Grafana Lens
Grafana tools for data visualization, monitoring, alerting, security, SRE investigation, and data collection pipeline management via Alloy. Use grafana_query...
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.5.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.5.0release · observed Apr 5, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bkftvrp76wq7nwsmqa236nh83ps7x:grafana-lens- Install using `clawhub skill install s17bkftvrp76wq7nwsmqa236nh83ps7x:grafana-lens` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/awsome-o/grafana-lens before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-awsome-o-grafana-lens/snapshot"
Documentation
CLAWHUB
153,921 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: grafana-lens
description: "Grafana tools for data visualization, monitoring, alerting, security, SRE investigation, and data collection pipeline management via Alloy. Use grafana_query, grafana_query_logs, grafana_query_traces, grafana_create_dashboard, grafana_update_dashboard, grafana_create_alert, grafana_share_dashboard, grafana_annotate, grafana_explore_datasources, grafana_list_metrics, grafana_search, grafana_get_dashboard, grafana_check_alerts, grafana_push_metrics, grafana_explain_metric, grafana_security_check, grafana_investigate, and alloy_pipeline. Trigger when asked about metrics, dashboards, monitoring, alerts, costs, token usage, data visualization, PromQL, Prometheus, LogQL, Loki, log queries, error logs, log search, TraceQL, Tempo, traces, distributed tracing, span search, find slow traces, debug session traces, annotations, deployments, sharing charts, investigating alert notifications, pushing custom data (calendar, git, fitness, finance) to Grafana for visualization, pushing historical data, backfilling metrics, recording past data with timestamps, modifying dashboards, adding panels, removing panels, changing dashboard settings, updating dashboard time range, explain metric, metric trend, what is this metric, how has this changed, is this metric normal, why did my bill spike, cost visibility, security monitoring, security check, security audit, am I being attacked, is my agent compromised, suspicious activity, threat detection, prompt injection detection, set up security alerts, investigate, debug, triage, root cause, what's wrong, why is X broken, anomaly detection, RED method, USE method, alert fatigue, postmortem, incident summary, collect metrics from, monitor my database, monitor my app, scrape endpoint, set up log collection, collect Docker logs, tail log files, collect Kubernetes logs, receive OTLP, set up trace collection, data collection pipeline, Alloy pipeline, pipeline status, pipeline health, node exporter, system metrics, postgres exporter, mysql exporter, redis exporter, syslog, Grafana Alloy."
metadata:
{
"openclaw":
{
"emoji": "🔭",
"requires": { "config": ["grafana.url", "grafana.apiKey"] },
},
}
---
# Grafana Lens
You have full native Grafana access — query data, create dashboards, set alerts, receive alert notifications, annotate events, explore datasources, push custom data, and deliver visualizations inline. Works with ANY data in Grafana, not just agent metrics.
## Musts
- **Always call `grafana_explore_datasources` first** when you need a datasource UID — never guess UIDs
- **Always call `grafana_search` before creating a dashboard** — avoid duplicates
- **Always call `grafana_get_dashboard` before `grafana_share_dashboard`** — you need exact panel IDs
- **Always call `grafana_get_dashboard` before `grafana_update_dashboard`** — you need panel IDs and current structure
- **Prefer `grafana_query` for direct answers** over creating dashboards — "what's mREADME.md
# Grafana Lens **Agent-driven Grafana observability for OpenClaw — query, visualize, alert, trace, and share across 15+ messaging channels.** > **Note:** This is a community-built OpenClaw plugin, not an official Grafana Labs product. Grafana, Loki, Tempo, and Prometheus are trademarks of Grafana Labs. [OpenClaw](https://openclaw.com) is an open-source AI agent platform. Grafana Lens extends it with full Grafana integration — 18 composable tools that let your agent query metrics and logs, trace distributed requests, create dashboards, set up alerts, render charts, run security audits, investigate incidents, push custom data, and manage data collection pipelines — all through natural language conversation. --- ## Why Grafana Lens? | Pain Point | How Grafana Lens Helps | |---|---| | **"Where did my budget go?"** | Cost dashboards with model-level attribution, token tracking, and cost anomaly alerts | | **"Is my agent stuck in a loop?"** | Real-time tool loop detection, stuck session monitoring, and SRE operations dashboard | | **"Am I being prompt-injected?"** | 12-pattern prompt injection detection with security dashboard and threat-level reporting | | **"I need observability but don't want another SaaS"** | Fully self-hosted, open source, OTLP-native — runs on a free local Grafana stack | | **"I can't debug multi-step agent sessions"** | Hierarchical traces: session → LLM call → tool execution, with log-to-trace correlation | | **"My alert fired — now what?"