Definition

Log correlation connects log records to related requests, spans, services, or events using shared fields.

Signals

Why use it

Move from an error message to the request and service that produced it.

Common use cases

  • Investigate exceptions
  • follow a request across services
  • compare logs around an incident.

Benefits

  • Preserves detailed error context alongside request timing.

Limitations

  • Missing IDs, inconsistent field names, retention differences, and unsampled traces can leave links incomplete.

Practical pattern

Include trace_id, span_id, service.name, environment, and timestamps. Configure field mappings between the log and trace backends.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

Related concepts

Investigation patterns

Related guides

FAQ

Can timestamps alone correlate logs?

They can narrow a search, but concurrent requests and clock skew make timestamps weaker evidence than a shared identifier.