AppStatus Documentation Hub for Production Operations

Docs > Platform Observability > Getting Started with Log Management

Getting Started with Log Management

Overview

This guide introduces AppStatus Log Management and covers:

  • Ship logs from the SDK, the agent, or any OpenTelemetry log exporter
  • One search covers recent logs and the cold archive
  • No rehydration step before searching old data
  • Trace-ID correlation between a request and its log lines
  • Volume control through Log Pipelines

What is Log Management in AppStatus?

Logs from your services and hosts are searchable in one place. A single query covers both recent logs and the archive — you do not restore an old day into a hot tier first and then search it.

Log lines that carry a trace ID link straight to the request that produced them, so you can move from a slow trace to its logs without switching tools or copying identifiers by hand.

Key capabilities:

  • Federated search across hot storage and cold archive in one pass
  • The same filters work identically on recent and archived logs
  • Trace-ID correlation to APM and Error Tracking
  • Structured field search alongside free-text
  • Ingestion-time filtering and redaction via Log Pipelines

What you will see

What a search result looks like

app.appstatus.ioSample data
TimeServiceLevelMessage
14:22:07.184checkout-apiERRORpayment authorisation failed — upstream timeout
14:22:07.180checkout-apiWARNretry 2/3 for order 8842
14:22:06.902payments-workerINFOsubmitted charge, awaiting confirmation
14:22:06.744checkout-apiINFOorder 8842 created

Scroll the table sideways to see every column.

Lines sharing a trace ID show together, so you read the request as a story rather than four unrelated rows.

Troubleshooting

Logs arrive but are not linked to any trace

The trace ID has to be present in the log context. Most SDKs add it automatically once APM is enabled in the same process; custom loggers usually need the field passed explicitly.

Archive search returns nothing for an old incident

Check the time range covers the incident in the archive’s timezone, and confirm the service was shipping logs then. If a pipeline dropped those lines, they were never stored.

Log volume is higher than expected

Find the top sources by volume, then shape them in Log Pipelines. Dropping health-check and readiness-probe lines usually removes the bulk without losing anything you would read.

Operational Guidance

  • Start from the trace or error, not from a raw log search — you will find the line faster.
  • Archive search returns the same fields as hot search, so a filter that works on recent logs works on old ones.
  • If log volume is driving cost, shape it in Log Pipelines rather than turning logging off.

Step-by-Step Setup

Logs are useful the moment they arrive, but they are far more useful with a trace ID attached. Set up shipping first, then spend two minutes making sure the correlation field is present — it is the difference between searching and knowing.

Before you start

  • A service or host already producing logs
  1. 1

    Create an ingest key scoped to logs

    Open Ingest Keys and create a key scoped to logs for the environment you are setting up. The key value is shown once — copy it into your secret manager now, not into source control.

    WhereIngest Keys → Create key
    Tip

    One scope per key. A key reused across signals turns a single leak into full ingest access.

  2. 2

    Ship your logs

    Send logs from the application SDK, from the agent already running on the host, or from any OpenTelemetry log exporter you have in place. All three land in the same searchable store.

    WhereLog Management → Add source
  3. 3

    Include the trace ID

    Make sure log context carries the trace ID. Most SDKs add it automatically when APM runs in the same process; custom loggers usually need the field passed explicitly.

    WhereLogger configuration
    Tip

    This single field is what makes one-click drill-down between a trace and its logs work.

  4. 4

    Run a search

    Search for a recent request and confirm lines arrive with the service name, level and message you expect. Check that a filter you would actually use returns what it should.

    WhereLog Management → Search
  5. 5

    Shape the noisy sources

    Sort sources by volume. If health checks or readiness probes dominate, send them through a pipeline rather than turning logging off.

    WhereLog Pipelines → Create pipeline

Configuration Options

Every option you can set, what each choice means, and what to pick. Use this as a reference while you fill in the form.

Search and retention

FieldOptionsWhat it doesRecommended
Time rangeAny windowCovers hot storage and archive in one pass.Search the incident window directly — no rehydration step needed.
Service filterService nameNarrows to one source.Match the APM service name so the two line up.
LevelDEBUG–ERRORFilters by severity.Emit standard levels; mixed conventions make filters unreliable.
Trace IDAny traceReturns every line from one request.The fastest way in during an incident.

Feature Reference

Every feature, where to find it in the app, and what it does. Use this when you know what you want to do but not where it lives.

FeatureWhere in appDescription
Federated searchLog Management → SearchHot storage and cold archive queried together, nothing rehydrated.
Trace correlationLog line → TraceJump from a log line to the request that produced it.
Structured fieldsSearch filtersFilter on your own fields, not just free text.
Volume by sourceLog Management → SourcesFind what to shape before it becomes a cost problem.

Next Steps

Continue building your monitoring stack: