Skill: OpenClaw Log Analysis
Changelog
- 2026-03-19: Initial creation
Overview
Procedures for analyzing OpenClaw container logs to detect issues, patterns, and anomalies.
Log Access
# All logs
docker logs openclaw-okny-openclaw-1
# Recent logs (last N lines)
docker logs --tail 100 openclaw-okny-openclaw-1
# Time-bounded logs
docker logs --since 1h openclaw-okny-openclaw-1
docker logs --since "2026-03-19T12:00:00" openclaw-okny-openclaw-1
# Follow live
docker logs -f openclaw-okny-openclaw-1
# Both stdout and stderr
docker logs openclaw-okny-openclaw-1 2>&1
Error Classification
Critical Errors (Act Immediately)
FATAL/fatal— Process is crashingENOENTon config files — Config missing or movedEACCES— Permission denied, process can't access needed filesOOMKilled— Out of memory, container killedZod/validationerrors — Config schema violationETIMEDOUTon API calls — Network connectivity lost- Connection refused to Anthropic API — Auth or network issue
Warning Errors (Monitor)
ECONNRESET— Connection reset, usually transient429/rate limit— API rate limiting, may need throttlingtimeout— Slow responses, may indicate overload- Memory usage warnings — Approaching limits
Known Harmless (Ignore)
nostr module missing— Nostr not installed, not neededapply_patchentries — Normal operationautoSelectFamily— Node.js deprecation warning, harmlessExperimentalWarning— Node.js experimental feature warnings
Analysis Procedures
Error Scan
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -i -E "error|exception|fatal|crash|panic|ENOENT|EACCES|ETIMEDOUT" | grep -v -E "nostr|apply_patch|autoSelectFamily" | tail -30
Warning Scan
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -i "warn" | grep -v -E "nostr|apply_patch|autoSelectFamily" | tail -20
Activity Analysis
# Message throughput
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -c -i "message"
# API call frequency
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -c -i "anthropic\|api.*call"
# Agent activity
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -i -E "agent|maks|scout|clawexpert|makspm" | tail -20
Pattern Detection
# Repeated errors (potential loop)
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -i error | sort | uniq -c | sort -rn | head -10
# Error frequency over time
docker logs --since 1h openclaw-okny-openclaw-1 2>&1 | grep -i error | awk '{print $1}' | sort | uniq -c
Log Analysis Checklist
- Run error scan — any new error types?
- Run warning scan — any increasing warnings?
- Check activity levels — any agents silent?
- Check for repeated errors — any error loops?
- Compare to baseline — anything unusual?
- Update runbook with any new patterns found
Escalation Rules
- New error type never seen before → Investigate immediately, add to runbook
- Error count > 10 in 1 hour → Warning level escalation
- Error count > 50 in 1 hour → Critical level escalation
- Any
FATALorOOM→ Critical, immediate action - API connectivity errors → Warning, check in 5 minutes, escalate if persistent