Log Analysis and Diagnostic Data Gathering Questions

Extracting signal from existing logs and diagnostic output to find a root cause: parsing and querying log data, correlating traces and metrics during an investigation, and gathering the right diagnostic information (including asking clarifying questions) before drawing conclusions. Covers text-processing and query techniques for locating evidence in logs (structured log parsing, ElasticSearch/SQL-style log queries, log aggregation and retention trade-offs) and reconstructing a timeline from the data on hand. This is the analysis-of-existing-data skill used during troubleshooting and investigation across infrastructure and operations roles: distinct from monitoring and observability, which is about instrumenting a system so telemetry exists in the first place (see the observability topics for that), and distinct from SIEM-based security detection and formal digital-forensics practice (chain of custody, artifact/disk/memory analysis), which have their own dedicated coverage elsewhere in the catalog.

MediumTechnical
28 practiced

Implement a robust function (in Python or Go) that parses timestamps found in logs which may appear as any of:

  • 10/Oct/2024:13:55:36 -0700
  • 2024-10-09T11:23:45Z
  • 1700000000 (epoch seconds)

The function should normalize all to UTC ISO8601 strings, handle timezone offsets, and return a clear error for invalid formats. Describe your approach and show key code or algorithmic steps.

MediumTechnical
36 practiced

During an incident retro, you go looking for the application log from four days ago and it's gone; only the last couple of days of rotated files still exist. Walk through how you'd figure out whether that's expected retention behavior or a rotation misconfiguration, and what you'd check or change so it doesn't bite the next investigation.

MediumTechnical
38 practiced

Write a Logstash/ELK grok pattern (or equivalent) for Nginx 'combined' access logs to extract client_ip, timestamp, method, path, protocol, status, bytes_sent, and user_agent. Explain how you'd handle query strings in path, percent-encoding, and very long user-agent strings to avoid mapping explosion in Elasticsearch.

MediumTechnical
30 practiced

Coding task in Python: build a memory-efficient utility that reads multiple large newline-delimited JSON log files and extracts, in chronological order, all events that have a given request_id between two timestamps. The function signature should be extract_events(file_paths, request_id, start_ts, end_ts) and must stream files without loading them entirely into memory. Describe edge cases you would handle in production.

EasyTechnical
37 practiced

Given a sample Apache access log line formatted without quotes:

127.0.0.1 - frank [10/Oct/2024:13:55:36 -0700] GET /index.html HTTP/1.1 200 2326

Write a single PCRE regular expression to extract the following named groups: client_ip, user, timestamp, method, path, protocol, status, bytes. Show how you'd run grep -P or awk to capture these fields and mention timestamp parsing caveats (timezones, format).

Unlock Full Question Bank

Get access to all 28 Log Analysis and Diagnostic Data Gathering interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.