Telemetry Querying Skill
Use this skill as the entry point for any investigation, debugging, or data question that may be answered from telemetry data. It helps you decide where the relevant signal lives (metrics, logs, traces, RUM) and tells you which reference files to load before querying.
Loading References
Before querying, load the reference files for the chosen pillar:
Safety
All query commands (cx logs, cx spans, cx metrics, cx dataprime, cx search-fields) are read-only and work in --read-only mode. They never modify data and can be run freely without --yes.
Quick Routing Guide
Use this table for obvious cases where one pillar is the clear first choice:
For ambiguous questions (e.g., "How much money did users spend last week?"), the signal could live in any pillar. Follow the Discovery Workflow below.
Discovery Workflow
When the answer could reside in multiple pillars, run discovery in parallel to find the best source.
Step 1: Search Metrics
Check if a relevant metric exists:
If a matching metric is found, load references/promql-guidelines.md + references/metrics-querying.md and continue.
Step 2: Search Log and Span Fields
Use semantic field search to find relevant DataPrime paths:
If you know a concrete value that should appear in the data but don't know which field holds it, use value search instead. It returns the matching field keys alongside sample values, which also lets you infer the field's type (string, numeric, enum, etc.):
Requirements: cx search-fields needs a Coralogix API key or OAuth on the active profile. If credentials are missing, prompt the user to run cx profiles add <name>.
If matching fields are found:
- For logs: load
references/dataprime-reference.md+references/logs-querying.md - For spans: load
references/dataprime-reference.md+references/spans-querying.md
Step 3: Search the Codebase
When discovery results are ambiguous or you need to validate what a metric/field actually represents, search the codebase:
- Look for metric registration code (e.g.,
prometheus.NewCounter,metrics.record) - Look for log statements that emit the field (e.g.,
logger.info("transaction", ...)) - Look for span attributes (e.g.,
span.setAttribute("purchase.amount", ...))
This confirms the semantic meaning and helps you choose the right pillar.
Step 4: Choose and Query
Based on discovery results, pick the pillar with the clearest signal, load its reference files (see Loading References), then query.
Fallback and Pivoting
If your initial route yields no results, pivot to another pillar.
Example pivot paths:
- Metrics empty → try traces (per-request data) or logs (event records)
- Logs empty → try traces (structured span attributes) or metrics (aggregated counters)
- Traces empty → try logs (text-based debug output)
Do not stop after one failed attempt. Try at least two pillars before concluding the data does not exist.
CLI Commands Reference
Examples
Example 1: Business Question (Ambiguous Source)
Question: "How much money did people spend on the platform last week?"
Approach:
- Search metrics:
cx metrics search --name '*revenue*'andcx metrics search --name '*transaction*' - Search log fields:
cx search-fields "transaction amount" --dataset logs - Search span fields:
cx search-fields "payment total" --dataset spans - If a metric like
payment_total_usdexists, load metrics references and run a range query - If only logs have the data, load logs references and use DataPrime aggregation
- If traces have
purchase.amountattribute, load spans references
Example 2: Latency Question (Clear First Choice)
Question: "What's the average latency of the checkout route?"
Approach:
- First try metrics:
cx metrics search --name '*checkout*latency*'orcx metrics search --name '*http*duration*' - If a histogram metric exists, load metrics references and use
histogram_quantile - If no metric, fall back to traces: load spans references and aggregate span durations
Example 3: Frontend Performance (RUM)
Question: "Why is the dashboard page loading slowly for users?"
Approach:
- This is clearly a RUM question - load
references/rum-querying.md+references/rum-fields.md+references/dataprime-reference.md - Query web vitals and page load times with
cx dataprime query --source rum.events '...' - If RUM shows backend calls are slow, pivot to spans references for the API calls
Example 4: Error Investigation (Logs + Traces)
Question: "Why are users getting 500 errors on the payment endpoint?"
Approach:
- Check error rate metrics → load metrics references
- Search for error logs → load logs references
- Get traces for failed requests → load spans references
- Cross-reference: find trace IDs in logs, then fetch full traces for root cause
Beyond Investigation
Not every question is answered by querying data. If the user's intent is operational rather than investigative, route to the appropriate workflow skill:
Key Principles
- Load references before querying: check the Loading References table first
- Discover before querying: always run search/discovery to find the right source
- Parallel discovery: for ambiguous questions, search metrics, logs, and spans concurrently
- Validate with code: when unsure what a metric or field represents, check the codebase
- Pivot on failure: if one pillar is empty, try another before giving up

