Generate Logging Query Language queries
Use this skill to generate correct Logging Query Language (LQL) queries for
Cloud Logging.
Core rules
Strict syntax requirements:
- Always use double quotes (
") for string literals. Do not use
single quotes (').
- Write boolean operators in all capitals:
AND, OR, NOT.
- Always use parentheses to group terms and explicitly enforce precedence.
Common pitfalls:
- Instance ID vs. Instance Name: For the
gce_instance resource type,
do NOT compare instance names to instance IDs. Instance names are
strings (for example, my-instance). Instance IDs are numeric. If you
only have the name, then search by instance name,
SEARCH("my-instance"), or use resource.labels.instance_name if that
label is available for the resource.
- Resource Type Accuracy: Do not guess resource types. You must look
up the correct
resource.type value in the service-specific reference
files. For example, use internal_http_lb_rule for Internal HTTP(S)
Load Balancer rules when filtering by forwarding rule name or region
(instead of http_load_balancer).
Output format and placeholders:
- Output only the raw LQL query text. Do not include conversational
filler. Do not wrap the query in markdown code blocks unless explicitly
requested by the user. Valid LQL comments (using
--) are allowed, and
are the ONLY acceptable way to include explanations or warnings.
- Never block on missing variables. If the user's request lacks
specific identifiers (like a project ID, instance name, or IP address),
do not ask them for clarification. Instead, insert uppercase placeholder
strings wrapped in angle brackets (for example,
"<PROJECT_ID>",
"<YOUR_SERVICE_NAME>") directly into the query.
Preferred fields:
- Include
resource.type and log_id restrictions when the query targets
specific Google Cloud services or resources. Global queries (for
example, "latest error logs") do not require these restrictions.
Detailed reference
Refer to references/api_reference.md for LQL syntax rules, including
Operators, NULL handling, SEARCH, and Regex.
Service reference files
Before generating a query, you MUST read the examples for the specific service.
LQL schemas and resource.type values are service-specific.
For the following services, read the exact file listed:
- App Engine
- BigQuery
- Cloud Functions
- Cloud Observability (Monitoring, Logging, Trace)
- Cloud Run
- Cloud Source Repositories
- Cloud SQL
- Cloud Storage
- Cloud Tasks
- Compute Engine (GCE)
- Dataflow
- Dataproc
- Deployment Manager
- Kubernetes Engine (GKE)
- IAM & Service Accounts
- Networking (VPC, Load Balancing, and others)
- Security (Audit logging)
- Service Usage (Enable/Disable API, Quotas)
- Spanner
- Third Party (for example, Nginx, Apache)
For Google Cloud services that aren't listed: If the service is not listed
above, write the LQL query based on your general knowledge.
Query generation rules
- Resource Types: Explicitly define the
resource.type in your queries
when focusing on specific services. For some queries, you may need to search
across multiple types (for example, resource.type=("bigquery_project" OR "bigquery_dataset")).
- Audit and admin logs: Google Cloud Audit logs (Admin Activity, Data
Access) always follow a standard structure inside
protoPayload. If the
user asks for logs about who created, updated, or deleted a resource, or an
API being called:
- Do NOT fall back to
SEARCH(). Instead, use protoPayload.methodName.
- Construct the method name by guessing the service and the verb. Example:
protoPayload.methodName:"compute.instances.insert".
- Always use the colon operator (
:) instead of equals (=) for
methodName. The colon operator results in substring matching, which is
the only feasible option when the exact API string isn't known.
- For generic API enable/disable events, use
resource.type="audited_resource".
- Handling Unknown Schemas (Crucial): If the user asks to filter by a
specific field or condition, and if you cannot find a matching example or
schema in the reference files, then you must generate a query using global
search.
- Only specify
jsonPayload.* or protoPayload.* field structures when
you are certain of their exact name.
- Use the
SEARCH() function to find the keyword globally within the
correct resource.type.
- Agent Prompt to User: When delivering a query that uses
SEARCH, you
MUST add an LQL comment (using --) at the top of the query indicating
you used a global keyword search because the exact schema wasn't in your
references. Do NOT output conversational text, strictly adhere to the
Output Format rule.
