Knowing what the system is doing.
WHAT TO LOG
Requests, with timing and outcome Errors, with context Significant business events Administrative actions
WHAT TO NEVER LOG
Passwords Tokens and keys Payment details Personal data beyond what is necessary
WHY
Logs are widely accessible and retained, and they become the breach.
WHAT STRUCTURED LOGGING PROVIDES
Logs that can be searched and aggregated rather than read.
WHAT TO INCLUDE IN EVERY ENTRY
A request identifier The tenant The user, where applicable Timestamp in a single standard
WHY THE REQUEST IDENTIFIER
It connects entries across services into one story.
WHAT METRICS TO COLLECT
Request rate, error rate and duration Queue depth Resource use
Business measures: signups, payments, cancellations
WHY BUSINESS MEASURES ALONGSIDE TECHNICAL
A drop in signups reveals a broken form faster than any error rate.
WHAT TO ALERT ON
Conditions affecting customers.
WHAT TO SET RETENTION FOR
Every log type, deliberately.
WHY
Log storage becomes a substantial cost, quietly.
WHAT TO KEEP LONGER
Audit logs, which may be required.
WHAT TO BUILD
A single place to search everything.