Structured loggingeasy0-2 years

`grep "order 1041" app.log` returns lines about order 1041 and also lines about order 10412. Why, and how does switching to structured JSON logs fix it — not just "make it searchable", but mechanically?

grep matches a sequence of characters anywhere in a line, and "order 1041" is a literal substring of "order 10412" — grep has no concept of "1041" as a distinct value with boundaries, only as text that either appears or doesn't. A structured JSON log line puts the order id in its own field, "orderId":1041, as a genuine value rather than a phrase embedded in a sentence, so a query tool like jq can ask select(.orderId == 1041) — an equality check on a typed field — instead of a substring search on free text. jq's comparison is exact: 1041 equals 1041 and not 10412, because it's comparing two numbers, not scanning characters.

The lesson behind it →
More on Structured logging