Operations · inspect by default
/ops-logs
Correlate available logs around a specific failure
Use for bounded log correlation; trace follows a particular execution path through source and telemetry.
Make it your own.
In Claude Code, use the slash command and add your context. In Codex, select ops-logs from the just-vibe skill picker, then send the same brief.
Version 0.11.0 also supports /jv ops-logs, /just-vibe ops-logs and /jv:ops-logs in Claude. See shortcut setup and context examples.
/just-vibe:ops-logs Correlate sanitized logs for this request ID and time window./just-vibe:ops-logs Correlate logs across services with different clock offsets./just-vibe:ops-logs Analyze a redacted excerpt without querying or dumping full production logs.What the agent does
- Normalize time zones and identify clock skew.
- Follow stable request and job IDs across related services, redacting sensitive fields.
- Distinguish original failures and root events from retry cascades and repeated symptoms.
Inputs
- service/environment, time window, correlation identifiers, and question.
Optional context: scope, references, constraints, successCriteria, environment, mode, budget.
Scope
- Reads
- Focused log correlation and anomaly explanation, not unrestricted telemetry export.
- Writes
- No source changes in inspect/plan. Save only requested planning artifacts. A separately requested repair uses the relevant implementation workflow.
- Mode
- Inspect; service/environment, time window, correlation identifiers, and question.
- Prerequisites
- Exact service/environment, time window, revision/configuration identity, authorized logs/metrics, and operational constraints. Prefer observation before intervention; live restarts, traffic changes, restores, and notifications require the requested target/action. Redact sensitive telemetry.
Expected output
- Evidence-linked timeline with timestamps and correlation IDs, the likely causal sequence, redactions and gaps requiring metrics or traces.
How the work is checked
- Clock/time-zone differences are considered; missing logs are not proof that an event never occurred.
When to stop or clarify
- Bound query range and volume. Do not dump entire production logs into the conversation or external storage.
Handling missing context
- Infer
- Read service/environment, time window, revision, available telemetry and existing incident or recovery procedure.
- Assume
- Start from supplied logs and read-only observation; rank hypotheses without presenting an unexecuted intervention as recovery.
- Ask
- Resolve the precise target and missing authority before restart, restore, notification or traffic changes; continue evidence analysis while waiting.
Technical guidance
- Evidence
- Identify request/job IDs, service boundaries, clock skew, retention and redaction rules.
- Method
- Query bounded windows and correlate the first causal failure across retries and asynchronous stages.
- Pitfall
- Repeated downstream errors can all stem from one upstream failure; log absence can reflect sampling.
- Check
- Trace one failed and one healthy operation and document missing spans or inaccessible sources without inventing continuity.
Situational decisions
When a relevant span or time range is missing: Report the gap and query needed; absence is not proof the action never occurred.
The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.