/log-error-digest
Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze
$ npx -y skills add zebbern/claude-code-guide --skill log-error-digest --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition โ
- You can call itInvoke it directly when you want it.
- Slash command
/log-error-digest
Context preview
The summary Claude sees to decide when to auto-load this skill.
Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze
SKILL.md
log-error-digest.SKILL.mdname: log-error-digest
description: "Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze errors, find patterns, debug issues, or get distribution stats."
license: MIT
type: tool
tags: [logs, analysis, devops, monitoring]
Log Error Digest
Automated log file analysis that produces error clustering, frequency statistics, and time distribution reports.
Features
- **Error Clustering**: Groups similar error messages by normalizing dynamic parts (IPs, UUIDs, numbers, etc.) to identify root causes
- **Frequency Statistics**: Counts occurrences by error type, sorted by severity
- **Time Distribution**: Shows error distribution by hour and by date, helping pinpoint peak error periods
Supported Log Formats
| Format | Description | Auto-detection | |--------|-------------|----------------| | JSON | One JSON object per line with `timestamp`/`level`/`message` fields | Starts with `{` | | syslog | RFC 3164 format, e.g. `Jan 1 12:00:00 host proc[pid]: msg` | Starts with month name | | Nginx | Access log or error log format | Starts with IP or date/path pattern |
Usage
python scripts/analyze_logs.py <log_file_path> [options]
Parameters
| Parameter | Description | Default | |-----------|-------------|---------| | `log_file` | Path to the log file (required) | - | | `--format` | Log format: `auto`/`json`/`syslog`/`nginx` | `auto` | | `--top` | Show Top N error clusters | `20` | | `--output` | Export results to a JSON file | Terminal output only | | `--level` | Filter by log level (e.g. `ERROR`, `WARN`) | All levels | | `--since` | Only analyze logs after this time (ISO format) | No limit | | `--until` | Only analyze logs before this time (ISO format) | No limit |
Examples
# Auto-detect format and analyze the entire log file
python scripts/analyze_logs.py /var/log/app.log
# Specify Nginx format, show only Top 10 errors
python scripts/analyze_logs.py /var/log/nginx/error.log --format nginx --top 10
# Filter ERROR level only, export JSON report
python scripts/analyze_logs.py app.log --level ERROR --output report.json
# Analyze logs within a specific time range
python scripts/analyze_logs.py app.log --since 2024-01-01T00:00:00 --until 2024-01-02T00:00:00
Output
Terminal Output
=======================================================
Log Analysis Report
=======================================================
๐ Overview
Detected format: json
Total lines: 15,234
Parsed: 15,100 (parse failures: 134)
Matched entries: 12,800
Errors: 2,341
Time range: 2024-01-01 00:03:12 ~ 2024-01-01 23:58:45
๐ด Top Error Clusters (47 total)
#1 [ร523 ] Connection refused to database at 10.0.1.5:5432
First seen: 2024-01-01T00:15:30 Last seen: 2024-01-01T23:45:12
#2 [ร312 ] Timeout waiting for response from user-service after 30000ms
First seen: 2024-01-01T02:10:00 Last seen: 2024-01-01T22:30:45
#3 [ร198 ] File not found: /data/uploads/img_99421.png
First seen: 2024-01-01T08:00:00 Last seen: 2024-01-01T20:15:33
...
โฐ Time Distribution (by hour)
00:00 โโโโโโโโโโโโโโโโโโโโ 42
01:00 โโโโโโโโโโโโโโโโโโโโ 18
...
14:00 โโโโโโโโโโโโโโโโโโโโ 523
...
๐
Time Distribution (by date)
2024-01-01 โโโโโโโโโโโโโโโโโโโโ 2,341JSON Output
Use the `--output` parameter to export a structured JSON report for further processing or integration with monitoring systems.
Read more
name: log-error-digest description: "Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze errors, find patterns, debug issues, or get distribution stats." license: MIT type: tool tags: [logs, analysis, devops, monitoring]
Log Error Digest
Automated log file analysis that produces error clustering, frequency statistics, and time distribution reports.
Features
- **Error Clustering**: Groups similar error messages by normalizing dynamic parts (IPs, UUIDs, numbers, etc.) to identify root causes
- **Frequency Statistics**: Counts occurrences by error type, sorted by severity
- **Time Distribution**: Shows error distribution by hour and by date, helping pinpoint peak error periods
Supported Log Formats
| Format | Description | Auto-detection | |--------|-------------|----------------| | JSON | One JSON object per line with `timestamp`/`level`/`message` fields | Starts with `{` | | syslog | RFC 3164 format, e.g. `Jan 1 12:00:00 host proc[pid]: msg` | Starts with month name | | Nginx | Access log or error log format | Starts with IP or date/path pattern |
Usage
python scripts/analyze_logs.py <log_file_path> [options]
Parameters
| Parameter | Description | Default | |-----------|-------------|---------| | `log_file` | Path to the log file (required) | - | | `--format` | Log format: `auto`/`json`/`syslog`/`nginx` | `auto` | | `--top` | Show Top N error clusters | `20` | | `--output` | Export results to a JSON file | Terminal output only | | `--level` | Filter by log level (e.g. `ERROR`, `WARN`) | All levels | | `--since` | Only analyze logs after this time (ISO format) | No limit | | `--until` | Only analyze logs before this time (ISO format) | No limit |
Examples
# Auto-detect format and analyze the entire log file python scripts/analyze_logs.py /var/log/app.log # Specify Nginx format, show only Top 10 errors python scripts/analyze_logs.py /var/log/nginx/error.log --format nginx --top 10 # Filter ERROR level only, export JSON report python scripts/analyze_logs.py app.log --level ERROR --output report.json # Analyze logs within a specific time range python scripts/analyze_logs.py app.log --since 2024-01-01T00:00:00 --until 2024-01-02T00:00:00
Output
Terminal Output
=======================================================
Log Analysis Report
=======================================================
๐ Overview
Detected format: json
Total lines: 15,234
Parsed: 15,100 (parse failures: 134)
Matched entries: 12,800
Errors: 2,341
Time range: 2024-01-01 00:03:12 ~ 2024-01-01 23:58:45
๐ด Top Error Clusters (47 total)
#1 [ร523 ] Connection refused to database at 10.0.1.5:5432
First seen: 2024-01-01T00:15:30 Last seen: 2024-01-01T23:45:12
#2 [ร312 ] Timeout waiting for response from user-service after 30000ms
First seen: 2024-01-01T02:10:00 Last seen: 2024-01-01T22:30:45
#3 [ร198 ] File not found: /data/uploads/img_99421.png
First seen: 2024-01-01T08:00:00 Last seen: 2024-01-01T20:15:33
...
โฐ Time Distribution (by hour)
00:00 โโโโโโโโโโโโโโโโโโโโ 42
01:00 โโโโโโโโโโโโโโโโโโโโ 18
...
14:00 โโโโโโโโโโโโโโโโโโโโ 523
...
๐
Time Distribution (by date)
2024-01-01 โโโโโโโโโโโโโโโโโโโโ 2,341JSON Output
Use the `--output` parameter to export a structured JSON report for further processing or integration with monitoring systems.
Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user!
Repo: zebbern/claude-code-guide
Other skills on claude-code-guide.
- /academic-paper-reviewer
Simulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to \"review my paper,\" \"simulate peer review,\" or \"give my paper a peer
Open skill - /active-directory-attacks
This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration
Open skill - /api-fuzzing-bug-bounty
This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
Open skill - /api-shape-explorer
Generate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".
Open skill - /audit-flow
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems.
Open skill - /authentication-patterns
Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
Open skill

