1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[44],{27019:function(e,t,r){(window.__NEXT_P=window.__NEXT_P||[]).push(["/blog/logs-matter-more-than-metrics",function(){return r(42826)}])},42826:function(e,t,r){"use strict";r.r(t),r.d(t,{__toc:function(){return l}});var a=r(52322),o=r(6557),n=r(22945),i=r(24112),s=(r(21187),r(71199));const l=[{depth:2,value:"Not All Logs Are Created Equal",id:"not-all-logs-are-created-equal"},{depth:2,value:"Tricky Bugs Where Logs Are the Saving Grace",id:"tricky-bugs-where-logs-are-the-saving-grace"},{depth:3,value:"The Socket Timeout",id:"the-socket-timeout"},{depth:3,value:"Glofox Fake \u201cDDoS\u201d",id:"glofox-fake-ddos"},{depth:2,value:"Developer Religions",id:"developer-religions"},{depth:2,value:"A Closing Thought",id:"a-closing-thought"}];function d(e){const t=Object.assign({p:"p",em:"em",h2:"h2",h3:"h3",a:"a"},(0,s.a)(),e.components);return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(t.p,{children:(0,a.jsx)(t.em,{children:"Disclosure: I run an observability company, so this post is subject to some (heavy) bias. However, it also underscores why I wanted to work on HyperDX."})}),"\n",(0,a.jsx)(t.p,{children:"Metrics matter. Logs matter more."}),"\n",(0,a.jsx)(t.p,{children:"But that\u2019s not how most developers see it. Developers love metrics. It\u2019s something that they put care and attention into. Developers call meetings to figure out how to implement and interpret metrics. They are readily shown to new hires\u2014colorful dashboards with sprawling statistics measuring CPU, memory, and network health. Once, when demoing my product, I was told by a engineering director, \u201cThis is cool, but where are the fancy charts?\u201d"}),"\n",(0,a.jsx)(t.p,{children:"Logs get none of that hype. They are the ugly stepchild of observability. They get implemented, but with the attitude that you\u2019d treat a necessary evil. They don\u2019t get meetings dedicated to them. They\u2019re never flaunted to new hires. They just exist, quietly recording events in the background."}),"\n",(0,a.jsxs)(t.p,{children:["Here\u2019s the irony: while metrics might have the ",(0,a.jsx)(t.em,{children:"aesthetic"})," of a complex system, logs are ",(0,a.jsx)(t.em,{children:"more useful"})," 80% of the time. When an incorrect behavior emerges, logs are more likely to explain what happened than any metrics. Logs\u2014particularly logs with high cardinality\u2014provide a detailed recollection. They feature no dimension reduction. And metrics, by definition, do. They are just a crude read of a bug\u2019s ",(0,a.jsx)(t.em,{children:"effect"})," on an application."]}),"\n",(0,a.jsx)(t.h2,{id:"not-all-logs-are-created-equal",children:"Not All Logs Are Created Equal"}),"\n",(0,a.jsxs)(t.p,{children:["The importance of logs is partially diminished because they are poorly implemented in many organizations. The difference between a good log and a ",(0,a.jsx)(t.em,{children:"great"})," log is striking."]}),"\n",(0,a.jsxs)(t.p,{children:["Great logs are those with attributes that can tie an event to the source of the issue (e.g. a user_id, payment, host, etc.). This is often framed as logs with ",(0,a.jsx)(t.em,{children:"high cardinality"}),". High cardinality means that the log includes multiple fields containing unique values. For example, a front-end logged event might include a session ID, a request ID, a user ID, an organization ID, a payment ID, a timestamp, and a network trace. High cardinality like this is a heuristic for a log actually being useful in the case of an error."]}),"\n",(0,a.jsx)(t.h2,{id:"tricky-bugs-where-logs-are-the-saving-grace",children:"Tricky Bugs Where Logs Are the Saving Grace"}),"\n",(0,a.jsx)(t.p,{children:"I have two contrasting examples that illustrate the value of logs."}),"\n",(0,a.jsx)(t.h3,{id:"the-socket-timeout",children:"The Socket Timeout"}),"\n",(0,a.jsx)(t.p,{children:"A while ago, we had a weird issue with sockets\u2014customers reported certain queries would unpredictably time-out. On our dashboard, there were no reports of failed ClickHouse queries\u2014however, customers failed to get data that originated in ClickHouse. Looking through our traces associated with those specific customers and timestamps, we discovered the error: The ClickHouse query succeeded, but the load balancer\u2019s socket timed out before ClickHouse could reply. This was obvious by comparing the timestamps of the socket and the ClickHouse response, as well as observing the corresponding error returned within our API."}),"\n",(0,a.jsx)(t.p,{children:"Using the logs, we were able to correlate the types of requests that would lead to the same behavior. Additionally, on the ClickHouse side, we could determine what query properties caused sluggish performance. These details are all things untraceable to a spurious failure metric."