Definition
Logs are timestamped records of discrete activity, carrying messages and structured fields for an investigation.
Question it answers
What happened in this operation, and which error details explain the symptom?
Role in an investigation
Use logs to inspect the details behind a failed request after a trace identifies the relevant service. Scope searches to the same environment and time window before matching IDs. A business workflow identifier can bridge operations whose trace IDs differ.
Correlation fields
| Field or dimension | Purpose |
|---|---|
| trace_id and span_id | Locate records associated with a recorded trace or span. |
| service.name and environment | Separate similarly named services and production from test traffic. |
| timestamp and event timestamp | Distinguish when something happened from when it was observed. |
Find the error behind a slow request
A checkout trace shows a payment span timing out. Searching logs for that trace and service reveals repeated connection-pool waits. Those records provide a testable explanation; unrelated timeouts at the same minute do not belong to the request.
Limitations
- Text searches can match unrelated requests when identifiers are missing.
- Log retention may outlast trace retention, so a valid ID may no longer resolve.
- Request identifiers belong in structured fields; using each one as an indexed stream label can create excessive cardinality.
Supported by
Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.
- OpenTelemetry — Log records can include trace and span identifiers.
- Grafana with Tempo and Loki — Configured span links query related log records.
- Datadog — Trace ID injection connects application logs with APM traces.
Investigation patterns
- Trace to Logs
- Metrics to Traces
- Deployments to Error Rate
- Services to Dependencies
- Infrastructure to Applications
- Service to Database
- User Session to Backend Trace
- Queue Producer to Consumer
Related concepts
- Correlation IDs
- Log Correlation
- Trace Correlation
- Event Correlation
- Context Propagation
- Root Cause Analysis
Related guides
- What is Observability?
- What is MTTR?
- OpenTelemetry: Logs to Traces in Python
- OpenTelemetry: Queue Context, Retries and Batches
- Troubleshoot: Log Trace ID Not Found
FAQ
Can logs replace traces?
They can describe local activity, but do not automatically reconstruct parent-child execution or timing across services.