Query and analyze Claude Code observability data (metrics, logs, traces). Use when analyzing performance, costs, errors, tool usage, sessions, conversations, or subagents.
64
76%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./skills/observability-analyzer/SKILL.mdQuery Claude Code telemetry and generate insights from metrics, logs, and traces. Works with both default OTEL telemetry and enhanced hook-based telemetry.
| Source | Job Name | Contains |
|---|---|---|
| Default OTEL | claude_code | API metrics, token usage, costs |
| Enhanced Hooks | claude_code_enhanced | Sessions, conversations, tools, subagents |
query-metrics <promql>Execute PromQL query against Prometheus.
query-metrics 'sum(claude_code_token_usage)[7d]'query-logs <logql>Execute LogQL query against Loki.
query-logs '{job="claude_code_enhanced", event_type="tool_call"} | json' --since 24hanalyze-errorsDetect and group error patterns from enhanced telemetry.
{job="claude_code_enhanced", event_type="tool_result", status="error"} | jsonOutput: Error types, frequencies, affected tools, recommendations.
analyze-performanceIdentify slow operations and response sizes.
{job="claude_code_enhanced", event_type="tool_result"} | json | response_length > 50000Output: Large responses, estimated token costs, slow patterns.
analyze-costsCalculate token usage from content size estimates.
sum by (repo) (sum_over_time({job="claude_code_enhanced", event_type="context_utilization"} | json | unwrap estimated_session_tokens [24h]))Output: Token estimates by repo, session costs, projections.
analyze-toolsTool usage statistics and sequences.
sum by (tool) (count_over_time({job="claude_code_enhanced", event_type="tool_call"} | json [24h]))Output: Call frequency, success rates, tool sequences, common patterns.
analyze-sessionsSession lifecycle and duration analytics.
{job="claude_code_enhanced", event_type="session_end"} | jsonOutput: Session durations, turn counts, tools per session, termination reasons.
analyze-conversationsConversation and prompt analytics.
sum by (pattern) (count_over_time({job="claude_code_enhanced", event_type="user_prompt"} | json [24h]))Output: Prompt patterns (question/debugging/creation/ultrathink), turn distribution.
analyze-subagentsSubagent/Task tool usage.
{job="claude_code_enhanced", event_type="tool_call", tool="Task"} | jsonOutput: Subagent types used, completion rates, parallel execution patterns.
analyze-skillsSkill invocation analytics.
sum by (skill_name) (count_over_time({job="claude_code_enhanced", event_type="skill_usage"} | json [24h]))Output: Most used skills, skill usage by repo, trends.
analyze-contextContext window utilization.
{job="claude_code_enhanced", event_type="context_utilization"} | json | context_percentage > 50Output: High utilization sessions, compaction events, token efficiency.
analyze-reposRepository/project activity.
sum by (repo, tool) (count_over_time({job="claude_code_enhanced", event_type="tool_call"} | json [24h]))Output: Activity per repo, tool usage by project, branch patterns.
generate-reportComprehensive analysis report (all dimensions). Output: Markdown report with errors, performance, costs, sessions, conversations, tools.
# All events (last hour)
{job="claude_code_enhanced"} | json
# Session analytics
{job="claude_code_enhanced", event_type="session_end"} | json | duration_seconds > 300
# Tool errors
{job="claude_code_enhanced", event_type="tool_result", status="error"} | json
# High context usage
{job="claude_code_enhanced", event_type="context_utilization"} | json | context_percentage > 75
# Subagent spawns
{job="claude_code_enhanced", event_type="tool_call", tool="Task"} | json
# Skill invocations
{job="claude_code_enhanced", event_type="skill_usage"} | json
# Prompt patterns
{job="claude_code_enhanced", event_type="user_prompt"} | json | pattern="ultrathink"
# Tool sequences
{job="claude_code_enhanced", event_type="tool_call"} | json | line_format "{{.tool_name}} → {{.previous_tool}}"
# Context compaction
{job="claude_code_enhanced", event_type="context_compact"} | json
# Permission requests
{job="claude_code_enhanced", event_type="permission_request"} | json# Total token usage (7 days)
sum(increase(claude_code_token_usage[7d]))
# Error rate by tool
sum by (tool_name) (rate(claude_code_tool_result{status="failure"}[1h]))
# P95 tool latency
histogram_quantile(0.95, claude_code_tool_duration_bucket)
# Daily costs
sum(increase(claude_code_cost_usage[24h]))| Event Type | Description | Key Fields |
|---|---|---|
session_start | Session initialization | source, permission_mode |
session_end | Session termination | duration_seconds, turn_count, tools_used |
user_prompt | User message submitted | pattern, prompt_length, estimated_tokens |
tool_call | Tool invocation | tool_name, tool_details, sequence_position |
tool_result | Tool completion | status, response_length, is_error |
skill_usage | Skill invoked | skill_name |
context_utilization | Token estimate | estimated_session_tokens, context_percentage |
context_compact | Compaction event | trigger (manual/auto) |
subagent_complete | Task agent finished | total_subagents |
permission_request | Permission dialog | notification_type |
notification | System notification | notification_type |
Access: http://localhost:3000 (admin/admin)
scripts/query-prometheus.sh - PromQL query helperscripts/query-loki.sh - LogQL query helperscripts/analyze-errors.sh - Error analysis automationscripts/analyze-sessions.sh - Session analyticsscripts/generate-report.sh - Full analysis report93ed392
Also appears in
since Sep 12, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.