Whenever we write any kind of event into our logging system (which at its core is simply a run-of-the-mill ELK stack setup), four attributes are added:
- the userId (if an authenticated user session is active)
- the sessionId (this always exists, authenticated user or not)
- the requestId (nginx as the first point of contact generates this one)
- the clientId (when we see this browser for the very first time, we generate this and store it in a really-long-lived cookie)
I have yet to see a measure with a better cost-benefit ratio.
Hunting down a bug always starts with seeing an error event — and this event has all 4 attributes (userId might be NULL of course).
Want to find all other events related to the same session? Search Kibana for the sessionId. All events from the same HTTP request? Search for the requestId. Same client? clientId. Same user? userId.
In some cases it nearly feels like cheating.