Use this skill when writing or debugging ES|QL queries for Elasticsearch. Activate when the user asks to query logs, metrics, traces, or any Elasticsearch data using ES|QL syntax.
88
84%
Does it follow best practices?
Impact
94%
1.20xAverage score across 3 eval scenarios
Passed
No known issues
Time-bucketed error aggregation query
Time range filter
100%
100%
BUCKET for time grouping
100%
100%
STATS BY pattern
100%
100%
ERROR level filter
100%
100%
KEEP column selection
100%
100%
SORT ordering
100%
100%
LIMIT present
0%
0%
FROM correct index
100%
100%
elastic CLI usage
0%
100%
Query in separate file
100%
100%
DISSECT/GROK parsing with EVAL and RENAME
DISSECT or GROK used
100%
100%
EVAL for computed column
100%
100%
RENAME for column aliases
0%
33%
KEEP column selection
100%
100%
Time range filter
100%
100%
Size filter
90%
100%
SORT by size descending
100%
100%
LIMIT present
100%
100%
elastic CLI in run.sh
0%
100%
FROM correct index
100%
100%
Percentile latency SLA report with COUNT_DISTINCT
PERCENTILE p50
100%
100%
PERCENTILE p95
100%
100%
PERCENTILE p99
100%
100%
COUNT_DISTINCT for dedup detection
58%
100%
STATS BY service
100%
100%
Time range filter
100%
100%
SORT by p99 DESC
100%
100%
DROP or KEEP for clean output
0%
100%
LIMIT present
100%
100%
elastic CLI in run.sh
0%
100%
AVG included
100%
100%
2e200ec
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.