Question

What should you actually log, and what should you never log?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Log what you would need to diagnose a problem you cannot reproduce — and never log anything that turns your log store into a liability. Most logging is written for the moment it is added rather than for the incident where it will be read, which is why so little of it helps.

What to log:

Errors with full context — the exception, the stack trace, and the inputs and state needed to understand it. An error message with no context is nearly useless.

Significant state transitions — order placed, payment captured, user deleted — which form the audit trail.

External calls, with target, duration and outcome, since other systems are where unexplained behaviour usually originates.

Decisions the system made, particularly where it chose between paths or applied a rule — this is what you need when asking "why did it do that for this user?".

A correlation or trace identifier on everything, propagated across services. This single practice transforms debugging distributed systems, and its absence makes it close to impossible.

What to never log:

Passwords, tokens, API keys, session identifiers — including in full request bodies and headers, which is the usual accidental route.

Full card numbers, and anything under payment rules.

Personal data beyond what is necessary, since logs are subject to data protection law, are widely readable inside an organisation, and are frequently retained longer than the systems they describe.

Health data, credentials in URLs, and full request/response dumps as a default.

How to log well:

Structured logging. Emit key-value fields rather than interpolated prose, so logs are queryable. "User 4821 failed login from 10.2.1.3" cannot be aggregated; the same data as fields can.

Use levels meaningfully, and resist the drift where everything becomes INFO.

Do not log in tight loops, which costs real performance and buries the useful lines.

Make it sampleable, and set retention deliberately.

Redact at the logging layer, not by remembering — the only reliable protection.

Logs are one of three signals, alongside metrics and traces, and each answers a different question.

Related Questions