Use this skill whenever the user wants to search, inspect, or investigate service logs — including finding errors, tracing requests by correlation/trace ID, debugging incidents, checking service health via log evidence, or counting error occurrences. Trigger even for casual phrasing like 'what went wrong', 'why did X fail', 'check the logs for Y', or 'did service Z have errors between 2-4am'. Splunk/watchtower is the backend; this skill is read-only and handles index coverage validation automatically.