Logging Design Pattern, one log per client vs querying cetralized log

Viewed 84

I'm trying to choose between two patterns or maybe even another one that I have yet to consider for handling logging in my application.

I have a nodejs express server serving clients in an auto scaling group.

The goal is to ideally be able to see each user's activity very easily so that I can trouble shoot in production.

Approach 1, centralized logging using ELK to query based on certain json fields such as customerId requestId etc.

Approach 2, create a log filer per customer and query each file as needed.

In both approaches, log files will be rotated.

Creating a log file per customer just doesn't feel right to me especially when considering the scenarios of having millions of customers but in terms of performance...

  1. query 1 million files based on customer ID then subsequently query a much smaller file for the information you need

OR

  1. query centralized log file filtering results based on customerID etc.

Is one approach significantly better in performance than the other? What is the best practice in the industry at the moment for this scenario and is there a better approach to consider?

Lastly AWS Services seem to charge based on file size that you are querying. As such would one approach be more cost effective than the other?

0 Answers
Related