234ms
**P50**: 180ms
**P95**: 450ms
**P99**: 890ms

**Slow Requests** (>1s):
- /api/search: 2.3s avg (45 requests)
- /api/reports: 1.8s avg (23 requests)

**Fast Requests** (<100ms):
- /api/health: 5ms avg
- /api/status: 12ms avg

Usage Examples

@log-analyzer
@log-analyzer app.log
@log-analyzer --errors-only
@log-analyzer --time-range "last 24h"
@log-analyzer --pattern "database"
@log-analyzer --format json

Report Format

# Log Analysis Report
**Period**: 2024-01-15 00:00:00 to 2024-01-15 23:59:59
**Log File**: /var/log/app.log
**Total Entries**: 145,678
**Errors**: 2,345 (1.6%)
**Warnings**: 8,901 (6.1%)

---

## Executive Summary

- **Critical Issues**: 3
- **High Priority**: 8
- **Medium Priority**: 15
- **Overall Health**: ⚠️ Degraded (Database issues detected)

### Key Findings
1. Database connection pool exhaustion at 09:00-09:30
2. Rate limiting triggered for 2 IP addresses
3. Slow query performance on search endpoint
4. Memory leak warning in worker service

---

## Critical Issues

### 1. Database Connection Pool Exhaustion
**Severity**: Critical
**Occurrences**: 1,234
**Time Range**: 09:00:00 - 09:30:00
**Impact**: Service degradation, failed requests

**Error Pattern**:

Error: connect ETIMEDOUT Error: Too many connections Error: Connection pool timeout

**Root Cause Analysis**:
- Traffic spike (300% increase)
- Connection pool size: 10 (insufficient)
- Connections not being released properly
- No connection timeout configured

**Recommendations**:
1. Increase connection pool size to 50
2. Implement connection timeout (30s)
3. Review connection release logic
4. Add connection pool monitoring
5. Implement circuit breaker pattern

**Code Fix**:

// Increase pool size const pool = new Pool({ max: 50, // was: 10 min: 5, acquireTimeoutMillis: 30000, idleTimeoutMillis: 30000 });

// Ensure connections are released try { const client = await pool.connect(); const result = await client.query('SELECT * FROM users'); return result; } finally { client.release(); // Always release! }


---

### 2. Memory Leak in Worker Service

**Severity**: Critical **First Detected**: 06:00:00 **Pattern**: Memory usage increasing 50MB/hour

**Evidence**:

06:00 - Memory: 512MB 09:00 - Memory: 662MB 12:00 - Memory: 812MB 15:00 - Memory: 962MB (WARNING threshold)


**Likely Causes**:

- Event listeners not cleaned up
- Cached data not being cleared
- Circular references

**Recommendations**:

1. Add heap snapshot analysis
2. Review event listener cleanup
3. Implement cache eviction policy
4. Monitor with heap profiler

---

## High Priority Issues

### 3. Slow Search Query Performance

**Severity**: High **Endpoint**: /api/search **Occurrences**: 45 requests **Average Response**: 2.3s (target: <500ms)

**Slow Query Examples**:

2024-01-15 10:15:23 WARN [SearchService] Query took 2,345ms SELECT * FROM products WHERE name LIKE '%keyword%' Rows examined: 1,234,567


**Recommendations**:

1. Add full-text search index
2. Implement pagination (limit results)
3. Use Elasticsearch for search
4. Add query result caching

---

### 4. Rate Limit Violations

**Severity**: High **Affected IPs**: 2 **Requests Blocked**: 345

**Details**:

- IP: 192.168.1.100 (245 blocked requests)
  - Pattern: Automated scraping
  - Recommendation: Consider permanent block
- IP: 10.0.0.50 (100 blocked requests)
  - Pattern: Burst traffic from legitimate user
  - Recommendation: Increase rate limit for authenticated users

---

## Error Distribution

### By Severity

- **ERROR**: 2,345 (1.6%)
- **WARN**: 8,901 (6.1%)
- **INFO**: 134,432 (92.3%)

### By Service

- **api**: 1,567 errors
- **worker**: 456 errors
- **scheduler**: 234 errors
- **auth**: 88 errors

