Skip to main content
Glama

Count logs

count_logs
Read-onlyIdempotent

Get the exact number of log messages matching a query to size a problem. Use it to assess issue scope before deeper investigation.

Instructions

Exact number of messages matching a query. Cheap; use it to size a problem.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
queryNoLucene query, '*' for everything*
rangeNoRelative range ending now (or at to_time): '15m', '2h', '1d', '1h30m'
streamsNoStream titles or ids to search in; all streams when omitted
to_timeNoAbsolute end, same formats as from_time; default now
instanceNoGraylog instance (environment) from list_instances, e.g. 'staging' or 'prod'; the default instance when omitted
from_timeNoAbsolute start: ISO 8601 or 'YYYY-MM-DD HH:MM' in the instance timezone; overrides range

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint and destructiveHint=false, so the safety profile is covered. The description's only added behavioral claim is 'Cheap', which is a genuine cost signal not present in the structured fields, but it says nothing about count caps, accuracy limits, or whether the count is bounded.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences with zero filler, and the returned value is front-loaded ahead of the cost hint. Every clause carries information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a parameter-rich but conceptually simple read tool with a full-coverage schema, a complete annotation safety profile and a stated return value, the description is adequate. It omits only what to do with the count or how it compares to the histogram, which is a minor gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% across all six parameters, so query syntax, range formats, streams, instance and the from_time-overrides-range rule are all documented in the schema. The description adds no parameter detail, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: returns the exact number of messages matching a query. The word 'Exact' usefully contrasts with the histogram sibling, but no sibling is named, so an agent still has to infer the boundary with log_histogram or search_logs.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'use it to size a problem' implies a usage pattern (cheap pre-flight sizing before heavier queries) but gives no explicit when-not guidance and never names the alternatives (search_logs, log_histogram) that an agent should pick when it needs the messages themselves rather than a tally.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.