What kind of information does logging actually capture?
Discrete records of things that happened in an IT environment: activities, events, parameters and operating states, each anchored to a point in time.
The defining word is discrete. A log entry is a fact about a moment — a user logged in, a service threw an exception, a configuration value was changed, a batch job finished. That is a different shape of data from a metric, which is a continuous series of measurements sampled over time.
What gets written down falls into a few families:
- Activities — who or what did something (a login, an API call, a file access).
- Events — something happened to the system (a crash, a failover, a certificate expiry).
- Parameters — the values in play at that moment (which config, which version, which input).
- Operating states / status — the condition a component reported (service started, degraded, stopped).
Because each entry stands alone, logs are the strongest evidence you have about the past — which is why they carry the audit, forensic and security use cases that metrics cannot serve. Their weakness is the flip side: without deliberate structure and correlation, a pile of independent facts is just a pile.
Go deeper:
Logging (computing) — Wikipedia — event logs, transaction logs and message logs, and what each records.