Docs > Platform Observability > Getting Started with Log Management
Getting Started with Log Management
Overview
This guide introduces AppStatus Log Management and covers:
- Ship logs from the SDK, the agent, or any OpenTelemetry log exporter
- One search covers recent logs and the cold archive
- No rehydration step before searching old data
- Trace-ID correlation between a request and its log lines
- Volume control through Log Pipelines
What is Log Management in AppStatus?
Logs from your services and hosts are searchable in one place. A single query covers both recent logs and the archive — you do not restore an old day into a hot tier first and then search it.
Log lines that carry a trace ID link straight to the request that produced them, so you can move from a slow trace to its logs without switching tools or copying identifiers by hand.
Key capabilities:
- Federated search across hot storage and cold archive in one pass
- The same filters work identically on recent and archived logs
- Trace-ID correlation to APM and Error Tracking
- Structured field search alongside free-text
- Ingestion-time filtering and redaction via Log Pipelines
What you will see
What a search result looks like
Scroll the table sideways to see every column.
Lines sharing a trace ID show together, so you read the request as a story rather than four unrelated rows.
Troubleshooting
Logs arrive but are not linked to any trace
The trace ID has to be present in the log context. Most SDKs add it automatically once APM is enabled in the same process; custom loggers usually need the field passed explicitly.
Archive search returns nothing for an old incident
Check the time range covers the incident in the archive’s timezone, and confirm the service was shipping logs then. If a pipeline dropped those lines, they were never stored.
Log volume is higher than expected
Find the top sources by volume, then shape them in Log Pipelines. Dropping health-check and readiness-probe lines usually removes the bulk without losing anything you would read.
Operational Guidance
- Start from the trace or error, not from a raw log search — you will find the line faster.
- Archive search returns the same fields as hot search, so a filter that works on recent logs works on old ones.
- If log volume is driving cost, shape it in Log Pipelines rather than turning logging off.
Step-by-Step Setup
Logs are useful the moment they arrive, but they are far more useful with a trace ID attached. Set up shipping first, then spend two minutes making sure the correlation field is present — it is the difference between searching and knowing.
Before you start
- A service or host already producing logs
- 1
Create an ingest key scoped to logs
Open Ingest Keys and create a key scoped to logs for the environment you are setting up. The key value is shown once — copy it into your secret manager now, not into source control.
WhereIngest Keys → Create keyTipOne scope per key. A key reused across signals turns a single leak into full ingest access.
- 2
Ship your logs
Send logs from the application SDK, from the agent already running on the host, or from any OpenTelemetry log exporter you have in place. All three land in the same searchable store.
WhereLog Management → Add source - 3
Include the trace ID
Make sure log context carries the trace ID. Most SDKs add it automatically when APM runs in the same process; custom loggers usually need the field passed explicitly.
WhereLogger configurationTipThis single field is what makes one-click drill-down between a trace and its logs work.
- 4
Run a search
Search for a recent request and confirm lines arrive with the service name, level and message you expect. Check that a filter you would actually use returns what it should.
WhereLog Management → Search - 5
Shape the noisy sources
Sort sources by volume. If health checks or readiness probes dominate, send them through a pipeline rather than turning logging off.
WhereLog Pipelines → Create pipeline
Configuration Options
Every option you can set, what each choice means, and what to pick. Use this as a reference while you fill in the form.
Search and retention
| Field | Options | What it does | Recommended |
|---|---|---|---|
| Time range | Any window | Covers hot storage and archive in one pass. | Search the incident window directly — no rehydration step needed. |
| Service filter | Service name | Narrows to one source. | Match the APM service name so the two line up. |
| Level | DEBUG–ERROR | Filters by severity. | Emit standard levels; mixed conventions make filters unreliable. |
| Trace ID | Any trace | Returns every line from one request. | The fastest way in during an incident. |
Feature Reference
Every feature, where to find it in the app, and what it does. Use this when you know what you want to do but not where it lives.
| Feature | Where in app | Description |
|---|---|---|
| Federated search | Log Management → Search | Hot storage and cold archive queried together, nothing rehydrated. |
| Trace correlation | Log line → Trace | Jump from a log line to the request that produced it. |
| Structured fields | Search filters | Filter on your own fields, not just free text. |
| Volume by source | Log Management → Sources | Find what to shape before it becomes a cost problem. |
Next Steps
Continue building your monitoring stack:
