Log Analysis and Diagnostic Data Gathering Questions

Extracting signal from existing logs and diagnostic output to find a root cause: parsing and querying log data, correlating traces and metrics during an investigation, and gathering the right diagnostic information (including asking clarifying questions) before drawing conclusions. Covers text-processing and query techniques for locating evidence in logs (structured log parsing, ElasticSearch/SQL-style log queries, log aggregation and retention trade-offs) and reconstructing a timeline from the data on hand. This is the analysis-of-existing-data skill used during troubleshooting and investigation across infrastructure and operations roles: distinct from monitoring and observability, which is about instrumenting a system so telemetry exists in the first place (see the observability topics for that), and distinct from SIEM-based security detection and formal digital-forensics practice (chain of custody, artifact/disk/memory analysis), which have their own dedicated coverage elsewhere in the catalog.

EasyTechnical
31 practiced

Explain common logging severity levels (debug, info, notice, warning, error, critical/crit, alert, emergency) and how they map to syslog numeric priorities / priority names. Discuss production strategies for controlling volume (rate-limiting, sampling) of debug-level logs without losing context needed for post-incident analysis.

HardTechnical
32 practiced

You are given the following snippet from production logs and traces. Analyze the events and identify the most likely root cause and the immediate mitigation steps you would take. Logs:

2025-11-10T10:02:15.101Z service-A trace=abc123 request=R1 status=200 latency_ms=120
2025-11-10T10:02:15.201Z service-B trace=abc123 request=R1 status=500 error="DB timeout"
2025-11-10T10:02:15.301Z service-A trace=abc123 request=R1 status=200 retry=1
2025-11-10T10:02:16.000Z service-C trace=def456 request=R2 status=503

Provide a reasoned RCA hypothesis and at least three concrete verification steps and mitigations.

MediumTechnical
34 practiced

Write a robust regular expression or short code snippet that matches both IPv4 and IPv6 addresses in arbitrary log lines. Include normalization behavior for IPv6 (zero-compression) and handle edge cases where ports are appended (e.g., '2001:db8::1:443' or '192.0.2.1:8080'). Explain common pitfalls with naive regexes and how to validate extracted addresses.

EasyTechnical
42 practiced

A team wants to move from per-host log files to a centralized logging system. Walk through the benefits and risks of that move (reliability, latency, privacy and compliance, single points of failure) and how you'd decide whether centralizing actually meets this team's requirements rather than adding risk they don't need.

EasyTechnical
32 practiced

On a typical Linux system, where are system and application logs stored by default and what are the differences between text-based files under /var/log and the systemd journal? Include example commands to:

  • View the last 100 lines of a file-based log
  • Show logs for a specific systemd unit since yesterday
  • Follow a log file in real time

Explain when one source may contain entries the other does not and the implications for incident response.

Unlock Full Question Bank

Get access to all 27 Log Analysis and Diagnostic Data Gathering interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.