Recording what happened.
WHAT TO LOG
Errors, with context Significant actions External call failures Startup and configuration Access to sensitive functions
WHAT NOT TO LOG
Credentials Full personal data Every routine request, at volume
WHY NOT VOLUME
It fills disks and obscures what matters.
WHAT EVERY ENTRY NEEDS
A timestamp with a time zone What happened
Enough context to diagnose: which user, which record, what input
WHAT MAKES LOGS USELESS
Messages saying only that an error occurred No context Inconsistent formats No timestamps
WHAT TO ADOPT
A structured format, so entries can be searched and filtered.
WHAT TO CONFIGURE
Rotation, so files do not grow indefinitely Retention, appropriate to your needs
WHAT TO CENTRALISE
Logs from several servers, where you have them.
WHY
Correlating an incident across machines is otherwise impractical.
WHAT TO REVIEW
Logs after every deployment, and periodically thereafter.