4 ms·
I was looking for logfmt mentioned in the article and couldn't find it. Also stripe's canonical log lines[1] solve this problem nicely 1: https://stripe.com/b
by swlkr 4y ago
I was looking for logfmt mentioned in the article and couldn't find it.
Also stripe's canonical log lines[1] solve this problem nicely
1: https://stripe.com/blog/canonical-log-lines https://stripe.com/blog/canonical-log-lines
- ithkuil 4y agoYou can read about logfmt at https://brandur.org/logfmt https://brandur.org/logfmt It's quite nice at first glance. My main qualm with it is that there is no formal spec and I got bitten a few times by incompatibilities between emitters and parsers especially around quoted values. (In particular we had a rust binary emitting badly escaped values such that fluentbit emitted structured logs with thousands of fields which in turn caused graylog to explode which was particularly gnarly because at the same time we had a production incident we had to troubleshoot without historical logs)
- systemvoltage 4y agoStick with JSON. Just slightly less readable than logfmt but highly ubiquitous adaptation and parsing capabilities. logfmt might be fine for people at Stripe who've built infra around it, but for mortals, stick with JSON so you can send data around. When you have a million log lines, the question "Did it parse correctly?" shouldn't need to be asked because checking correctness is a huge problem.
- bornfreddy 4y agoTIL - thank you! Canonical log lines don't solve the exact same problem (they provide all the information for some api call in a single place), but they need to be structured to work. Logfmt: https://www.cloudbees.com/blog/logfmt-a-log-format-thats-easy-to-read-and-write https://www.cloudbees.com/blog/logfmt-a-log-format-thats-eas...