}),"\n",(0,a.jsx)(t.h3,{id:"glofox-fake-ddos",children:"Glofox Fake \u201cDDoS\u201d"}),"\n",(0,a.jsxs)(t.p,{children:["Pierre Vincent has a ",(0,a.jsx)(t.a,{href:"https://www.youtube.com/watch?v=NTWsaaYKiH0",children:"fantastic developer talk"})," at ",(0,a.jsx)(t.a,{href:"https://devsummit.infoq.com/conference/boston2024",children:"InfoQ\u2019s Dev Summit"})," where he discusses logs versus metrics. Pierre works at ",(0,a.jsx)(t.a,{href:"https://www.glofox.com",children:"Glofox"}),", a gym management software company. A few years ago, they experienced an incident that highlighted how metrics could be misleading in the absence of great logs."]}),"\n",(0,a.jsx)(t.p,{children:"Because Glofox creates gym software, the pandemic significantly impacted their product\u2019s usage. Gyms suddenly closed (and subsequently opened) on government orders. On one of these reopening dates, Glofox experienced a massive surge in requests, which lit up metrics."}),"\n",(0,a.jsx)(t.p,{children:"Through metrics, Glofox appeared to be suffering from a DDoS attack originating in Singapore. The easy remedy would be blocking all the IPs dispatching thousands of requests. Singapore was also reopening g
1yms that day, and Pierre suspected the incident wasn\u2019t actually an attack. But it also wasn\u2019t just returning users; the requests were overwhelming."}),"\n",(0,a.jsx)(t.p,{children:"By diving through logs, Glofox\u2019s engineering team nailed the culprit: Glofox\u2019s front-end had a bug where lengthy sessions would dispatch more and more requests due to an unintentional JS loop. Many of Glofox\u2019s Singaporean customers had been shut down for months but had minimized tabs. By reopening these tabs, Glofox\u2019s back end was inundated by months of quarantined requests, which imitated a DDoS attack."}),"\n",(0,a.jsx)(t.p,{children:"Only because of logs was Glofox able to diagnose the problem and devise a quick remedy that enabled their application to persist on one of the most important days of the year."}),"\n",(0,a.jsx)(t.h2,{id:"developer-religions",children:"Developer Religions"}),"\n",(0,a.jsx)(t.p,{children:"I\u2019ll admit this debate hinges on some concept of developer religions\u2014the idea that developers, myself included, have strong beliefs because of some hypothetical ideal. Some developers swear by the importance of metrics; I care more about capturing high cardinality data through logs."}),"\n",(0,a.jsx)(t.p,{children:"But to be clear, it is ridiculous to believe one should exist at the demise of the other. It\u2019s more a matter of foundations. In my worldview, high cardinality should be the north star for building a good observability stack; metrics should follow."}),"\n",(0,a.jsxs)(t.p,{children:["Funnily enough, I hold the opposite belief regarding our marketing strategy. For marketing, I care more about metrics than individual stories. That\u2019s because marketing is an optimizing outcomes problem\u2014strategies succeed or fail on the basis on an aggregate. That mindset doesn\u2019t hold when it comes to development, where the goal is to eliminate issues that ",(0,a.jsx)(t.em,{children:"any"})," user is facing."]}),"\n",(0,a.jsx)(t.h2,{id:"a-closing-thought",children:"A Closing Thought"}),"\n",(0,a.jsx)(t.p,{children:"Logs matter. They matter in the same vein that testing matters, CI/CD matters, security matters. Without good logs, errors turn from nuisances to headaches. So next time that your team brings up the importance of metrics, push aside the hype of fancy charts to spend time improving your logs. Of course, you can take my opinion with a grain of salt\u2014I run a observability company that\u2019s built on good logs\u2014but there\u2019s a reason that I ended up in this space."})]})}const c={MDXContent:function(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};const{wrapper:t}=Object.assign({},(0,s.a)(),e.components);return t?(0,a.jsx)(t,{...e,children:(0,a.jsx)(d,{...e})}):d(e)},pageOpts:{filePath:"pages/blog/logs-matter-more-than-metrics.mdx",route:"/blog/logs-matter-more-than-metrics",frontMatter:{title:"Logs Matter More Than Metrics",date:"Feb 7, 2025",summary:"Developers have a strange fascination with metrics and relatively little love for logs. Together, these are misplaced priorities.",hero:"/assets/blog/logs-matter-more-than-metrics/hero.png",by:"Michael Shi"},timestamp:1781601642e3,pageMap:[{kind:"Meta",data:{"_*":{display:"hidden"},docs:{title:"Docs",display:"children",type:"page"},blog:{title:"Blog",display:"children",type:"page",theme:{toc:!1,sidebar:!1,pagination:!1,footer:!1,typesetting:"article",layout:"raw"}},terms:{title:"Terms",display:"hidden",type:"page",theme:{sidebar:!1,pagination:!1}}}},{kind:"Folder",name:"blog",route:"/blog",children:[{kind:"Meta",data:{"*":{display:"hidden",theme:{toc:!0,sidebar:!1,pagination:!1,footer:!0,typesetting:"article",layout:"default"}},"clickhouse-acquires-hyperdx-to-accelerate-the-future-of-open-source-observability":"ClickHouse Acquires HyperDX to Accelerate the Future of Open-Source Observability","datadog-alternatives":"Top Open Source Alternatives to Datadog for Log and Metric Monitoring","logs-vs-traces":"Logs versus Traces: The Comprehensive Difference in 2025","opentelemetry-vs-prometheus":"OpenTelemetry vs Prometheus: Understanding the Differences","sampling-for-observability":"Why is Sampling for Observability So Hard?","datadog-grafana":"Datadog vs Grafana","datadog-vs-new-relic":"Datadog vs New Relic","securely-configure-your-otel-collector":"How to Securely Configure the OpenTelemetry Collector","securing-opentelemetry-hosting":"Securing your OpenTelemetry Hosting Instance: A Brief Guide","logs-matter-more-than-metrics":"Logs Matter More Than Metrics","best-datadog-alternatives-to-consider":"12 Best Datadog Alternatives to Consider in 2025","integrating-hyperdx-vue-js-opentelemetry":"Integrating HyperDX with Vue.js using OpenTelemetry","testing-sending-opentelemetry-events-curl":"Sending and Testing OpenTelemetry Events using cURL","whats-the-problem-with-opentelemetry":"What's the Problem with OpenTelemetry?","node-js-logging-best-practices":"Node.js Logging Best Practices","mirascope-hyperdx-integration":"HyperDX & Mirascope Integration","why-clickhouse-over-elasticsearch-observability":"Why We Chose Clickhouse Over Elasticsearch for Storing Observability Data","monitoring-node-js-with-opentelemetry":"How to Monitor & Debug Node.js Web App Performance with OpenTelemetry","opentelemetry-python-server-auto-instrumentation":"How to Auto-Instrument Python Servers with OpenTelemetry for Performance and Error Monitoring","release-notes-mar-2024"
1:"March 2024 Release Notes","release-notes-jan-2024":"January 2024 Release Notes","introducing-log-patterns-automatically-cluster-and-view-trends":"Introducing Log Patterns - Automatically Cluster and View Log Trends","aws-outage-analysis":"Analyzing Incident Data for Over 400 Sites During the AWS Lambda Outage","browser-based-distributed-tracing-with-opentelemetry":"How to Debug From Frontend to Backend Faster with OpenTelemetry","speeding-up-search-latency-with-server-sent-events-on-express":"How We Sped Up Search Latency with Server-sent Events in Express.js","docker-buildx-cache-with-github-actions":"Decreasing Docker Build Times by 50% in Github Actions with Docker Buildx Caching"}},{kind:"MdxPage",name:"aws-outage-analysis",route:"/blog/aws-outage-analysis",frontMatter:{title:"Analyzing Incident Data for Over 400 Sites During the AWS Lambda Outage",date:"Jun 14, 2023",summary:"How many sites were impacted by AWS's latest outage in US East 1, and how did the impacted sites respond?",hero:"/assets/blog/lambda_fire.jpg",by:"Michael Shi"}},{kind:"MdxPage",name:"best-datadog-alternatives-to-consider",route:"/blog/best-datadog-alternatives-to-consider",frontMatter:{title:"12 Best Datadog Alternatives to Consider in 2025",date:"Jan 30, 2025",summary:"Top 12 Datadog alternatives to consider in 2025 including HyperDX, New Relic and Splunk.",hero:"/assets/blog/12-best-datadog-alternatives-to-consider/comparison_splash.png",by:"Michael Shi"}},{kind:"MdxPage",name:"browser-based-distributed-tracing-with-opentelemetry",route:"/blog/browser-based-distributed-tracing-with-opentelemetry",frontMatter:{title:"How to Debug From Frontend to Backend Faster with OpenTelemetry",date:"Jun 5, 2023",summary:"How to implement OpenTelemetry to get full context of bugs from frontend to backend, with just a few extra lines of code.",hero:"/assets/blog/neon_servers.jpg",by:"Michael Shi"}},{kind:"MdxPage",name:"clickhouse-acquires-hyperdx-to-accelerate-the-future-of-open-source-observability",route:"/blog/clickhouse-acquires-hyperdx-to-accelerate-the-future-of-open-source-observability",frontMatter:{title:"ClickHouse Acquires HyperDX to Accelerate the Future of Open-Source Observability",date:"Mar 6, 2025",summary:"HyperDX is joining forces with ClickHouse to deliver the most performant, cost-effective, and developer-friendly observability platform.",hero:"/assets/blog/clickhouse-acquires-hyperdx-to-accelerate-the-future-of-open-source-observability/hero.png",by:"Michael Shi"}},{kind:"MdxPage",name:"datadog-alternatives",route:"/blog/datadog-alternatives",frontMatter:{title:"Top Open Source Alternatives to Datadog for Log and Metric Monitoring",description:"Explore powerful open source monitoring solutions that provide real-time insights without the hefty price tag of enterprise tools like Datadog.",date:"Mar 5, 2025",tags:["monitoring","observability","open-source","datadog-alternatives"],hero:"/assets/blog/datadog-os-alts.png",by:"Ali Ahmed"}},{kind:"MdxPage",name:"datadog-grafana",route:"/blog/datadog-grafana",frontMatter:{title:"Datadog vs Grafana",date:"Feb 26, 2025",summary:"Datadog and Grafana are both leading observability tools. Which is better for who?",hero:"/assets/blog/comparisons/datadog-grafana.png",by:"Mahir Khan"}},{kind:"MdxPage",name:"datadog-vs-new-relic",route:"/blog/datadog-vs-new-relic",frontMatter:{title:"Datadog vs New Relic",date:"Feb 26, 2025",summary:"Datadog and New Relic are both leading observability tools. Which is better for who?",hero:"/assets/blog/comparisons/datadog-newrelic.png",by:"Mahir Khan"}},{kind:"MdxPage",name:"docker-buildx-cache-with-github-actions",route:"/blog/docker-buildx-cache-with-github-actions",frontMatter:{title:"Decreasing Docker Build Times by 50% in Github Actions with Docker Buildx Caching",date:"Jan 14, 2023",summary:"How we improved Docker Build times by 50% with Github Actions Caches and Docker Buildx for our Cypress E2E Tests",hero:"/assets/blog/container-racecar.jpg",by:"Michael Shi"}},{kind:"MdxPage",name:"integrating-hyperdx-vue-js-opentelemetry",route:"/blog/integrating-hyperdx-vue-js-opentelemetry",frontMatter:{title:"Integrating HyperDX with Vue.js using OpenTelemetry",date:"Aug 15, 2024",summary:"Integrate HyperDX with Vue.js to seamlessly capture frontend events, errors, and network requests using OpenTelemetry for enhanced debugging.",hero:"/assets/blog/integrating-hyperdx-vue-js-opentelemetry/hero.png",by:"Mark Percival"}},{kind:"MdxPage",name:"introducing-log-patterns-automatically-cluster-and-view-trends",route:"/blog/introducing-log-patterns-automatically-cluster-and-view-trends",frontMatter:{title:"Introducing Log Patterns - Automatically Cluster and View Log Trends",date:"Jul 20, 2023",summary:"Log patterns speeds up analyzing logs by clustering similar log lines together, and showing their trends over time.",hero:"/assets/blog/log_pattern_0.jpg",by:"Michael Shi"}},{kind:"MdxPage",name:"logs-matter-more-than-metrics",route:"/blog/logs-matter-more-than-metrics",frontMatter:{title:"Logs Matter More Than Metrics",date:"Feb 7, 2025",summary:"Developers have a strange fascination with metrics and relatively little love for logs. Together, these are misplaced priorities.",hero:"/assets/blog/logs-matter-more-than-metrics/hero.png",by:"Michael Shi"}},{kind:"MdxPage",name:"logs-vs-traces",route:"/blog/logs-vs-traces",frontMatter:{title:"Logs versus Traces: The Comprehensive Difference in 2025",description:"Learn the critical differences between logs and traces in modern observability. This guide explains how discrete log messages and distributed trace data complement each other to provide complete system visibility and faster troubleshooting in complex architectures.",date:"Mar 5, 2025",tags:["observability","distributed-tracing","logging","monitoring","microservices","troubleshooting","system-performance","devops","opentelemetry","root-cause-analysis"],hero:"/assets/blog/logs-vs-traces.png",by:"Ali Ahmed"}},{kind:"MdxPage",name:"mirascope-hyperdx-integration",route:"/blog/mirascope-hyperdx-integration",frontMatter:{title:"HyperDX & Mirascope Integration",date:"May 30, 2024",summary:"We are excited to share that HyperDX is now integrated
1with Mirascope, a dev-friendly Python toolkit for building LLM-powered applications.",hero:"/assets/blog/hyperdx-mirascope-integration/hyperdx-mirascope.png",by:"Michael Shi"}},{kind:"MdxPage",name:"monitoring-node-js-with-opentelemetry",route:"/blog/monitoring-node-js-with-opentelemetry",frontMatter:{title:"How to Monitor & Debug Node.js Web App Performance with OpenTelemetry",date:"May 10, 2024",summary:"Log patterns speeds up analyzing logs by clustering similar log lines together, and showing their trends over time.",hero:"/assets/blog/monitoring-node-js-with-opentelemetry/node-server-auto-instrumentation.png",by:"Arindam Majumder"}},{kind:"MdxPage",name:"node-js-logging-best-practices",route:"/blog/node-js-logging-best-practices",frontMatter:{title:"Node.js Logging Best Practices",date:"Jun 20, 2024",summary:"Effective logging can make a night and day difference to debugging and managing Node.js applications. We'll explore best practices for logging in Node.js and a few popular logging libraries to get you started.