### By Error Type

1. Database errors: 1,234 (52.6%)
2. Validation errors: 567 (24.2%)
3. Rate limit errors: 345 (14.7%)
4. Authentication errors: 199 (8.5%)

---

## Performance Metrics

### Response Times

| Endpoint | Avg | P50 | P95 | P99 | Max |
| --- | --- | --- | --- | --- | --- |
| /api/users | 123ms | 95ms | 230ms | 450ms | 890ms |
| /api/search | 2,300ms | 1,800ms | 4,500ms | 6,200ms | 8,900ms |
| /api/posts | 156ms | 120ms | 280ms | 520ms | 780ms |
| /api/health | 5ms | 4ms | 8ms | 12ms | 25ms |

### Traffic Patterns

- **Peak**: 09:15:00 (1,234 req/min)
- **Average**: 410 req/min
- **Quiet Period**: 02:00-05:00 (45 req/min)

---

## User Activity

### Top Users by Request Count

1. User ID 12345: 2,345 requests
2. User ID 67890: 1,890 requests
3. User ID 11111: 1,456 requests

### Failed Authentication Attempts

- Total: 199
- Unique Users: 45
- Suspicious Pattern: User 99999 (23 failed attempts)

---

## Recommendations

### Immediate Actions (Today)

1. ✓ Increase database connection pool
2. ✓ Investigate memory leak in worker
3. ✓ Block suspicious IP (192.168.1.100)
4. ✓ Add monitoring for connection pool

### Short Term (This Week)

1. Optimize search queries
2. Implement query result caching
3. Review event listener cleanup
4. Add circuit breaker for database
5. Increase rate limits for authenticated users

### Long Term (This Month)

1. Migrate search to Elasticsearch
2. Implement comprehensive APM
3. Add automated log analysis
4. Set up predictive alerting
5. Improve error handling and logging

---

## Logging Improvements

### Missing Information

- Request IDs (for tracing)
- User context in some services
- Performance metrics in worker logs
- Structured error codes

### Suggested Log Format

{ "timestamp": "2024-01-15T10:30:00.000Z", "level": "error", "requestId": "req-abc-123", "service": "api", "userId": "12345", "endpoint": "/api/users", "method": "GET", "statusCode": 500, "duration": 234, "error": { "code": "DB_CONNECTION_ERROR", "message": "Database connection failed", "stack": "..." } }


---

## Monitoring Alerts to Set Up

1. **Database Connection Errors** > 10/min
2. **Response Time P95** > 500ms
3. **Error Rate** > 2%
4. **Memory Usage** > 80%
5. **Rate Limit Hits** > 100/hour from single IP

Analysis Techniques

Regular Expression Patterns

# Find all errors
grep -E "ERROR|Exception|Failed" app.log

# Extract timestamps and errors
grep "ERROR" app.log | awk '{print $1, $2, $4}'

# Count error types
grep "ERROR" app.log | cut -d':' -f2 | sort | uniq -c | sort -nr

# Find slow requests
awk '$7 > 1000 {print $0}' access.log  # Response time > 1s

Time-Based Analysis

# Errors per hour
awk '{print $1" "$2}' app.log | cut -d':' -f1 | uniq -c

# Peak error times
grep "ERROR" app.log | cut -d' ' -f2 | cut -d':' -f1 | sort | uniq -c | sort -nr

Tools Integration

  • Elasticsearch + Kibana: Centralized logging and visualization
  • Splunk: Enterprise log management
  • Datadog: APM and log analysis
  • CloudWatch: AWS log aggregation
  • Grafana Loki: Open-source log aggregation
  • Papertrail: Simple log management

Notes

  • Always consider log volume and retention
  • Implement log rotation and archiving
  • Use structured logging (JSON) for easier parsing
  • Include request IDs for distributed tracing
  • Set up alerts for critical error patterns
  • Regular log analysis prevents incidents
  • Correlation with metrics provides better insights

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenCode

27.54%
按下载量换算41

Antigravity

23.29%
按下载量换算35

Claude Code

18.36%
按下载量换算28

Gemini CLI

13.29%
按下载量换算20

windsurf

6.56%
按下载量换算10

github-copilot

3.43%
按下载量换算5

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills