Applications have produced logs for a long time, but a log message is only useful if it helps us understand what happened. Modern log tools can search more than plain text: they can filter on properties attached to an event. To make the most of them, we need to move from unstructured messages to structured logs.
What are unstructured logs?
Think of an application log as a diary. You might write “Marco had lunch at 13:00” in a diary. In code, the equivalent might look like this:
_logger.LogInformation($"User {userId} logged in at {DateTime.Now}");
_logger.LogError($"Error processing order {orderId}: {errorMessage}");
The output is plain text:
[2024-11-19 15:30:45 INF] User 12345 logged in at 19/11/2024 15:30:45
[2024-11-19 15:31:02 ERR] Error processing order ORD-789: Validation failed
These messages are easy for a person to read. For a machine, though, each line is just a string. Which part is the order ID? How can we filter reliably by that ID without parsing the text? A diary can be clear to its author yet hard to search systematically.
The shift to structured logging
Structured logging keeps messages readable while giving their values separate names and types. In .NET, the code uses a message template instead of string interpolation:
_logger.LogInformation("User {UserId} logged in at {LoginTime}",
userId,
DateTime.Now);
A logging provider can store an event like this in JSON:
{
"Timestamp": "2024-11-19T15:30:45.123Z",
"Level": "Information",
"Message": "User 12345 logged in at 19/11/2024 15:30:45",
"Properties": {
"UserId": "12345",
"LoginTime": "2024-11-19T15:30:45.123Z"
}
}
The difference is significant: UserId and LoginTime are properties, not fragments hidden inside the message. You can search, filter, and analyze them directly.
Benefits of structured logs
- Search: find all events for a user or order ID.
- Aggregation: calculate statistics based on log properties.
- Filtering: narrow results by any recorded property.
- Analysis: run richer queries over events.
- Observability: connect logs more effectively with other telemetry.
Conclusion
Moving to structured logging is like replacing a paper diary with a searchable digital record. You keep the human-readable account while gaining the ability to analyze its data.