Supporting links
Source: google/skills → skills/cloud/cloud-logging-query-generation/SKILL.md
1---2name: cloud-logging-query-generation3description: >- Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Spanner.4---567# Generate Logging Query Language queries89Use this skill to generate correct Logging Query Language (LQL) queries for10Cloud Logging.1112## Core rules13141. **Strict syntax requirements:**1516 * **Always use double quotes (`"`)** for string literals. Do not use17 single quotes (`'`).18 * Write boolean operators in all capitals: `AND`, `OR`, `NOT`.19 * Always use parentheses to group terms and explicitly enforce precedence.20212. **Common pitfalls:**2223 * **Instance ID vs. Instance Name:** For the `gce_instance` resource type,24 do NOT compare instance names to instance IDs. Instance names are25 strings (for example, `my-instance`). Instance IDs are numeric. If you26 only have the name, then search by instance name,27 `SEARCH("my-instance")`, or use `resource.labels.instance_name` if that28 label is available for the resource.29 * **Resource Type Accuracy:** Do not guess resource types. You must look30 up the correct `resource.type` value in the service-specific reference31 files. For example, use `internal_http_lb_rule` for Internal HTTP(S)32 Load Balancer rules when filtering by forwarding rule name or region33 (instead of `http_load_balancer`).34353. **Output format and placeholders:**3637 * Output **only** the raw LQL query text. Do not include conversational38 filler. Do not wrap the query in markdown code blocks unless explicitly39 requested by the user. Valid LQL comments (using `--`) are allowed, and40 are the ONLY acceptable way to include explanations or warnings.41 * **Never block on missing variables.** If the user's request lacks42 specific identifiers (like a project ID, instance name, or IP address),43 do not ask them for clarification. Instead, insert uppercase placeholder44 strings wrapped in angle brackets (for example, `"<PROJECT_ID>"`,45 `"<YOUR_SERVICE_NAME>"`) directly into the query.46474. **Preferred fields:**4849 * Include `resource.type` and `log_id` restrictions when the query targets50 specific Google Cloud services or resources. Global queries (for51 example, "latest error logs") do not require these restrictions.5253## Detailed reference5455Refer to `references/api_reference.md` for LQL syntax rules, including56Operators, NULL handling, SEARCH, and Regex.5758## Service reference files5960Before generating a query, you MUST read the examples for the specific service.61LQL schemas and `resource.type` values are service-specific.6263**For the following services, read the exact file listed:**6465* [App Engine](references/query_app_engine.md)66* [BigQuery](references/query_bigquery.md)67* [Cloud Functions](references/query_cloud_functions.md)68* [Cloud Observability (Monitoring, Logging, Trace)](references/query_cloud_observability.md)69* [Cloud Run](references/query_cloud_run.md)70* [Cloud Source Repositories](references/query_cloud_source_repositories.md)71* [Cloud SQL](references/query_cloud_sql.md)72* [Cloud Storage](references/query_cloud_storage.md)73* [Cloud Tasks](references/query_cloud_tasks.md)74* [Compute Engine (GCE)](references/query_compute_engine.md)75* [Dataflow](references/query_dataflow.md)76* [Dataproc](references/query_dataproc.md)77* [Deployment Manager](references/query_deployment_manager.md)78* [Kubernetes Engine (GKE)](references/query_gke.md)79* [IAM & Service Accounts](references/query_iam.md)80* [Networking (VPC, Load Balancing, and others)](references/query_networking.md)81* [Security (Audit logging)](references/query_security.md)82* [Service Usage (Enable/Disable API, Quotas)](references/query_service_usage.md)83* [Spanner](references/query_spanner.md)84* [Third Party (for example, Nginx, Apache)](references/query_third_party.md)8586**For Google Cloud services that aren't listed:** If the service is not listed87above, write the LQL query based on your general knowledge.8889## Query generation rules90911. **Resource Types:** Explicitly define the `resource.type` in your queries92 when focusing on specific services. For some queries, you may need to search93 across multiple types (for example, `resource.type=("bigquery_project" OR94 "bigquery_dataset")`).952. **Audit and admin logs:** Google Cloud Audit logs (Admin Activity, Data96 Access) always follow a standard structure inside `protoPayload`. If the97 user asks for logs about who created, updated, or deleted a resource, or an98 API being called:99 * Do NOT fall back to `SEARCH()`. Instead, use `protoPayload.methodName`.100 * Construct the method name by guessing the service and the verb. Example:101 `protoPayload.methodName:"compute.instances.insert"`.102 * **Always use the colon operator (`:`)** instead of equals (`=`) for103 `methodName`. The colon operator results in substring matching, which is104 the only feasible option when the exact API string isn't known.105 * For generic API enable/disable events, use106 `resource.type="audited_resource"`.1073. **Handling Unknown Schemas (Crucial):** If the user asks to filter by a108 specific field or condition, and if you cannot find a matching example or109 schema in the reference files, **then you must generate a query using global110 search.**111 * Only specify `jsonPayload.*` or `protoPayload.*` field structures when112 you are certain of their exact name.113 * Use the `SEARCH()` function to find the keyword globally within the114 correct `resource.type`.115 * *Agent Prompt to User:* When delivering a query that uses `SEARCH`, you116 MUST add an LQL comment (using `--`) at the top of the query indicating117 you used a global keyword search because the exact schema wasn't in your118 references. Do NOT output conversational text, strictly adhere to the119 Output Format rule.120121## Supporting links122123* [Cloud Logging query language documentation](https://docs.cloud.google.com/logging/docs/view/logging-query-language)124* [Monitored resource types catalog](https://docs.cloud.google.com/logging/docs/api/v2/resource-list)125* [Cloud Logging query library](https://docs.cloud.google.com/logging/docs/view/query-library)126127---128129**Source:** [`google/skills`](https://github.com/google/skills) → `skills/cloud/cloud-logging-query-generation/SKILL.md`