Skip to main content
Glama
welingtoncassis

newrelic-mcp-nerdgraph

search_logs

Read-onlyIdempotent

Search application logs by service, level, trace ID, or message content to troubleshoot incidents; returns newest matches first with sensitive values masked.

Instructions

Search logs by service, level, trace id or message content.

Returns the newest matches first. Credential-shaped values in log messages are masked before the result leaves the server.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
levelNoERROR, WARN, INFO, DEBUG.
limitNo
sinceNoNRQL time window, e.g. '30 MINUTES AGO'.
trace_idNoCorrelate logs with one distributed trace.
account_idsNo
entity_guidNo
service_nameNoMatched against service.name, entity.name, faas.name.
message_containsNoSubstring match on the log message.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), and the description adds genuinely useful behavior beyond that: results are ordered newest-first and credential-shaped values are masked server-side before returning. It stops short of describing pagination/limit behavior when more than 500 matches exist, which is the one remaining trait an agent would want.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences, front-loaded with the core purpose, then the two behavioral facts. Every sentence earns its place with no padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return shape needn't be explained, and the description covers ordering plus the masking guarantee. It is nearly complete for an 8-param search tool, but omits filter-combination semantics and result-limit/truncation behavior, which matter for correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 63%, and the description only restates the four already-documented filters (service, level, trace id, message) without adding format or semantics beyond the schema. It does not compensate for the undocumented parameters (account_ids, entity_guid, limit), and it never says whether multiple filters combine as AND or OR.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (search) and resource (logs) and enumerates the filter dimensions (service, level, trace id, message content), so an agent knows exactly what the tool does. It never distinguishes itself from the adjacent summarize_log_errors or get_recent_errors siblings, so it falls short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description only implies usage; it gives no when-to-use condition, no prerequisites, and names no alternatives. With summarize_log_errors and get_recent_errors in the sibling set, the agent gets no routing signal for when a raw search beats an aggregation tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.