\n",hero:"/assets/blog/node-js-logging-best-practices/hero.png",by:"Pavel Romanov"}},{kind:"MdxPage",name:"opentelemetry-python-server-auto-instrumentation",route:"/blog/opentelemetry-python-server-auto-instrumentation",frontMatter:{title:"How to Auto-Instrument Python Servers with OpenTelemetry for Performance and Error Monitoring",date:"Apr 5, 2024",summary:"How to quickly instrument your Python servers with OpenTelemetry to easily diagnose performance issues and debug errors.",hero:"/assets/blog/opentelemetry-python-server-auto-instrumentation/python-server-opentelemetry-auto-instrumentation.png",by:"Panchanan Panigrahi"}},{kind:"MdxPage",name:"opentelemetry-vs-prometheus",route:"/blog/opentelemetry-vs-prometheus",frontMatter:{title:"OpenTelemetry vs Prometheus: Understanding the Differences",description:"Learn how OpenTelemetry and Prometheus complement each other in the observability ecosystem. This guide explains their distinct purposes, how they work individually, and how they can be effectively used together in modern monitoring stacks.",date:"Mar 5, 2025",tags:["observability","opentelemetry","prometheus","monitoring","metrics","cncf","cloud-native","devops","kubernetes","time-series"],hero:"/assets/blog/opentelemetry-vs-prometheus.png",by:"Mathew Pregasen"}},{kind:"MdxPage",name:"release-notes-jan-2024",route:"/blog/release-notes-jan-2024",frontMatter:{title:"January 2024 Release Notes",date:"Jan 31, 2024",summary:"We're kicking off the new year strong with new alerts overview, tagging saved searches, chart improvements, and more.",hero:"/assets/blog/release-notes-jan-2024/jan-2024-release-notes.png",by:"Michael Shi"}},{kind:"MdxPage",name:"release-notes-mar-2024",route:"/blog/release-notes-mar-2024",frontMatter:{title:"March 2024 Release Notes",date:"Mar 31, 2024",summary:"Service dashboard, generic webhook alerts, HyperDX Local, and more.",hero:"/assets/blog/release-notes-mar-2024/mar-2024-release-notes.png",by:"Michael Shi"}},{kind:"MdxPage",name:"sampling-for-observability",route:"/blog/sampling-for-observability",frontMatter:{title:"Why is Sampling for Observability So Hard?",description:"Learn how to implement effective sampling strategies for high-volume observability data. This guide explains head sampling vs tail sampling approaches, when to use each method, and modern techniques for balancing cost with data quality.",date:"Mar 5, 2025",tags:["observability","sampling","telemetry","distributed-tracing","tail-sampling","head-sampling","data-management","monitoring","scaling","performance"],hero:"/assets/blog/sampling-for-observability.png",by:"Mahir Khan"}},{kind:"MdxPage",name:"securely-configure-your-otel-collector",route:"/blog/securely-configure-your-otel-collector",frontMatter:{title:"How to Securely Configure the OpenTelemetry Collector",summary:"How do you securely configure your OTel Collector for production?",date:"Feb 25, 2025",tags:["observability","opentelemetry","otel collector","collector","sampling","telemetry","distributed-tracing","tail-sampling","head-sampling","data-management","monitoring","scaling","performance"],hero:"/assets/blog/securing-your-otel-collector.png",by:"Rakan AlZagha"}},{kind:"MdxPage",name:"securing-opentelemetry-hosting",route:"/blog/securing-opentelemetry-hosting",frontMatter:{title:"Securing your OpenTelemetry Hosting Instance: A Brief Guide",summary:"How do you secure your OpenTelemetry Hosting instances?",date:"Feb 25, 2025",tags:["observability","opentelemetry","sampling","telemetry","distributed-tracing","tail-sampling","head-sampling","data-management","monitoring","scaling","performance"],hero:"/assets/blog/securing-your-otel-instance.png",by:"Rakan AlZagha"}},{kind:"MdxPage",name:"speeding-up-search-latency-with-server-sent-events-on-express",route:"/blog/speeding-up-search-latency-with-server-sent-events-on-express",frontMatter:{title:"How We Sped Up Search Latency with Server-sent Events in Express.js",date:"Jun 2, 2023",summary:"Our experience with speeding up HyperDX's search UI by adopting Server-sent events in Express.js",hero:"/assets/blog/ocean_mag.jpg",by:"Michael Shi"}},{kind:"MdxPage",name:"testing-sending-opentelemetry-events-curl",route:"/blog/testing-sending-opentelemetry-events-curl",frontMatter:{title:"Sending and Testing OpenTelemetry Events using cURL",date:"Aug 15, 2024",summary:"Learn how to use cURL to send OpenTelemetry events to test your OpenTelemetry endpoint.",hero:"/assets/blog/testing-sending-opentelemetry-events-curl/hero.png",by:"Mark Percival"}},{kind:"MdxPage",name:"whats-the-problem-with-opentelemetry",route:"/blog/whats-the-problem-with-opentelemetry",frontMatter:{title:"What's the Problem with OpenTelemetry?",date:"Jun 25, 2024",summary:"Is OpenTelemetry a fundamentally flawed project, or is there a lot more to the story?",hero:"/assets/blog/whats-the-problem-with-opentelemetry/hero.png",by:"Michael Shi"}},{kind:"MdxPage",name:"why-clickhouse-over-elasticsearch-observability",route:"/blog/why-clickhouse-over-elasticsearch-observability",frontMatter:{title:"Why We Chose Clickhouse Over Elasticsearch for Storing Observability Data",date:"May 13, 2024",summary:"Why we thought Clickhouse was the right database choice for storing logs, metrics, traces and events for HyperDX over a traditional pick like Elasticsearch.",hero:"/assets/blog/why-clickhouse-over-elasticsearch-observability/secret_sauce_hero.png",by:"Michael Shi"}}]},{kind:"MdxPage",name:"blog",route:"/blog"},{kind:"Folder",name:"docs",route:"/docs",children:[{kind:"Meta",data:{index:"Getting Started",search:"Search",alerts:"Alerts",dashboards:"Dashboards",install:"Install",integrations:"Integrations",api:"API","oss-vs-cloud":"OSS vs Cloud"}},{kind:"MdxPage",name:"alerts",route:"/docs/alerts",frontMatter:{title:"Alerts"}},{kind:"Folder",name:"api",route:"/docs/api",children:[{kind:"MdxPage",name:"alerts",route:"/docs/api/alerts",frontMatter:{title:"Managing Alerts"}},{kind:"MdxPage",name:"charts",route:"/docs/api/charts",frontMatter:{title:"Querying Chart Data"}},{kind:"MdxPage",name:"dashboards",route:"/docs/api/dashboards",frontMatter:{title:"Managing Dashboards"}},{kind:"Meta",data:{alerts:"Managing Alerts",dashboards:"Managing Dashboards",charts:"Querying Chart Data"}}]},{kind:"MdxPage",name:"dashboards",route:"/docs/dashboards",frontMatter:{title:"Dashboards"}},{kind:"MdxPage",name:"index",route:"/docs",frontMatter:{title:"Getting Started"}},{kind:"Folder",name:"install",route:"/docs/install",children:[{kind:"Meta",data:{index:"Introduction","-- SDKs --":{type:"separator",title:"SDKs"},browser:"Browser JS",elixir:"Elixir",golang:"Golang",java:"Java",nest:"NestJS",next:"Next.js",javascript:"Node.js",deno:"Deno",python:"Python","react-native":"React Native",ruby:"Ruby on Rails","-- Platforms --":{type:"separator",title:"Platforms"},"aws-cloudwatch":"AWS CloudWatch","aws-ec2":"AWS EC2","aws-ecs":"AWS ECS","aws-lambda":"AWS Lambda","aws-sns":"AWS SNS",cloudflare:"Cloudflare Workers",docker:"Docker/Docker Compose",fly:"Fly.io",heroku:"Heroku",kubernetes:"Kubernetes",vercel:"Vercel","-- Data Collectors --":{type:"separator",title:"Data Collectors"},fluentd:"Fluentd",opentelemetry:"OpenTelemetry",syslog:"Syslog",fluentbit:"Fluent Bit","-- LLMs --":{type:"separator",title:"LLMs"},mirascope:"Mirascope",openlit:"OpenLIT",openllmetry:"OpenLLMetry"}},{kind:"MdxPage",name:"aws-cloudwatch",route:"/docs/install/aws-cloudwatch",frontMatter:{title:"AW
1S CloudWatch"}},{kind:"MdxPage",name:"aws-ec2",route:"/docs/install/aws-ec2",frontMatter:{title:"AWS EC2"}},{kind:"MdxPage",name:"aws-ecs",route:"/docs/install/aws-ecs",frontMatter:{title:"AWS ECS"}},{kind:"MdxPage",name:"aws-lambda",route:"/docs/install/aws-lambda",frontMatter:{title:"AWS Lambda"}},{kind:"MdxPage",name:"aws-sns",route:"/docs/install/aws-sns",frontMatter:{title:"AWS Simple Notification Service (SNS)"}},{kind:"MdxPage",name:"browser",route:"/docs/install/browser",frontMatter:{title:"Browser"}},{kind:"MdxPage",name:"cloudflare",route:"/docs/install/cloudflare",frontMatter:{title:"Cloudflare Workers"}},{kind:"MdxPage",name:"deno",route:"/docs/install/deno",frontMatter:{title:"Deno"}},{kind:"MdxPage",name:"docker",route:"/docs/install/docker",frontMatter:{title:"Docker/Docker Compose"}},{kind:"MdxPage",name:"elixir",route:"/docs/install/elixir",frontMatter:{title:"Elixir"}},{kind:"MdxPage",name:"fluentbit",route:"/docs/install/fluentbit",frontMatter:{title:"Fluent Bit"}},{kind:"MdxPage",name:"fluentd",route:"/docs/install/fluentd",frontMatter:{title:"Fluentd"}},{kind:"MdxPage",name:"fly",route:"/docs/install/fly",frontMatter:{title:"Fly.io"}},{kind:"MdxPage",name:"golang",route:"/docs/install/golang",frontMatter:{title:"Golang"}},{kind:"MdxPage",name:"heroku",route:"/docs/install/heroku",frontMatter:{title:"Heroku"}},{kind:"MdxPage",name:"index",route:"/docs/install",frontMatter:{title:"Introduction"}},{kind:"MdxPage",name:"java",route:"/docs/install/java",frontMatter:{title:"Java Integration"}},{kind:"MdxPage",name:"javascript",route:"/docs/install/javascript",frontMatter:{title:"Node.js"}},{kind:"MdxPage",name:"kubernetes",route:"/docs/install/kubernetes",frontMatter:{title:"Kubernetes"}},{kind:"MdxPage",name:"mirascope",route:"/docs/install/mirascope",frontMatter:{title:"Mirascope"}},{kind:"MdxPage",name:"nest",route:"/docs/install/nest",frontMatter:{title:"NestJS"}},{kind:"MdxPage",name:"next",route:"/docs/install/next",frontMatter:{title:"Next.js Serverless Functions"}},{kind:"MdxPage",name:"openlit",route:"/docs/install/openlit",frontMatter:{title:"OpenLIT"}},{kind:"MdxPage",name:"openllmetry",route:"/docs/install/openllmetry",frontMatter:{title:"OpenLLMetry"}},{kind:"MdxPage",name:"opentelemetry",route:"/docs/install/opentelemetry",frontMatter:{title:"OpenTelemetry"}},{kind:"MdxPage",name:"python",route:"/docs/install/python",frontMatter:{title:"Python"}},{kind:"MdxPage",name:"react-native",route:"/docs/install/react-native",frontMatter:{title:"React Native"}},{kind:"MdxPage",name:"ruby",route:"/docs/install/ruby",frontMatter:{title:"Ruby on Rails"}},{kind:"MdxPage",name:"syslog",route:"/docs/install/syslog",frontMatter:{title:"Syslog"}},{kind:"MdxPage",name:"vercel",route:"/docs/install/vercel",frontMatter:{title:"Vercel"}}]},{kind:"Folder",name:"integrations",route:"/docs/integrations",children:[{kind:"MdxPage",name:"enterprise-sso",route:"/docs/integrations/enterprise-sso",frontMatter:{title:"Enterprise SSO"}},{kind:"MdxPage",name:"pagerduty",route:"/docs/integrations/pagerduty",frontMatter:{title:"Pagerduty"}},{kind:"MdxPage",name:"sourcemap",route:"/docs/integrations/sourcemap",frontMatter:{title:"Javascript Source Maps"}},{kind:"Meta",data:{"enterprise-sso":"Enterprise SSO",sourcemap:"Javascript Source Maps",pagerduty:"Pagerduty"}}]},{kind:"MdxPage",name:"oss-vs-cloud",route:"/docs/oss-vs-cloud",frontMatter:{title:"OSS vs Cloud"}},{kind:"MdxPage",name:"search",route:"/docs/search",frontMatter:{title:"Search"}},{kind:"Folder",name:"v2",route:"/docs/v2",children:[{kind:"Meta",data:{index:"Getting Started","-- Setup --":{type:"separator",title:"Setup"},connections:"Connections",sources:"Sources",local:"Local Mode","-- Querying --":{type:"separator",title:"Querying"},search:"Search"}},{kind:"MdxPage",name:"connections",route:"/docs/v2/connections",frontMatter:{title:"Connections"}},{kind:"MdxPage",name:"index",route:"/docs/v2",frontMatter:{title:"Getting Started"}},{kind:"MdxPage",name:"local",route:"/docs/v2/local",frontMatter:{title:"Local Mode"}},{kind:"MdxPage",name:"search",route:"/docs/v2/search",frontMatter:{title:"Search"}},{kind:"MdxPage",name:"sources",route:"/docs/v2/sources",frontMatter:{title:"Source"}}]}]},{kind:"Folder",name:"terms",route:"/terms",children:[{kind:"MdxPage",name:"dpa",route:"/terms/dpa",frontMatter:{title:"DeploySentinel Customer Data Processing Addendum",date:"Mar 28, 2025"}},{kind:"MdxPage",name:"privacy",route:"/terms/privacy",frontMatter:{title:"Privacy Policy",date:"Feb 17, 2022"}},{kind:"MdxPage",name:"security",route:"/terms/security",frontMatter:{title:"Information Security Addendum",date:"Mar 28, 2025"}},{kind:"MdxPage",name:"service-2022-02-17",route:"/terms/service-2022-02-17",frontMatter:{title:"ARCHIVE: Terms of Service",date:"Feb 17, 2022"}},{kind:"MdxPage",name:"service",route:"/terms/service",frontMatter:{title:"Terms of Service",date:"Mar 28, 2025"}},{kind:"MdxPage",name:"subprocessors",route:"/terms/subprocessors",frontMatter:{title:"HyperDX Service Sub-Processors and Affiliates",date:"Mar 28, 2025"}},{kind:"Meta",data:{dpa:"DeploySentinel Customer Data Processing Addendum",security:"Information Security Addendum",service:"Terms of Service",subprocessors:"HyperDX Service Sub-Processors and Affiliates",privacy:"Privacy Policy","service-2022-02-17":"ARCHIVE: Terms of Service"}}]}],flexsearch:{codeblocks:!0},title:"Logs Matter More Than Metrics",headings:l},pageNextRoute:"/blog/logs-matter-more-than-metrics",nextraLayout:n.ZP,themeConfig:i.Z};t.default=(0,o.j)(c)},18771:function(e,t,r){"use strict";r.d(t,{Z:function(){return o}});var a=r(52322);function o(e){let{size:t=16}=e;return(0,a.jsxs)("svg",{width:t,height:t,viewBox:"0 0 512 512",fill:"none",xmlns:"http://www.w3.org/2000/svg",children:[(0,a.jsxs)("g",{clipPath:"url(#clip0_614_1164)",children:[(0,a.jsx)("path",{d:"M256 0L477.703 128V384L256 512L34.2975 384V128L256 0Z",fill:"#4FFA7A"}),(0,a.jsx)("path",{d:"M311.365 84.4663C314.818 86.9946 316.431 92.1862 315.256 96.9926L284.313 223.563H341.409C344.836 223.563 347.936 226.127 349.295 230.086C350.655 234.046 350.014 238.644 347.665 241.786L210.211 425.598C207.472 429.26 203.089 430.062 199.635 427.534C196.182 425.005 194.569 419.814 195.744 415.007L226.686 288.437H169.591C166.164 288.437 163.064 285.873 161.705 281.914C160.345 277.954 160.986 273.356 163.335 270.214L300.789 86.4023C303.528 82.7403 307.911 81.938 311.365 84.4663Z",fill:"#080A0B"})]}),(0,a.jsx)("defs",{children:(0,a.jsx)("clipPath",{id:"clip0_614_1164",children:(0,a.jsx)("rect",{width:"512",height:"512",fill:"white"})})})]})}},25703:function(e,t,r){"use strict";r.d(t,{Z:function(){return n}});var a=r(52322),o=(r(2784),r(18771));function n(e){let{size:t="sm"}=e;const r={sm:{fontSize:14,iconSize:14,iconMarginBottom:3},md:{fontSize:16,iconSize:16,iconMarginBottom:3},lg:{fontSize:18,iconSize:18,iconMarginBottom:3},xl:{fontSize:22,iconSize:22,iconMarginBottom:3}};return(0,a.jsxs)("div",{className:"align-items-center