Search and filter Observability logs using ES|QL. Use when investigating log spikes, errors, or anomalies; getting volume and trends; or drilling into services or containers during incidents.
---
name: observability-logs-search
description: >
Search and filter Observability logs using ES|QL. Use when investigating log spikes,
errors, or anomalies; getting volume and trends; or drilling into services or containers
during incidents.
metadata:
author: elastic
version: 0.2.0
---
# Logs Search
Search and filter logs to support incident investigation. The workflow mirrors Kibana Discover: apply a time range and
scope filter, then **iteratively add exclusion filters (NOT)** until a small, interesting subset of logs remains—either
the root cause or the key document. Optionally view logs in context (preceding and following that document) or pivot to
another entity and start a fresh search. Use ES|QL only (`POST /_query`); do not use Query DSL.
## When NOT to use
- **Metrics or traces** — use the dedicated metric or trace tools.
## Parameter conventions
Use consistent names for Observability log search:… load the full skill through Skill MeInstall the Observability Logs Search skill
If full content is available, it applies in this conversation and stays installed for future sessions.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp