Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Use when investigating dropped network traffic, packet drops, drop reasons, VPC Flow Logs (including Private Service Connect / PSC, serverless / App Engine Direct VPC, and cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.
Permissions
Files
Investigates Google Cloud networking issues by analyzing GCP logs, metrics, and diagnostics. Use when investigating dropped network traffic, packet drops, drop reasons, VPC Flow Logs (including Private Service Connect / PSC, serverless / App Engine Direct VPC, and cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.
Version history
big_query_linked_dataset, _AllLogs) before using Cloud Logging for
high-volume analysis or aggregations. This is the preferred method for
finding trends or top-blocking rules.LIMIT 1 in SQL or --limit=1 in gcloud logging read) to verify
the exact payload schema and field paths.EXCLUDE_ALL_METADATA, causing VM names to be NULL in VPC Flow Logs. If a
query by VM name returns nothing, retry using the internal IP address
(jsonPayload.connection.src_ip).run_shell_command with gcloud to list resources in the project.gcloud or bq only if MCP servers are unavailable.
DO NOT use gcloud monitoring; it is restricted. Immediately use the curl
templates in metrics-analysis.md.If a BigQuery query fails with an 'Unrecognized name' error or schema mismatch:
bq show --schema --format=json {project_id}:{dataset_id}.{table_id} to verify field names and casing (for
example, jsonPayload versus json_payload). 2. Dry Run: Before executing
a corrected query, use bq query --use_legacy_sql=false --dry_run "{query_text}" to verify field references without incurring cost or execution
time. 3. Retry: Apply identified fixes to the original query and execute.For detailed SQL patterns, field definitions, and advanced troubleshooting, read the corresponding reference file:
CRITICAL: If the user asks for Cost Estimation, you MUST strictly use
references/vpc-flow-logs-cost-estimation.md. Do NOT read or usereferences/vpc-flow-analysis.mdfor cost estimation tasks.
In these kits
More from @google
Works with
Claude, Codex, Cursor & more