d-flex",style:{color:"white",userSelect:"none"},children:[(0,a.jsx)("div",{className:"me-2",style:{marginBottom:r[t].iconMarginBottom},children:(0,a.jsx)(o.Z,{size:r[t].iconSize})}),(0,a.jsx)("span",{className:"fw-bold mono",style:{fontSize:r[t].fontSize},children:"HyperDX"})]})}},24112:function(e,t,r){"use strict";r.d(t,{Z:function(){return u}});var a=r(52322),o=(r(2784),r(25703)),n=r(37108),i=r.n(n),s=r(96577),l=r.n(s),d=r(22945),c=r(65075),g=r(19233),h=r(1699);const m={color:"#fff",backgroundColor:"#16161B"};var u={useNextSeoProps:function(){const e=(0,h.Nn)(),t=(0,h.At)(),r=(0,h.Gu)(),{frontMatter:a,title:o}=(0,d.ZR)(),n=e?"HyperDX Blog":t?"HyperDX Docs":r?"HyperDX":"";var i;return{title:"".concat(null!==(i=a.title)&&void 0!==i?i:o," - ").concat(n),description:a.summary,openGraph:{...null!=a.hero?{images:[{url:"https://www.hyperdx.io".concat(a.hero),alt:"HyperDX Blog",type:"image/png"}]}:{},site_name:"HyperDX"},twitter:{site:"@hyperdxio",cardType:"summary_large_image"}}},logo:(0,a.jsx)(o.Z,{}),footer:{text:"Made with \u2665 in San Francisco, \xa9 2025 DeploySentinel, Inc."},head:null,editLink:{component:null},darkMode:!1,feedback:{content:null},nextThemes:{forcedTheme:"dark",defaultTheme:"dark"},toc:{title:"Contents",float:!0,backToTop:!0},components:{},main:function(e){let{children:t}=e;const{frontMatter:r}=(0,d.ZR)(),o=(0,h.Nn)(),n=(0,h.At)();return(0,a.jsxs)("div",{className:"roboto",children:[(0,a.jsxs)("div",{className:"jsx-10a5b8d95e557000",children:[(0,a.jsx)(i(),{id:"10a5b8d95e557000",children:"body{overflow-x:hidden}img{-webkit-border-radius:15px;-moz-border-radius:15px;border-radius:15px}.children code{color:#dcdcdc}.children pre{background:none!important;outline:1px solid#333!important}"}),o&&(0,a.jsx)("div",{style:{margin:"-150px -50vw -100px",height:250,filter:"blur(150px)",opacity:.5,zIndex:0,position:"relative",background:"linear-gradient(90deg, rgb(80, 250, 219) 0%, rgba(164, 42, 238) 100%)",pointerEvents:"none"},className:"jsx-10a5b8d95e557000"}),(0,a.jsxs)("div",{style:{zIndex:1,position:"relative"},className:"jsx-10a5b8d95e557000",children:[(0,a.jsx)("h1",{style:{borderBottom:"none"},className:"jsx-10a5b8d95e557000 mb-3 mt-3 fs-0 fw-bold white-text-gradient",children:r.title}),o&&(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)("div",{className:"jsx-10a5b8d95e557000 text-muted mt-2 fs-7 mb-4 text-center d-flex justify-content-center",children:(0,a.jsxs)("div",{className:"jsx-10a5b8d95e557000 d-inline-flex align-items-center",children:[null!=r.by&&(0,a.jsxs)("span",{className:"jsx-10a5b8d95e557000 d-inline-flex align-items-center",children:[(0,a.jsxs)("span",{className:"jsx-10a5b8d95e557000 mx-2",children:[(0,a.jsx)(l(),{width:"24",height:"24",className:"rounded-circle",src:"/assets/blog/profiles/".concat(r.by,".jpg"),alt:r.by})," "]})," ",r.by," \u2022\xa0"]}),r.date]})}),null!=r.hero&&(0,a.jsx)("div",{style:{maxHeight:380,width:"100%",height:"40%",position:"relative",aspectRatio:"5 / 2"},className:"jsx-10a5b8d95e557000 mb-4",children:(0,a.jsx)(l(),{quality:100,unoptimized:!0,style:{objectFit:"cover"},className:"rounded",src:r.hero,alt:r.title,fill:!0})})]})]})]}),(0,a.jsxs)("div",{style:{zIndex:1,position:"relative"},className:"children",children:[o&&(0,a.jsx)(i(),{id:"ec8001275257943c",children:".children{font-size:17px;color:#dcdcdc}.children p{line-height:1.9rem!important}"}),!o&&(0,a.jsx)(i(),{id:"7be18ccd00380423",children:'.children{font-size:16px;color:#dcdcdc}.children a{text-decoration:none!important}.children div[role="tablist"]{margin-top:0!important}.children p{line-height:1.75rem!important;margin-top:0!important;margin-bottom:1.25em!important}.children .nextra-callout{background:none!important;color:#dcdcdc!important;font-size:14px}.children .nextra-callout p{margin:0!important}.children h2{font-size:26px!important;margin-top:3.5rem!important;margin-bottom:1rem!important;padding-bottom:1rem!important}.children h3{font-size:18px!important;margin-top:1.5em!important;margin-bottom:.5em!important;line-height:1.6!important}.children h4{font-size:16px!important;margin-bottom:.5em!important}'}),t]}),n&&(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)("img",{referrerPolicy:"no-referrer-when-downgrade",src:"https://static.scarf.sh/a.png?x-pxid=8167f508-ea32-4021-a0ac-42db3c691850"}),(0,a.jsx)(c.qZ,{anon_key:g.Tr,style:{darkMode:!0,accentColor:"#50FA7B"},floatingButtonStyle:m})]})]})},gitTimestamp:null,project:{link:"https://github.com/hyperdxio/hyperdx"},chat:{link:"https://discord.gg/FErRRKU78j"}}},83021:function(){}},function(e){e.O(0,[4833,9097,6577,5072,9774,2888,179],(function(){return t=27019,e(e.s=t);var t}));var t=e.O();_N_E=t}]); 2//#
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.