** | `grafana_investigate` gathers metrics, logs, traces in parallel and generates hypotheses with specific tool+params for follow-up | | **"I want to track my own data in Grafana"** | Push any custom metrics (fitness, calendar, git, finance) from conversation | | **"How do I get my data INTO Grafana?"** | `alloy_pipeline` sets up data collection from databases, Docker, Kubernetes, log files, and more — 29 recipes, just describe what you want to monitor | --- ## Key Features - **18 Composable Agent Tools** — Query PromQL/LogQL/TraceQL, create dashboards, set alerts, share panel images, run security checks, investigate incidents, push custom metrics, manage data collection pipelines, and more - **SRE Investigation** — Multi-signal triage (`grafana_investigate`), anomaly scoring with z-score against 7-day baselines, seasonality comparison, and alert fatigue detection - **Full OTLP Observability** — Metrics → Prometheus, Logs → Loki, Traces → Tempo. Push-based with no scraping — data is available immediately - **Security Monitoring** — 6-check threat assessment covering prompt injection, cost anomalies, tool loops, session enumeration, webhook errors, and stuck sessions - **12 Pre-Built Dashboard Templates** — From LLM Command Center and Cost Intelligence to Security Overview and SRE Operations - **Custom Data Observatory** — Push any external data (calendar events, git commits, fitness stats, financial metrics) into Grafana via conversation - **Works with ANY Datasource** — Not limited
_meta.json
{
"ownerId": "kn785ebhh3a5v4pqymw1yhz6wh8292pc",
"slug": "grafana-lens",
"version": "0.5.0",
"publishedAt": 1775407137121
}references/agent-metrics.md
# Agent Metrics Reference Metrics come from two sources — both push via OTLP to the same collector/Mimir instance and are queryable in Grafana. ## Core Agent Telemetry (from diagnostics-otel) These are published by OpenClaw's built-in `diagnostics-otel` extension. Grafana Lens dashboards query them but does not collect them. | Prometheus Name | Type | Labels | Source Event | |----------------|------|--------|-------------| | `openclaw_tokens_total` | counter | `openclaw_token`, `openclaw_model`, `openclaw_provider`, `openclaw_channel` | `model.usage` | | `openclaw_cost_usd_total` | counter | `openclaw_model`, `openclaw_provider`, `openclaw_channel` | `model.usage` | | `openclaw_run_duration_ms_milliseconds` | histogram | `openclaw_model`, `openclaw_provider`, `openclaw_channel` | `model.usage` | | `openclaw_context_tokens` | histogram | `openclaw_context` (limit/used), `openclaw_model`, `openclaw_provider`, `openclaw_channel` | `model.usage` | | `openclaw_message_processed_total` | counter | `openclaw_outcome`, `openclaw_channel` | `message.processed` | | `openclaw_message_duration_ms_milliseconds` | histogram | `openclaw_outcome`, `openclaw_channel` | `message.processed` | | `openclaw_message_queued_total` | counter | `openclaw_channel`, `openclaw_source` | `message.queued` | | `openclaw_webhook_received_total` | counter | `openclaw_channel`, `openclaw_webhook` | `webhook.received` | | `openclaw_webhook_error_total` | counter | `openclaw_channel`, `openclaw_webhook` | `webhook.error` | | `openclaw_webhook_duration_ms_milliseconds` | histogram | `openclaw_channel`, `openclaw_webhook` | `webhook.processed` | | `openclaw_queue_depth` | histogram | `openclaw_lane`, `openclaw_channel` | `message.queued`, `queue.lane.*`, `heartbeat` | | `openclaw_queue_wait_ms_milliseconds` | histogram | `openclaw_lane` | `queue.lane.dequeue` | | `openclaw_queue_lane_enqueue_total` | counter | `openclaw_lane` | `queue.lane.enqueue` | | `openclaw_queue_lane_dequeue_total` | counter | `openclaw_lane` | `queue.lane.dequeue` | | `openclaw_session_state_total` | counter | `openclaw_state`, `openclaw_reason` | `session.state` | | `openclaw_session_stuck_total` | counter | `openclaw_state` | `session.stuck` | | `openclaw_session_stuck_age_ms_milliseconds` | histogram | `openclaw_state` | `session.stuck` | | `openclaw_run_attempt_total` | counter | `openclaw_attempt` | `run.attempt` | **Label names use underscores** (OTel dots → Prometheus underscores): `openclaw.model` → `openclaw_model`. **OTel unit suffix**: Histograms declared with `unit: "ms"` get `_milliseconds` appended in Prometheus (OTLP-to-Prometheus translation). So the OTel instrument `openclaw_run_duration_ms` becomes `openclaw_run_duration_ms_milliseconds_bucket` in PromQL. All PromQL in this doc uses the physical Prometheus names. **Label value reference**: - `openclaw_token`: `input`, `output`, `cache_read`, `cache_write`, `prompt`, `total` - `openclaw_context`: `limit`, `used` - `openclaw_outcome`: `co
references/alloy-components.md
# Alloy Component Reference — Escape Hatch Companion
When no recipe fits, compose raw Alloy configs using these component patterns.
