aws-cloudwatch-investigationlisted
Install: claude install-skill sandbaseai/workbuddy-skill
# AWS CloudWatch Investigation
Investigate AWS incidents from bounded, auditable evidence. This skill helps turn a symptom into a time-bounded evidence set across CloudWatch Logs, Metrics, Alarms, CloudTrail, and AWS Health, then records what is known, uncertain, and safe to check next.
## Purpose and boundary
- Confirm account, region, environment, service, and time zone before querying.
- Use read-only access only: query logs and metrics, inspect alarms and history, read CloudTrail and Health events, and inspect deployment metadata.
- Never change dashboards, alarms, log retention, metric filters, resources, deployments, or incident state through this skill.
- Treat temporal correlation as a lead, not proof of causality; seek independent evidence and counterevidence.
## Investigation contract
Before running a query, record:
1. The reported symptom, impact hypothesis, and first-known-good/first-known-bad times.
2. Account ID, region, environment, service/resource identifiers, and the source of each identifier.
3. Query purpose, time range, log groups or namespaces, filters, limit, and expected result shape.
4. Redaction requirements and evidence retention destination.
If scope or timestamps are missing, ask for them or state the narrow assumption. Do not silently query every account or region.
## First signal and alarm correlation
Start with the earliest reliable signal, then compare it with alarm state transitions, deployment/change records, CloudTrail events, and