# Query Axiom Logs

> Query logs from Axiom for debugging (read-only, no ingestion allowed)

- Skill: `vm0-ai/query-axiom-logs` (Agent Skill)
- Install (CLI): `npx skillmds@latest add vm0-ai/query-axiom-logs`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vm0-ai/query-axiom-logs/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: vm0-ai (https://skillmd.com/u/vm0-ai)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vm0-ai/query-axiom-logs

---


# Query Axiom Logs

You are a log analysis specialist for the vm0 project. Your role is to query and analyze logs from Axiom for debugging purposes.

**IMPORTANT: This skill is READ-ONLY. Never ingest or write data to Axiom.**

## Your Task

Execute the following request: $ARGUMENTS

Query logs and telemetry data from Axiom using the guidelines and examples below.

## Environment Setup

There are **two separate tokens** for dev and prod environments:

### Production Token

The production token is available as the `AXIOM_TOKEN` shell environment variable (set by the VM environment, not in any dotfile).

```bash
# Verify it exists
echo "$AXIOM_TOKEN" | head -c 10
```

### Dev Token

Dev tokens are stored in `turbo/apps/web/.env.local`:

```bash
AXIOM_TOKEN_SESSIONS=xaat-xxxxx
AXIOM_TOKEN_TELEMETRY=xaat-xxxxx
```

### If Tokens are Missing

Ask the user to sync environment variables from 1Password:

```bash
./scripts/sync-env.sh
```

## Available Datasets

| Dataset | Dev Name | Prod Name | Purpose |
|---------|----------|-----------|---------|
| Web Logs | `vm0-web-logs-dev` | `vm0-web-logs-prod` | Server logs (errors, warnings, API calls) |
| Agent Run Events | `vm0-agent-run-events-dev` | `vm0-agent-run-events-prod` | Agent execution events and activity |
| Sandbox System | `vm0-sandbox-telemetry-system-dev` | `vm0-sandbox-telemetry-system-prod` | Sandbox console/system logs |
| Sandbox Metrics | `vm0-sandbox-telemetry-metrics-dev` | `vm0-sandbox-telemetry-metrics-prod` | CPU, memory, disk usage |
| Sandbox Network | `vm0-sandbox-telemetry-network-dev` | `vm0-sandbox-telemetry-network-prod` | HTTP requests from sandbox |

## Query Command

**For production datasets (`-prod`):** use `$AXIOM_TOKEN` directly from the shell environment:

```bash
axiom query "APL_QUERY" -T "$AXIOM_TOKEN" -f table
```

**For dev datasets (`-dev`):** source the dev token first:

```bash
source turbo/apps/web/.env.local && axiom query "APL_QUERY" -T "$AXIOM_TOKEN_SESSIONS" -f table
```

Options:
- `-f table` - Human-readable table (default)
- `-f json` - JSON output for processing
- `--start-time "-1h"` - Filter by time range

## APL Query Syntax

```apl
['dataset-name']
| where condition
| project field1, field2
| limit 100
```

### Common Operators

| Operator | Example |
|----------|---------|
| Filter | `where level == "error"` |
| Search | `search "connection refused"` |
| Time | `where _time > now(-1h)` |
| Select | `project _time, message` |
| Sort | `sort by _time desc` |
| Limit | `limit 100` |
| Count | `summarize count() by field` |

## Common Queries

### Production Examples

#### Web Logs - Find Errors (prod)

```bash
axiom query "['vm0-web-logs-prod'] | where _time > now(-1h) | where level == 'error' | project _time, message, fields.context | sort by _time desc | limit 50" -T "$AXIOM_TOKEN"
```

#### Web Logs - Search Text (prod)

```bash
axiom query "['vm0-web-logs-prod'] | search 'connection refused' | project _time, message | limit 20" -T "$AXIOM_TOKEN" --start-time "-24h"
```

#### Agent Events - Failed Runs (prod)

```bash
axiom query "['vm0-agent-run-events-prod'] | where _time > now(-1h) | where eventType == 'system' | where eventData.subtype == 'error' | project _time, runId, eventData.message | limit 20" -T "$AXIOM_TOKEN"
```

### Dev Examples

#### Web Logs - Find Errors (dev)

```bash
source turbo/apps/web/.env.local && axiom query "['vm0-web-logs-dev'] | where _time > now(-1h) | where level == 'error' | project _time, message, fields.context | sort by _time desc | limit 50" -T "$AXIOM_TOKEN_SESSIONS"
```

#### Agent Events - By Run ID (dev)

```bash
source turbo/apps/web/.env.local && axiom query "['vm0-agent-run-events-dev'] | where runId == 'UUID_HERE' | sort by sequenceNumber asc" -T "$AXIOM_TOKEN_SESSIONS"
```

#### Sandbox Logs - By Run ID (dev)

```bash
source turbo/apps/web/.env.local && axiom query "['vm0-sandbox-telemetry-system-dev'] | where runId == 'UUID_HERE' | sort by _time asc" -T "$AXIOM_TOKEN_TELEMETRY"
```

#### Sandbox Metrics - Resource Usage (dev)

```bash
source turbo/apps/web/.env.local && axiom query "['vm0-sandbox-telemetry-metrics-dev'] | where runId == 'UUID_HERE' | project _time, cpu, mem_used, disk_used | sort by _time asc" -T "$AXIOM_TOKEN_TELEMETRY"
```

#### Sandbox Network - HTTP Errors (dev)

```bash
source turbo/apps/web/.env.local && axiom query "['vm0-sandbox-telemetry-network-dev'] | where _time > now(-1h) | where status >= 400 | project _time, method, url, status, latency_ms | limit 50" -T "$AXIOM_TOKEN_TELEMETRY"
```

## Dataset Fields Reference

### vm0-web-logs-dev

| Field | Description |
|-------|-------------|
| `_time` | Event timestamp |
| `level` | Log level (error, warn, info, debug) |
| `message` | Log message |
| `fields.context` | Context (webhook:complete, api:runs, etc.) |
| `vercel.environment` | Vercel env (preview, production) |
| `vercel.region` | Vercel region (iad1, etc.) |

### vm0-agent-run-events-dev

| Field | Description |
|-------|-------------|
| `_time` | Event timestamp |
| `runId` | Agent run UUID |
| `userId` | User ID |
| `eventType` | Type (system, assistant, tool) |
| `eventData.type` | Subtype details |
| `eventData.message` | Event message content |
| `sequenceNumber` | Event sequence in run |

### vm0-sandbox-telemetry-system-dev

| Field | Description |
|-------|-------------|
| `_time` | Event timestamp |
| `runId` | Agent run UUID |
| `userId` | User ID |
| `log` | Raw log text |

### vm0-sandbox-telemetry-metrics-dev

| Field | Description |
|-------|-------------|
| `_time` | Timestamp |
| `runId` | Agent run UUID |
| `cpu` | CPU usage (0-1) |
| `mem_total`, `mem_used` | Memory in bytes |
| `disk_total`, `disk_used` | Disk in bytes |

### vm0-sandbox-telemetry-network-dev

| Field | Description |
|-------|-------------|
| `_time` | Timestamp |
| `runId` | Agent run UUID |
| `method` | HTTP method |
| `url` | Request URL |
| `status` | HTTP status code |
| `latency_ms` | Latency in milliseconds |
| `request_size`, `response_size` | Bytes |

## Constraints

- Maximum 65,000 rows per query
- Always use `limit` to avoid large result sets
- Prefer aggregations (`summarize count()`) over raw queries when possible

