What are the three pillars of observability and what question does each answer?
basicMetrics tell you that something is wrong and how much (aggregated numbers over time), logs tell you what happened for a specific event (discrete records), and traces tell you where time went across services for one request.
- Metrics are cheap and good for alerting; high-cardinality detail is expensive.
- Logs are detailed but costly to search at scale.
- Traces connect services; they need propagation of context across every hop.
- Monitoring answers known questions (dashboards/alerts); observability lets you ask new questions of telemetry.
- Can logs replace metrics? Deriving metrics from logs is costly, slower and fragile.
- Is a trace the same as a log with a request ID? No, a trace has structured parent/child spans with timing.