Chapter 14: Logging and Light Observability
14.12 Lab — generate, query, write the note
Lab
Practise the CloudWatch Logs primary path (or stdout + documented ship step if your account setup blocks agents today — still write the incident note).
- Run badge API hello API (or any tiny app) that writes an ERROR line on a deliberate bad request.
- Capture logs with
docker logsand (when available) ship/query via CloudWatch Logs in your lab account. - Create or use a clearly named lab log group; confirm events appear.
- Query/filter the last ERROR; copy one line.
- Write a five-line incident note (When, Symptom, Evidence, Action, Follow-up) in your notebook or private README — no real secrets, no customer PII.
- Add one sentence on how a correlation id would make the search easier.
- Optional interview prep: three bullets comparing CloudWatch Logs vs ELK at idea level (store, search, ops ownership) — no invented product limits.
Practice task
Redact this bad log line into a safe version:
ERROR user=priya token=AKIAexample secret=hunter2 order=55 failed
(Use obviously fake placeholders only — never paste real credentials into notes you might commit.)
Thodkyaat sangaycha tar
- Logs are CCTV: metrics detect; logs explain.
- Containers: prefer stdout/stderr; use
docker logs/ Compose logs. - journald + logrotate keep hosts healthy; link AWS Linux chapters for depth.
- Primary path: CloudWatch Logs (groups/streams/search); ELK is the common alternate idea — do not dual-build both in this lab.
- Correlation ids tie one request across lines; never log secrets.
- Close incidents with a short note: when, symptom, evidence, action, follow-up.
Samajla ka? Nasel tar lab (14.12) ERROR line + five-line incident note paryant sodu naka – secrets log madhe nahi. Aata pudhe jaauya Kubernetes intro kade.