Definition

Logs are timestamped records of discrete activity, carrying messages and structured fields for an investigation.

Question it answers

What happened in this operation, and which error details explain the symptom?

Role in an investigation

Use logs to inspect the details behind a failed request after a trace identifies the relevant service. Scope searches to the same environment and time window before matching IDs. A business workflow identifier can bridge operations whose trace IDs differ.

Correlation fields

Fields that make the connection possible
Field or dimensionPurpose
trace_id and span_idLocate records associated with a recorded trace or span.
service.name and environmentSeparate similarly named services and production from test traffic.
timestamp and event timestampDistinguish when something happened from when it was observed.

Find the error behind a slow request

A checkout trace shows a payment span timing out. Searching logs for that trace and service reveals repeated connection-pool waits. Those records provide a testable explanation; unrelated timeouts at the same minute do not belong to the request.

Limitations

  • Text searches can match unrelated requests when identifiers are missing.
  • Log retention may outlast trace retention, so a valid ID may no longer resolve.
  • Request identifiers belong in structured fields; using each one as an indexed stream label can create excessive cardinality.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

Investigation patterns

Related concepts

Related guides

FAQ

Can logs replace traces?

They can describe local activity, but do not automatically reconstruct parent-child execution or timing across services.