3 ms·
You can if your loggung structure is uniform, and includes a correlation ID. This happens every day... pretty simple actually.
by suff 8y ago
You can if your loggung structure is uniform, and includes a correlation ID. This happens every day... pretty simple actually.
- ryanworl 8y agoThis is literally the point of the article. Charity is saying to structure your logs, add useful information to them from all portions of the transaction, and save the logs somewhere to query them across all fields in any combination. That's what her product does. This is in opposition to poor quality text logs, which typically contain almost no useful information, and time series aggregates, which either throw away all the context, or explode traditional time series databases when you try to add high cardinality fields to them. Edit: I should add that "dashboards" in this context means the typical wall of time series charts you can buy from a bunch of different vendors.
- fizx 8y agoTitle is a bit clickbait, really.
- icedchai 8y agoSounds simple. Unfortunately, having uniform logging structure in a non-trivial project is about as likely to happen as winning the lottery.
- drb91 8y ago...only if you view software development like gambling. All problems can be methodically addressed; fixing log formatting is actually rather easy to track down.
- icedchai 8y agoYes, in your own code, it is easily fixed... With third party code, like dependencies, it becomes more of a problem...
- drb91 8y agoThat's true. But you only need to re-format the events you care about from that dependency.
- Fellshard 8y agoThat's still a non-trivial problem, depending on how easy it is to adapt logs from a library; maybe with a proper logging facade, it's easy to attach those adapters to those logs, but I suspect most libraries don't have strong contracts around the formats of their logs, as it is. Maybe that's something to improve.
- scarface74 8y agoI use .Net and Serilog for structured logging. Each log entry can be a structure with name/value pairs instead of just a stream of text. Most of the time it’s JSON. You have various outputs (sinks) where you can send your logs to almost anywhere - AWS CloudWatch to its own group/stream where you can trigger alerts, a NoSql database like ElasticSearch or Mongo where you can do queries against properties. You can also have every log entry tagged with metadata like the application name/EC2 instance, AMI being used either globally or within a “context” (everything that’s called inside a using block). Why anyone would do unstructured logging in 2018 is beyond me.
- lallysingh 8y agoNo it's not. You can start with something that snarfs data from your log messages and normalizes them. Then you just have to log enough data that you can extract it after. The normalization can connect IDs together to make the log data more accessible.
- icedchai 8y agoNow I have two problems: my app and a logging thing.