Prerequisites

  • One affected log with timestamp, service, environment and the original trace identifier.
  • Read access to the selected trace backend and telemetry pipeline diagnostics.

Install dependencies

No new dependency is needed for the investigation. Use a recent controlled request and the existing backend tools.

Runnable example

# Preserve the exact log field; do not use the request ID or span ID.
trace_id = "0123456789abcdef0123456789abcdef"
import re
assert re.fullmatch(r"[0-9a-fA-F]{32}", trace_id)
assert int(trace_id, 16) != 0
print(trace_id.lower())

Connect your backend

Start with a direct trace-ID lookup in the intended backend/tenant. Remove unrelated service filters and use the log time to check retention. If lookup succeeds but the log link fails, repair the link field or selected data source. If lookup fails, follow the known request through the application exporter, Collector receivers/processors/exporters and storage. A valid identifier proves context existed; it does not prove the span was recorded, exported or retained.

Verification checklist

  1. Check the field type and format using the example: a W3C trace ID is 32 hexadecimal characters and nonzero. Some backend displays use different representations; confirm conversion rather than guessing.
  2. Emit a fresh controlled request, capture its ID and timestamp, then query that exact ID directly in the intended tenant.
  3. Check head and tail sampling decisions. The sampled flag in a log is not proof that downstream tail sampling retained the trace.
  4. Inspect exporter failures and Collector receive/send/drop evidence for the same interval. Use a temporary debug exporter only in a controlled environment with approved telemetry.
  5. After a targeted correction, repeat with a new request and confirm the log link opens its matching service/operation. Record the affected stage and evidence.

Common failures

Troubleshooting the connection
SymptomCheck
ID belongs to another fieldMap the actual trace_id; do not treat a 16-character span ID or custom correlation ID as a trace ID.
Direct lookup works; click failsCorrect the log-derived field, URL template, encoding or trace data source.
Recent trace is absentCheck sampling decisions, exporter endpoint/protocol/authentication, processor drops and ingestion delays.
Old trace is absentCompare log versus trace retention and tenant selection; a configuration fix cannot recover expired telemetry.

Related concepts

Related signals

Related patterns

Related guides

Official documentation