log-analyzer

Identify error, authentication failure, and suspicious access patterns across service logs.

Updated Feb 21, 2026
One-click install
npx skills add https://github.com/abzhaw/juliaz_agents --skill log-analyzer-abzhaw
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: log-analyzer
Source: https://github.com/abzhaw/juliaz_agents/tree/main/meta/agents/security-agent/skills/06-log-analyzer
Command: npx skills add https://github.com/abzhaw/juliaz_agents --skill log-analyzer-abzhaw

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Logs are the primary source of system visibility. This skill reduces manual log triage by quickly spotting spikes in errors, authentication failures, and suspicious access patterns.

Core Features & Use Cases

  • Cross-service log scanning for errors, auth failures, and anomalous access patterns.
  • Trend-based alerting and concise risk summaries suitable for incident response.
  • Use Case: SOC or DevOps teams detect breaches or misconfigurations and initiate rapid remediation.

Quick Start

Scan all service logs for error spikes, failed auth attempts, and suspicious access patterns in the last 24 hours.

Frequently Asked Questions about log-analyzer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect authentication failures and suspicious access patterns in service logs?

Log analysis for anomaly detection works by scanning cross-service logs to identify spikes in errors, authentication failures, and suspicious access patterns. It applies threshold-based alerts and duration-based trends to generate concise risk summaries with highlighted signals for incident response.

How do I scan PM2 logs for error spikes and anomalies?

You can scan PM2 logs for error spikes by applying cross-service log scanning that targets PM2, startup, bridge, orchestrator, frontend, and Docker logs. The analyzer identifies duration-based trends and threshold-based alerts, outputting an actionable summary with highlighted risk signals.

Does log analysis work with Docker logs for security breach detection?

Yes, log analysis works with Docker logs for security breach detection by scanning relevant Docker logs alongside PM2, bridge, orchestrator, and frontend logs. It identifies authentication failures and suspicious access patterns, applying threshold-based alerts to output concise risk summaries for incident response.

What is the best way to triage service logs for incident response?

The best way to triage service logs for incident response is cross-service log scanning that applies duration-based trends and threshold-based alerts to identify error spikes and authentication failures. This reduces manual triage by generating concise, actionable risk summaries with highlighted signals.

Can I use anomaly detection to monitor cross-service logs without manual threshold configuration?

Anomaly detection for cross-service logs identifies suspicious access patterns and error spikes by applying duration-based trends and threshold-based alerts across PM2, Docker, bridge, orchestrator, and frontend logs. It outputs a concise, actionable summary with highlighted risk signals, reducing manual triage.