Definition
Log correlation connects log records to related requests, spans, services, or events using shared fields.
Signals
Why use it
Move from an error message to the request and service that produced it.
Common use cases
- Investigate exceptions
- follow a request across services
- compare logs around an incident.
Benefits
- Preserves detailed error context alongside request timing.
Limitations
- Missing IDs, inconsistent field names, retention differences, and unsampled traces can leave links incomplete.
Practical pattern
Include trace_id, span_id, service.name, environment, and timestamps. Configure field mappings between the log and trace backends.
Supported by
Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.
- OpenTelemetry — Log records can carry trace and span IDs.
- Grafana with Tempo and Loki — Configured links connect spans and matching log queries.
Related concepts
Investigation patterns
Related guides
- What is Observability?
- What is MTTR?
- OpenTelemetry: Logs to Traces in Python
- Troubleshoot: Log Trace ID Not Found
FAQ
Can timestamps alone correlate logs?
They can narrow a search, but concurrent requests and clock skew make timestamps weaker evidence than a shared identifier.