Production Debugging & Incident Response Playbook · 课时

结构化日志记录最佳实践

实施结构化日志记录,以便更轻松地解析和分析生产问题,并更快完成调试

第 1 / 4 课11 个步骤

结构化日志记录最佳实践 是 CoddyKit 上的免费 Production Debugging & Incident Response Playbook 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Production Debugging & Incident Response Playbook 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Production Debugging & Incident Response Playbook 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

What are Logs?

Logs are records of events that happen in your application or system. Think of them as a diary for your software!

They're crucial for understanding what your program is doing, especially when things go wrong in a live "production" environment.

The Messy Truth

Often, logs are just plain text strings. This is called unstructured logging. While easy to write, unstructured logs are hard for computers to read and analyze, making debugging a slow, manual process.

Consider this example:

import logging

logging.basicConfig(level=logging.INFO)
logger = logging.getLogger(__name__)

def process_order(order_id, item_count):
    logger.info(f"Processing order {order_id} with {item_count} items.")
    if item_count > 10:
        logger.warning(f"Large order detected for {order_id}. Items: {item_count}.")
    logger.info(f"Order {order_id} processed successfully.")

if __name__ == "__main__":
    process_order("ORD-123", 5)
    process_order("ORD-456", 12)

What is Structured Logging?

Structured logging means your logs are formatted as machine-readable data, not just free-form text. The most common format is JSON.

Instead of a single string, each log entry is an object with key-value pairs. This makes them easy to search, filter, and analyze programmatically.

Why Structured Logging Rocks

Structured logs offer many advantages:

  • Faster Debugging: Quickly find relevant events.
  • Better Analysis: Easily query and aggregate data.
  • Automated Tools: Integrate with monitoring and alerting systems.
  • Consistency: Ensures all logs contain expected fields.

JSON is King

While other formats exist, JSON (JavaScript Object Notation) is the most popular choice for structured logging due to its simplicity and widespread support.

A JSON log entry is a self-contained object, making it incredibly versatile for storing varied data. Here's what a structured log might look like:

{
  "timestamp": "2023-10-27T10:30:00Z",
  "level": "INFO",
  "service": "order-processor",
  "message": "Order processed successfully",
  "order_id": "ORD-123",
  "item_count": 5
}

Code It Up!

Let's see how to implement structured logging. Many languages have libraries that make this easy. Here's a basic Python example using the standard logging module with a custom JSON formatter.

import logging
import json

class JsonFormatter(logging.Formatter):
    def format(self, record):
        log_entry = {
            "timestamp": self.formatTime(record, self.datefmt),
            "level": record.levelname,
            "name": record.name,
            "message": record.getMessage(),
            "file": record.filename,
            "line": record.lineno
        }
        if hasattr(record, 'order_id'):
            log_entry['order_id'] = record.order_id
        if hasattr(record, 'item_count'):
            log_entry['item_count'] = record.item_count
        return json.dumps(log_entry)

logger = logging.getLogger(__name__)
logger.setLevel(logging.INFO)

handler = logging.StreamHandler()
handler.setFormatter(JsonFormatter())
logger.addHandler(handler)

def process_order(order_id, item_count):
    extra_data = {'order_id': order_id, 'item_count': item_count}
    logger.info("Processing order", extra=extra_data)
    if item_count > 10:
        logger.warning("Large order detected", extra=extra_data)
    logger.info("Order processed successfully", extra=extra_data)

if __name__ == "__main__":
    process_order("ORD-123", 5)
    process_order("ORD-456", 12)

Must-Have Fields

Every structured log entry should include these core fields for effective analysis:

  • timestamp: When the event happened (ISO 8601 format).
  • level: Severity (INFO, WARN, ERROR, DEBUG).
  • service: Which service or application generated the log.
  • message: A human-readable summary of the event.
  • hostname/pod_name: Where the log originated.

Enrich Your Logs

Beyond essential fields, add contextual data specific to the event. This is key for tracing requests across distributed systems, helping you connect the dots when debugging complex issues.

  • request_id: To track a single user request.
  • user_id: To identify the user involved.
  • transaction_id: For specific business transactions.
import logging
import json
import uuid

# Reusing the JsonFormatter from previous scene
class JsonFormatter(logging.Formatter):
    def format(self, record):
        log_entry = {
            "timestamp": self.formatTime(record, self.datefmt),
            "level": record.levelname,
            "message": record.getMessage()
        }
        for key, value in record.__dict__.items():
            if not key.startswith('_') and key not in ['name', 'levelname', 'pathname', 'filename', 'module', 'exc_info', 'exc_text', 'stack_info', 'lineno', 'funcName', 'created', 'msecs', 'relativeCreated', 'thread', 'threadName', 'processName', 'process', 'args', 'msg', 'asctime']:
                log_entry[key] = value
        return json.dumps(log_entry)

logger = logging.getLogger(__name__)
logger.setLevel(logging.INFO)
handler = logging.StreamHandler()
handler.setFormatter(JsonFormatter())
logger.addHandler(handler)

def handle_web_request(user_id):
    request_id = str(uuid.uuid4())[:8]
    extra_data = {'request_id': request_id, 'user_id': user_id, 'service': 'api-gateway'}
    logger.info("Received web request", extra=extra_data)
    
    if user_id == "user-vip":
        logger.info("VIP user request detected", extra=extra_data)
    else:
        logger.debug("Standard user request", extra=extra_data)
    
    logger.info("Request processed", extra=extra_data)

if __name__ == "__main__":
    handle_web_request("user-123")
    handle_web_request("user-vip")

Log Levels

Log levels help categorize the severity and importance of a log message. Common levels include:

  • DEBUG: Detailed info, only useful when diagnosing problems.
  • INFO: Confirmation that things are working as expected.
  • WARN: An unexpected event, but the application is still running.
  • ERROR: An error that prevents some functionality from working.
  • CRITICAL: A severe error, application might be unable to continue.

Quick Check

Structured logging is a powerful technique for improving observability. Let's test your understanding of its key advantages.

Structured Logging Recap

You've learned about the power of structured logging! By formatting your logs as machine-readable data (like JSON), you unlock faster debugging, better analysis, and seamless integration with monitoring tools.

Remember to include essential fields and contextual data to make your logs truly useful for diagnosing issues in production.

免费开始

用 AI 导师学习 Production Debugging & Incident Response Playbook — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
12
课程
48

常见问题解答

「结构化日志记录最佳实践」课时是免费的吗?

是的 — 「结构化日志记录最佳实践」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Production Debugging & Incident Response Playbook 课程的其余内容,请升级到 CoddyKit PRO。 Production Debugging & Incident Response Playbook 课程共包含 4 节课。

「结构化日志记录最佳实践」这节课中我会学到什么?

实施结构化日志记录,以便更轻松地解析和分析生产问题,并更快完成调试 你通过在浏览器中直接运行的动手代码来练习 Production Debugging & Incident Response Playbook,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Production Debugging & Incident Response Playbook 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Production Debugging & Incident Response Playbook 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。

「结构化日志记录最佳实践」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Production Debugging & Incident Response Playbook 课中编写并运行代码吗?

能。每节 Production Debugging & Incident Response Playbook 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 结构化日志记录最佳实践
  2. 指标、仪表盘与可观测性
  3. 设计智能告警策略
  4. 日志聚合与保留策略
← 返回 Production Debugging & Incident Response Playbook