Implementing Logging Strategies

1. Using Structured Logging

AspectDetail
FormatJSON (one event per line)
Stable keystimestamp, level, message, service
SchemaOpenTelemetry Logs / ECS
AvoidString concatenation; use structured fields

Example: JSON log event

{"ts":"2026-05-15T12:00:00Z","level":"INFO","service":"orders","traceId":"abc","spanId":"def","msg":"order placed","orderId":"ord_123","userId":"u_42","total":49.95}

2. Implementing Log Levels

LevelUse
TRACEVery fine; off in prod
DEBUGDiagnostic; sampled in prod
INFOSignificant lifecycle events
WARNRecoverable issue
ERROROperation failed
FATALProcess must exit

3. Adding Correlation IDs

FieldDetail
traceId / spanIdFrom W3C trace context
requestIdPer-HTTP-request UUID
correlationIdBusiness workflow ID
MDC / contextSet per request; auto-included in logs

4. Centralizing Logs

StackComponents
ELK / ElasticElasticsearch + Logstash + Kibana
EFKFluent Bit / Fluentd shipper
Loki + GrafanaIndex labels not content; cheap
CloudCloudWatch, Stackdriver, Azure Monitor
PatternApp → stdout → agent → backend

5. Implementing Log Sampling

StrategyDetail
Probabilistic1% of DEBUG, 100% of ERROR
Rate limitN events/sec per logger
Tail samplingKeep all logs for traces with errors
DedupSuppress identical lines (Logback)

6. Using Contextual Logging

MechanismDetail
MDC (Java) / context (Go)Per-request bag of fields
Auto-fieldsservice, env, version, host
Per-call fieldsuserId, tenantId, orderId
CleanupClear context at request end

7. Logging Security Events

EventFields
Login success/failureuserId, IP, user-agent
Permission deniedresource, action
Privilege changeactor, target
Token issuance/revocationjti, exp
StorageSeparate, append-only stream

8. Handling Sensitive Data

PracticeDetail
Never logPasswords, secrets, full PAN, JWT contents
MaskEmail j***@x.com, card ****1234
Allow-list serializerOnly fields explicitly marked safe
ComplianceGDPR, HIPAA, PCI-DSS

9. Implementing Log Retention

TierRetention
Hot (search)7–30 days
Warm30–90 days
Cold (archive)1–7 years (compliance)
AuditPer regulation; tamper-evident

10. Using Log Timestamps

PracticeDetail
FormatISO-8601 with ms + UTC
SourceUse NTP-synced wall clock; HLC for ordering
AvoidLocal time zones in logs

11. Implementing Log Rotation

StrategyDetail
ContainerStream to stdout; let runtime rotate
VMlogrotate by size or daily
Compressiongzip rotated files
RetentionDisk: keep 7 days; ship to central earlier

12. Using Logging Tools

ToolUse
Logback / Log4j 2 / TinylogJava
Pino / WinstonNode.js
zap / zerologGo
structlog / loguruPython
Fluent Bit / Vector / FilebeatShippers
Loki / Elastic / OpenSearchBackends