Use `alloy_pipeline` with `config` param + optional `sampleQueries` for data verification.
## Table of Contents
- [Log Sources](#log-sources)
- [Log Processing](#log-processing)
- [Metrics Exporters](#metrics-exporters)
- [OTel Processors](#otel-processors)
- [OTel Connectors](#otel-connectors)
- [Profiling](#profiling)
- [Frontend](#frontend)
- [Wiring Patterns](#wiring-patterns)
---
## Log Sources
### loki.source.gelf — GELF UDP Log Source
Receives GELF (Graylog Extended Log Format) logs over UDP. Common with Graylog, Docker GELF driver.
```alloy
loki.source.gelf "my_gelf" {
forward_to = [loki.write.default.receiver]
}
```
Default: listens on `0.0.0.0:12201` (UDP). Override with `use_incoming_timestamp = true`.
Labels: Auto-extracts `__gelf_message_host`, `__gelf_message_level`, `__gelf_message_facility`.
Use `loki.relabel` to promote `__gelf_*` labels.
**Sample queries**: `{source="gelf"}`, `{source="gelf"} |= "error"`
### loki.source.api — Loki Push API Endpoint
Accepts logs via Loki-compatible HTTP push API. Use for centralized log gateways, TCP JSON ingestion.
```alloy
loki.source.api "push" {
http {
listen_address = "0.0.0.0"
listen_port = 3500
}
forward_to = [loki.process.parse.receiver]
}
```
**Sample queries**: `{source="push-api"}`, `rate({source="push-api"}[5m])`
### loki.source.kafka — Kafka Log Consumer
Consumes log messages from Apache Kafka topics.
```alloy
loki.source.kafka "logs" {
brokers = ["kafka:9092"]
topics = ["app-logs"]
consumer_group = "alloy"
forward_to = [loki.process.parse.receiver]
}
```
Authentication: Add `authentication { type = "sasl" ... }` block for SASL/SCRAM.
**Sample queries**: `{source="kafka"}`, `{source="kafka", topic="app-logs"}`
### loki.source.windowsevent — Windows Event Logs
Collects Windows Event Log entries. Windows-only.
```alloy
loki.source.windowsevent "events" {
eventlog_name = "Application"
forward_to = [loki.process.parse.receiver]
}
```
Common event logs: `"Application"`, `"System"`, `"Security"`.
**Sample queries**: `{source="windowsevent"}`, `{source="windowsevent"} |= "error"`
---
## Log Processing
Insert `loki.process` between source and `loki.write` for parsing, enrichment, and routing.
### stage.json — JSON Field Extraction
```alloy
loki.process "parse" {
stage.json {
expressions = {
"timestamp" = "",
"level" = "",
"message" = "",
"request_id" = "context.request_id",
}
}
forward_to = [loki.write.default.receiver]
}
```
Empty string `""` extracts the top-level key matching the name. Dotted paths extract nested fields.
### stage.labels — Promote Fields to Labels
```alloy
stage.labels {
values = {
"level" = "",
"service" = "",
}
}
```
Promotes extracted fields to Loki index labels. Use sparingly — high-cardinAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/awsome-o/skills/grafana-lens",
"sourceUrl": "https://clawhub.ai/awsome-o/skills/grafana-lens",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:57:39.886Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-awsome-o-grafana-lens/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-awsome-o-grafana-lens/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T05:57:39.886Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceUrl": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:57:39.886Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.5.0",
"href": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceUrl": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-05T16:38:57.121Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-awsome-o-grafana-lens/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-awsome-o-grafana-lens/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.5.0",
"description": "Major update: Adds Alloy pipeline management, new recipes, and greatly expands data collection capabilities. - Introduced Alloy pipeline management with the new `alloy_pipeline` tool and support for recipes, creation, status, diagnosis, and deletion actions. - Added dozens of Alloy pipeline recipes and helpers for setting up metrics, logs, traces, exporters, and agent integrations. - Expanded documentation and quickstart references for Alloy, pipeline composition, and common data-collection use cases. - Extended the SKILL to include scenarios for managing data collection pipelines, collecting logs and metrics from multiple sources, and handling credentials securely. - Updated and refined limits, troubleshooting, and best-practices guidance in user instructions.",
"href": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceUrl": "https://clawhub.ai/awsome-o/grafana-lens",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-05T16:38:57.121Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
