LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

Why is "what should we log?" never answerable as a fixed list?

Because logging is always embedded in a context: the goals decide what is worth recording, and the goals differ per source, per consumer and per compliance regime.

Start from the purpose — why are we logging at all? — and every other decision follows from it. The dimensions that the purpose drives:

  • Data and information sources — a firewall, a database and a Kubernetes cluster have different things worth saying, and say them differently.
  • Collection method, formats and storage — how the data is picked up, in what shape, and where it lands.
  • Filtering and normalisation — reducing the volume and unifying field names so entries from different sources can be compared at all.
  • Correlation and analytics — what you intend to join together later; if you never capture a shared key, you cannot correlate afterwards.
  • The consumer — a SIEM (Security Information and Event Management platform), a developer debugging, and an auditor proving compliance each need different fields retained for different lengths of time.

The practical consequence: a logging configuration copied from another organisation is almost always wrong, because it encodes their goals. Decide the questions you need to answer first, then work backwards to what must be recorded to answer them.

Go deeper:

From Quiz: ITIA / IT Infrastructure Monitoring: Logging, Monitoring and Observability | Updated: Sep 17, 2026