Search and filter Observability logs using ES|QL. Use when investigating log spikes, errors, or anomalies; getting volume and trends; or drilling into services or containers during incidents.
---
name: observability-logs-search
description: >
Search and filter Observability logs using ES|QL. Use when investigating log spikes,
errors, or anomalies; getting volume and trends; or drilling into services or containers
during incidents.
metadata:
author: elastic
version: 0.2.0
---
# Logs Search
Search and filter logs to support incident investigation. The workflow mirrors Kibana Discover: apply a time range and
scope filter, then **iteratively add exclusion filters (NOT)** until a small, interesting subset of logs remains—either
the root cause or the key document. Optionally view logs in context (preceding and following that document) or pivot to
another entity and start a fresh search. Use ES|QL only (`POST /_query`); do not use Query DSL.
## When NOT to use
- **Metrics or traces** — use the dedicated metric or trace tools.
## Parameter conventions
Use consistent names for Observability log search:… install to load the full skillInstall the Observability Logs Search skill
It activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp