Ask Claude about your Custom Logs file, in plain English
Connect Claude, Claude Code, Cursor or any MCP client to Query Streams once. Claude reads the structure of your Custom Logs file, writes the SQL, runs it read-only through the Agent that already sits with your data, and answers with the rows. No database password ever reaches the AI. About ten minutes, and the Free plan covers it.
What you’ll end up with
A Claude that can answer questions about any text log you describe with live, read-only queries over the tables the Agent builds from your files, and tell you which file each answer came from — without ever seeing a login or a file path, and without a firewall change: the Agent already inside your network reads the folder and sends back only the rows. Once the Agent is in place, connecting Claude takes about 90 seconds if you are comfortable with a settings screen. Like this:
What errors did the backup job log overnight?
This connector has a format with a Timestamp defined. Claude reads the columns of fileset.events, then runs one query for ERROR and WARN messages between midnight and 6 a.m., ordered by event_time:
| event_time | file_name | message |
|---|---|---|
| 2026-09-26 02:14:07 | backup.log | ERROR copy failed: access denied on /mnt/nas01/archive |
| 2026-09-26 02:15:09 | backup.log | WARN retrying in 60 s (attempt 2 of 3) |
| 2026-09-26 02:17:11 | backup.log | ERROR giving up after 3 attempts |
The job lost access to the archive share at 02:14 and gave up three minutes later. Ask Claude how many nights this month ended the same way. The answer covers what the Agent had read at its last scan.
How often does the backup job fail, and is it the same problem every time?
I took each night’s run from fileset.events, matched the start and finish lines, and pulled the failing path out of any ERROR line:
| Night | Result | Failing path | Duration |
|---|---|---|---|
| 25 Sep | OK | — | 1 h 42 m |
| 26 Sep | FAILED | /mnt/nas01/archive | 0 h 09 m |
| 27 Sep | FAILED | /mnt/nas01/archive | 0 h 08 m |
Two nights running, same path, and it aborts nine minutes in with access denied rather than running out of space. Something changed the permissions on the NAS archive share on the 26th. Until it is fixed you have no backup newer than the 25th.
Rather not wire up an AI client at all? On the Business plan, Nova is the assistant built into Query Streams itself. It has every tool Claude gets here, plus the ones Claude does not: it drafts and validates the SQL against your Schema Intelligence model, turns the answer into a chart, and saves the result as a query your team can run from Excel, Google Sheets or the REST API — no key, no connector, nothing to install. Use MCP when your people already live in Claude, Cursor or ChatGPT; use Nova when you want the answers inside the Portal.
Custom Log Folder is for any text log the built-in cards do not know. You describe the format once, or let Nova suggest one, and every line becomes a SQL row Claude can query. That is AI log analysis on your own files, with nothing to upload. The Agent tails each file as it grows, recognises rotated files so nothing is read twice, reads each .gz archive once, and backfills the last 30 days on first read.
What you’ll need
A Query Streams account
MCP is on every plan, including Free. Free allows one key or one connected app, which is all this guide needs. Sign up at my.querystreams.com.
The Agent on a computer that can open the folder
Version 2.6.0 or later. The folder can be on that computer or on a file share it can reach. The Agent runs as a service, so type shares as \\server\share\folder, not as a mapped drive letter. New to the Agent? Install it on Windows, macOS or Linux.
MCP switched on for you
Creators, owners and admins have it from the start. Everyone else needs an admin to flip the MCP switch beside their name under Account → Access Control. Until then the MCP page says “MCP is disabled for your account”.
An AI client
Claude on the web, Claude Desktop or the Claude mobile apps connect with no key. Claude Code, Cursor, ChatGPT and about ten other tools work too; the Portal has a ready-made recipe for each.
Where does the work happen? On the computer that runs the Agent. It scans the folder, copies the rows into a local cache there, and runs the SQL Claude writes against that cache. The files themselves never leave that computer, and neither does anything Claude did not ask for.
Set it up in four steps
-
Point the Agent at the folder
In the portal open Data → Data Agents, find the Agent that can open the folder and click its Add connector button. Under the Files & Folders pill click the Custom Log Folder card. The wizard then walks you through Folders, Check, Settings, Realm and Review:
- Folders
- Type the Root folders, one per line, as paths on the Agent’s computer. Scan subfolders is on, Max depth is 8. Include patterns starts with the right glob for this file type; add Exclude patterns if the folder holds files you do not want. A mapped drive letter shows an amber advisory: the Agent cannot see it, so use the
\\server\sharepath instead. - Check
- The Agent reads a sample of up to 64 files and shows what it will build. Nothing is created yet. Ready to create means every sampled file fits. An amber banner, “{n} of {m} file(s) will be set aside”, lists files that do not fit with Show which files and why; you can create the connector anyway and fix them later. If the folder mixes layouts, a blue panel offers Switch to one table per layout.
- Settings
- Scan interval (every hour by default, from every 5 minutes to daily) is how often the Agent looks for new, changed and vanished files. Watch folder for changes reacts within seconds on local disks. When a file vanishes is Drop its rows by default.
- Realm, Review
- Pick the Data Realm the rows count against, check the summary and click Create connector. The first scan starts right away; the connector’s Manifest tab shows what it built and any files it set aside.
- Add your log folder under Root folders and set Include patterns to match your files.
- Choose an Encoding. It is required and has no default.
- Describe the format: Record boundary, Grammar (delimited, key=value, grok, JSON lines, #Fields header or fixed width), Timestamp, Typed columns and Identity column. Or click Let Nova suggest a format, which has a daily cap.
- On Check, the Agent reads a sample and shows the file count, size, a row estimate and the tables it will build. Nothing is created yet. Test connection also offers the closest built-in log type when one fits.
-
See what tables you get
Parsed lines land in
fileset.events, or in the Table name you chose. The Agent keeps the rows in a local cache on the Agent computer and serves them as SQL. Every row says which file it came from in_source_file. Until you define a format, each line is onemessagetagged withfile_name.Table What it holds eventsOne row per record: event_time, the columns your format defines, andmessage. With no format yet,event_timeis the file’s modified time.events_raw_linesLines your format did not match, kept in linewith areasonsuch asno-grammar-match. Nothing is dropped.filesEvery log file in the folder right now, with relative_path,size_bytesandmodified_utc.files_eventsThe history of each file: appeared,modified,rotated,truncatedanddriftrows, timed byevent_at.log_cursorsEach file’s read position and state. A set-aside file shows state parkedwith the reason inlast_error.Every folder connector also gives Claude the same bookkeeping tables, all in the
filesetschema:Table What it holds filesEvery file currently in the folder: path, name, extension, size, created and modified times. Ask “what is in this folder?” and Claude reads this. files_eventsThe change history: one row per file that appeared, was modified, vanished, or was set aside ( drift), with the time inevent_atand the reason indetail.directories,volumesFolder sizes and counts, and the disks or shares the roots live on. _source_file,_row_idTwo columns on every data row: which file the row came from, and a stable row id inside that file. Group by _source_fileto compare files. -
Connect Claude
Open Streams → Live → MCP. There are two ways in, and they end at the same place:
Chat apps · no keyclaude.ai, Claude Desktop, ChatGPT
In Claude, Query Streams is in the Anthropic Connectors Directory: browse connectors, click Connect. Elsewhere you paste one address into the app,
https://mcp.querystreams.com/mcp, and connect from a chat. A Query Streams page opens, you pick the organization and the permissions, and click Approve connection. Nothing to copy, nothing to keep secret. The connection appears under Connected Apps and can be revoked there.Developer tools · a keyClaude Code, Cursor, VS Code and friends
On My Keys click Generate key. Give it a Key name such as “Claude Code on my laptop”, keep Read and Execute ticked, choose an Expiration (Never, 30 days, 90 days or 1 year) and click Generate key. Copy it, then Continue to install: the Connect tab shows the exact snippet for your tool with the key already filled in.
Both ways use the same three permissions, which you choose on the consent screen or on the key:
- Read
- List connectors, browse tables and columns, read your saved queries and alert rules. Never returns row data.
- Execute
- Run read-only SQL and saved queries through your Agent and return the rows. Without it Claude can describe your data but not answer from it.
- Analyze
- Profile tables, discover relationships and queue a Schema Intelligence run. It spends Nova AI credits and data allowance, so the consent screen never pre-ticks it.
Lost the key? Open My Keys: the eye icon shows it again and Copy full key copies it. Revoke it there if a laptop goes missing; every client using it fails on its next call, within about five minutes.
Then pick the recipe for the Claude you use. The server address is the same everywhere:
https://mcp.querystreams.com/mcp.Claude on the web, Claude Desktop and mobile no key
- Open Settings → Connectors and click Browse connectors. Query Streams is listed in the Anthropic Connectors Directory: find Query Streams and click Connect. (Or open the directory listing directly and click Connect there.)
- If your organization hides directory connectors, click Add custom connector instead. Name it Query Streams, paste
https://mcp.querystreams.com/mcp, leave the OAuth fields empty, click Add, then in any chat click + → Browse connectors → Query Streams → Connect. - A Query Streams tab opens. Sign in if asked, pick the organization, review Read and Execute, optionally Limit to specific connectors, and click Approve connection.
- Back in Claude you see “Connected to Query Streams”. The first time Claude uses a tool it asks; choose Always allow.
If you do add it by hand in Claude Desktop, use Settings → Connectors → Add, not the in-chat Add marketplace option, which expects a git repository. Connectors sync to your Claude account, so the mobile apps and Desktop pick it up automatically. Menu names are Anthropic’s and can move.
Claude Code key
One command, with your key from My Keys:
Terminalclaude mcp add --transport http querystreams https://mcp.querystreams.com/mcp \ --header "X-MCP-Key: qsmcp_PASTE_YOUR_KEY_HERE"
That writes the current project’s
.mcp.json. Add--scope userto have Query Streams in every project. Run/mcpinside Claude Code to see it connected.Cursor key
Open Cursor Settings → MCP → Add New MCP Server, or edit
.cursor/mcp.jsonat the root of your workspace:.cursor/mcp.json{ "mcpServers": { "querystreams": { "url": "https://mcp.querystreams.com/mcp", "headers": { "X-MCP-Key": "qsmcp_PASTE_YOUR_KEY_HERE" } } } }Restart Cursor or run MCP: Restart Servers; a
querystreamsbadge appears in the MCP status bar.Using something else? The Connect tab has ready-to-paste recipes for ChatGPT, VS Code, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI, plus a Paste & merge tool that drops the
querystreamsentry into a config file you already have. Any client that speaks MCP over HTTP works: serverhttps://mcp.querystreams.com/mcp, headerX-MCP-Key(anAuthorization: Bearerheader with the same key also works). -
Ask your first question
Start with something you can check by opening the folder, so you see Claude reach for the right table. Three that work well with any text log you describe:
- “Which log files are you reading, and when did each last change?”
- Claude queries
fileset.filesforrelative_path,size_bytesandmodified_utc, newest first. - “Show me every ERROR from the last hour.”
- Claude filters
fileset.eventsonmessageand the last hour ofevent_time, newest first. - “Which lines did my format fail to parse, and why?”
- Claude reads
fileset.events_raw_lines, groups byreasonand shows examples, so you can adjust the format.
To confirm the wiring, ask “What Query Streams connectors do I have?”. Claude calls
qs_list_connectors, and on My Keys the key’s Last used time updates within a few seconds.
That’s it. Drop a new file in the folder and, after the next scan, Claude can answer from it. The files never left the computer the Agent runs on, and nobody typed a password into an AI.
How new, changed and deleted files show up
New and changed files
On every Scan interval the Agent compares each file’s size and modified time with its ledger. A new file that fits is added; a changed file is re-read whole, so a table never holds two versions of one file. Turn on Watch folder for changes to react within seconds on a local disk.
Deleted files
A file that vanishes drops its rows, unless you chose Keep rows, mark deleted. If a share goes offline and most files vanish at once, the Agent keeps the last good inventory instead of deleting everything.
Set-aside files
A file that does not fit the layout, cannot be opened, or is locked is set aside: none of its rows load, and files_events records which file and why. It is retried automatically the next time it changes. There is no Rescan button.
What Claude sees
The data as of the last scan. No MCP tool triggers a scan, so ask “when was this last updated?” and Claude reads the latest event_at in files_events for you.
What Claude can do once connected
Claude sees nineteen small tools. You never call them yourself; Claude picks the right one for your question. In plain terms:
Understand your data
List connectors, databases and Agents. Read the tables and columns of your Custom Logs file with descriptions, sample values and relationships when Schema Intelligence has run.
Profile and explore
Profile a column to see its real values before filtering on it. Discover joins between tables that never had a foreign key declared. (Analyze)
Use your saved queries
List the saved, parameterised queries your team trusts and run them with new values. Federated queries that span sources run server-side and come back already joined.
Run read-only SQL
Write and run a SELECT in the right dialect for Custom Logs. Up to 1,000 rows and 60 seconds by default; Claude can ask for more, up to 50,000 rows and five minutes. (Execute)
Check alerts
List your alert rules, their current state and recent firings. Claude can draft a rule as a dry run; a person arms it on the Alerts page.
Improve the model
Check Schema Intelligence coverage per database and, with your agreement, queue a run so the next answers are better. (Analyze)
The tool names, if you want to recognise them in Claude’s replies
| Permission | Tools |
|---|---|
| Read | qs_list_organizations qs_list_agents qs_list_connectors qs_get_si_status qs_get_connector_schema qs_get_table_schema qs_get_relationships qs_list_saved_queries qs_get_task_status qs_list_alert_rules qs_get_alert_state qs_list_recent_alerts |
| Analyze | qs_profile_table qs_discover_relationships qs_request_si_analysis qs_setup_si |
| Execute | qs_run_query qs_run_saved_query qs_create_alert_rule (proposes only; never armed from Claude) |
Why Schema Intelligence matters here
Every answer Claude receives is tagged with where the structure came from, and Claude adjusts how much it trusts what it sees.
| Tier | What Claude sees | Result |
|---|---|---|
| Schema Intelligence | Descriptions for every table and column, sample values, enum meanings, declared and discovered joins. | Claude writes the right Custom Logs SQL first time and explains the data in your business terms. |
| Captured schema | Table and column names, types, keys. | Claude works, but infers meaning from names and may ask a follow-up. |
| Live schema | The database is outside the connector’s capture selection, so structure is read live on each request (needs the Execute permission; SQL Server, MySQL and PostgreSQL). | Queries still run. Claude explores with small selects when it needs more. |
If a database matters, run Schema Intelligence on it once from Nova → Intelligence. The My Keys tab shows a coverage panel per connector. How Schema Intelligence works.
What the plans allow
MCP is on every plan, including Free, with no separate fee. What each plan sets is how many keys or connected apps you can hold and how many calls a minute Claude may make:
| Plan | Keys per user | Keys per organization | Calls per minute |
|---|---|---|---|
| Free | 1 | 1 | 30 |
| Personal Core | 1 | 1 | 60 |
| Personal Plus | 1 | 1 | 90 |
| Business Core | 2 | 3 | 120 |
| Business Plus | 3 | 5 | 150 |
| Business Max | 5 | 10 | 240 |
| Enterprise Core | 5 | 25 | 300 |
| Enterprise Plus | 8 | 50 | 450 |
| Enterprise Max | 10 | 100 | 600 |
A connected app counts as a key. On top of the per-minute figure, any one key may run at most 10 queries a minute. A query returns up to 1,000 rows and runs for up to 60 seconds unless Claude asks for more, to a ceiling of 50,000 rows and five minutes. The rows Claude receives count against your Data Realm allowance, the same pool your Excel and Sheets queries use, and MCP is measured before compression, so a wide result costs more here than the same rows in a spreadsheet. Schema Intelligence runs started from Claude spend Nova AI credits, exactly as they do from the Portal. See the pricing page for the allowances.
Keeping it safe
Read-only, checked by the Agent
Only SELECT statements run. The check happens on the computer that runs the Agent, before your Custom Logs file sees the SQL, so nothing Claude writes can change data.
No credentials in the AI
The Custom Logs login stays on the Agent. Claude holds a Query Streams key or connection, which you can revoke from the MCP page; the change takes effect within about five minutes.
Everything is logged
Every tool call appears on the MCP Activity tab and every query in Query History as client type MCP, attributed to the person whose key or connection made it. The SQL text and the key itself are never written to the activity log.
What the AI provider receives
Table and column names, the Schema Intelligence descriptions including sample values, and the rows of the queries you ask for. Those go to the AI provider you connected, under its terms. Query Streams never sees your chat.
Good next moves
- Tune the format by asking Claude which lines landed in
events_raw_lines, then edit the connector. Saving a change makes the Agent re-sample. - Turn on Watch folder for changes (near real-time) to pick up new lines within seconds on a local disk. The scheduled scan stays the guarantee.
- Ask for a built-in type if your format is common. The Portal says: “Need a log type that is not listed? Open a support request and we add it within a few days.”
When something doesn’t work
| What you see | What it means | Fix |
|---|---|---|
| Claude shows no Query Streams tools | The connector was added but never connected from a chat, or the key was pasted into the wrong place. | In Claude: + → Browse connectors → Query Streams → Connect. In a developer tool: restart it, then check Last used on My Keys. |
MCP_KEY_REQUIRED or 401 | No key reached the server, usually a stray newline from copy and paste or the key in the wrong header. | Copy the key again from My Keys and send it in the X-MCP-Key header. |
MCP_USER_DISABLED | An admin switched MCP off for your user. | Ask them to turn the MCP switch back on under Account → Access Control. |
MCP_SCOPE_REQUIRED or MCP_SCOPE_DENIED | The key or connection lacks the permission for that action, usually Execute. | Edit the key on My Keys and tick Execute, or reconnect the app and approve it. |
MCP_KEY_ORG_LIMIT_EXCEEDED | Your plan’s key limit is used up. On Free that is one key or one connected app. | Revoke one you no longer use, or move up a plan. |
MCP_AGENT_NOT_CONNECTED or MCP_AGENT_NOT_REGISTERED | The Agent that owns your Custom Logs file is not connected right now. | Open Data → Data Agents and start the Agent on its computer. |
MCP_DATABASE_NOT_CAPTURED | The database is outside the connector’s capture selection, so there is no stored schema or Schema Intelligence for it. Queries still work. | Add it to the capture selection on the connector, then run Schema Intelligence if you want richer answers. |
MCP_RATE_LIMITED | Too many calls a minute for your plan, or more than 10 query runs a minute on one key. | Wait a moment. Schema Intelligence lets Claude answer in fewer calls. |
MCP_QUERY_TIMEOUT or MCP_OUTPUT_TOO_LARGE | The query ran past its timeout or returned more than Claude can take in one reply. | Ask for fewer rows or columns, or a date filter. Claude usually suggests this itself. |
MCP_DATA_REALM_EXHAUSTED | Your organization’s data allowance for the period is used up. | Wait for the allowance to reset or top it up from the Portal. |
| Read-only violation | The SQL was not a SELECT. | By design. Nothing writes through MCP. |
Questions people ask
Do I have to write a regex?
No. Run Test connection and the Agent offers the closest built-in log type, or click Let Nova suggest a format. You can also pick delimited, key=value, JSON lines, #Fields header or fixed width instead of grok.
What happens to lines my format does not match?
They are kept in events_raw_lines with a reason, such as no-grammar-match. Nothing is dropped. A file that cannot be read at all is set aside and listed in the connector’s Files dialog with the reason.
What does Claude see before I define a format?
Each line becomes one row with file_name and message. event_time is the file’s modified time, not the time written in the line. Define a Timestamp and columns in the format to get real event times and fields.
Does Claude read my files?
No. The Agent reads them on its own computer and keeps the rows in a local cache there. Claude sends SQL to Query Streams, the Agent runs it against that cache, and only the rows the question needs travel back. Claude never opens a file and cannot change, move or delete one.
Do I need to open a port or run a VPN?
No. The Agent makes one outbound connection on port 443 and both requests and rows travel over it. If outbound HTTPS works, this works.
Can the folder be on a network share, or in OneDrive or Dropbox?
A share works as long as the Agent’s computer can open it; type it as \\server\share\folder, because the Agent runs as a service and cannot see drives mapped at your login, and add the share login on the folder’s row if it needs one. For a synced cloud folder, set it to keep files on this device; the Agent skips cloud placeholder files.
Does the Free plan really cover this?
Yes. Free is a plan you keep, not a trial that expires. MCP is included on every plan; Free allows one key or one connected app and 30 calls a minute. Folder connectors have no file cap of their own. See exactly what Free includes on the pricing page.
Which AI tools work besides Claude?
Anything that speaks MCP over HTTP: ChatGPT, Cursor, VS Code with Copilot, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI all have a ready-made recipe on the Connect tab.

