---
title: "sparklogs"
description: "Query and analyze SparkLogs: system and application logs plus device health and state over time, one host or the fleet."
canonical: https://agentpluginsdirectory.com/plugins/sparklogs
last-updated: 2026-10-02
---

# sparklogs
Query and analyze SparkLogs: system and application logs plus device health and state over time, one host or the fleet.
- Slug: sparklogs
- Publisher: IT Lightning, LLC
- Repository: https://github.com/itlightning/sparklogs-ai-plugins
- Manifest: plugins/generic/sparklogs/plugin.json
- Version: 1.8.0
- License: Apache-2.0
- Category (editorial): devops-cloud
- Skills: 4 (sparklogs-analyze-cause, sparklogs-ask, sparklogs-feedback, sparklogs-investigate)
- MCP servers: 1 (sparklogs)
- Stars: 0
- Repository created: 2026-05-01
- Repository last pushed: 2026-10-01
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/sparklogs
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What sparklogs does, in the publisher's words

Investigation skills for SparkLogs MCP, packaged to Agent Plugins v1.

- plugin.json: the Agent Plugins manifest.
- skills/: sparklogs-ask, sparklogs-investigate, sparklogs-analyze-cause, in the Agent Skills layout. Each skill carries the reference corpus it cites under its own references directory, so a skill directory is self-contained.
- mcp.json: the SparkLogs MCP server, transport streamable-http. Hosts find it at the plugin root by convention. URL and transport only; sign in with SparkLogs (OAuth) when the host prompts.

Commands, rules, and subagents are host-specific formats that Agent Plugins v1 does not define, so they are not in this package. They ship in the Claude and Cursor packages.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/itlightning/sparklogs-ai-plugins/HEAD/plugins/generic/sparklogs/README.md

## Skills

- sparklogs-analyze-cause: From a prior SparkLogs investigation summary, derive candidate cause hypotheses with confirm/refute steps and confidence. Use when the engineer wants cause analysis after findings exist.
- sparklogs-ask: Query SparkLogs logs and device health/state over time to answer what happened on a host or across a fleet. Counts, timelines, disk, CPU, patches, Windows events, other system and application log events, installed software, collection health. Conversational answers from SparkLogs telemetry.
- sparklogs-feedback
- sparklogs-investigate: Cited SparkLogs investigation: gather logs and device health/state into a structured system-condition summary with query URLs, confidence, and what was not checked. Use when the engineer needs a thorough ticket write-up or a full investigation report.

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- sparklogs: transport: streamable-http; url: https://mcp.sparklogs.app/mcp

Read from the plugin's own mcp.json. Environment variable names only, never values.
