Skip to content

Logging and Observability

Source of truth: internal/logging/logging.go, internal/middleware/middleware.go, installer scripts. The Go process always writes slog to os.Stdout. There is no application file logger.

Application logger

Setting Default Effect
LOG_FORMAT json JSON slog; only text switches to text
LOG_LEVEL debug debug / info / warn / error

Always-on fields from logging.New: service, environment, instance_id, version.

Go slog.JSONHandler also emits time, level, msg.

Where logs go

Runtime Destination
Console serve Process stdout
Windows Native Process stdout (SCM typically discards it). Installer file: C:\IQVizyon\IQVIntegrationAPI\logs\installer-update.log. Event Log source is registered; application slog is not written there.
Linux Native systemd journal (journalctl -u iqv-integration-api.service). /var/log/iqvizyon/iqv-integration-api is a unit ReadWritePaths directory, not an application log file sink.
Docker Container stdout/stderr → Docker json-file (max-size: 10m, max-file: 5)

```bash

Linux native

sudo journalctl -u iqv-integration-api.service -f

Docker

docker logs -f docker compose logs -f ```

request_id

  • Header: X-Request-ID (internal/requestid)
  • Missing/invalid → new UUID
  • Echoed on the response and stored in the JSON envelope as request_id
  • Access logs include request_id

Access log fields

middleware.RequestLogger: timestamp, request_id, method, path, status_code, duration_ms, remote_ip, user_agent, message.

Panic recover adds panic, stack. HTTP start/stop may log addr, tls_mode.

Collecting logs for troubleshooting

  1. Capture /health/live and /health/ready responses (no secrets).
  2. Collect installer/update logs (Windows installer-update.log; Linux script stdout).
  3. Collect application stdout/journal/docker logs for the same request_id.
  4. Collect deployment.json / Linux deployment metadata (no secrets).
  5. Do not attach .env, Mongo URIs, tokens, or raw request bodies.

Never log

  • Authorization headers
  • Client secrets / JWT secrets
  • Access tokens / passwords / private keys
  • Unredacted MongoDB URIs
  • Full sensitive request bodies
  • Integration actor ObjectIDs

Config.RedactedMap() redacts mongodb_uri and health-push bearer tokens and exposes only integration_actor_configured (boolean).