{
  "id": 11798303,
  "title": "Observability Explained: Logs, Metrics, Traces, and What Monitoring Misses",
  "url": "https://urgent.news/2026/10/03/observability-explained-logs-metrics-traces-and-what-monitoring-misses",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T23:52:59.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/safesploit/observability-explained-logs-metrics-traces-and-what-monitoring-misses-3l61"
  },
  "original_language": "en",
  "account": "Observability is a powerful method for understanding the inner workings of modern systems. While traditional monitoring can confirm if a server is running and if the application is returning a \"200 OK\" status, it cannot always explain why the system behaves in unexpected ways. Observability fills this gap by providing insights into what is happening inside a system based on the telemetry it generates.\n\nThe three traditional pillars of observability are logs, metrics, and traces. Events, while not always emphasized, are also becoming increasingly important in observability. Let's take a closer look at each of these pillars.\n\nLogs provide valuable information about what happened in a system. They are generated by applications, operating systems, network devices, security tools, and various services. Examples include nginx access logs, PHP error logs, MariaDB logs, and Kubernetes container logs. Logs can give us detailed information about specific events, such as authentication issues or slow queries.\n\nMetrics represent numerical measurements that change over time. Common examples include CPU and memory usage, HTTP request rates, and error rates. Metrics are excellent for creating dashboards, setting up alerts, planning capacity, and analyzing trends. They help us understand how much, how often, and how fast things are happening. However, metrics alone often don't tell us the \"why\" behind the changes.\n\nTraces follow a request as it moves through various components of a system. Imagine a user request to \"/users\" that goes through Nginx, PHP, MariaDB, and other services. A distributed trace would show the time spent at each stage, helping us identify where the delays are occurring. Tracing is especially valuable in distributed systems where a single request might involve multiple components.\n\nEvents represent meaningful changes that occur at a specific moment. Examples include application deployments, database latency increases, Kubernetes pod restarts, and security modifications. These events can provide crucial context during incident investigation, helping us determine what changed when application performance issues arise.\n\nIn summary, observability is essential for understanding the behavior of modern systems. By combining logs, metrics, traces, and events, we can gain a deeper understanding of what is happening inside a system, even when traditional monitoring approaches fall short. Monitoring remains important, but observability provides the context needed to investigate and resolve complex issues.",
  "summary": "📡 1. The Three Observability Pillars (and the \"Fourth\") 1️⃣ Logs — What happened? 2️⃣ Metrics — How much, how often, and how fast? 3️⃣ Traces — Where did the request go? 4️⃣ Events (the unofficial pillar) — What changed? What about profiles? 2. Monitoring, Security, and Observability 🖥️ Infrastructure monitoring 📈 Application monitoring 🔐 Security monitoring 3. Following a Request Through a…",
  "key_points": [
    "Logs provide detailed information about specific events in a system",
    "Metrics represent numerical measurements changing over time",
    "Traces follow a request through various system components"
  ],
  "editors_take": "The emphasis on observability marks a shift from merely tracking system performance to gaining a deeper understanding of internal system workings, enabling more effective investigation and resolution of complex issues.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}