What disappears when you raise the level
ERROR, WARN, INFO, DEBUG and TRACE are a convention shared by logging libraries rather than a specification. On the syslog side RFC 5424 defines eight severities, so even the number of steps differs. This tool therefore offers no recommended share per level and instead lays out what belongs at each level and what does not.
What it does calculate is volume. Enter the lines each level writes per day and the average size of one line, and you get the mix, the daily volume, and the lines kept, dropped and removed as a share once the minimum level moves. Volume uses 1 MiB as 1,048,576 bytes, as of October 2026.
The counts are a plain sum of what you type. Sampling, compression and duplicate ingestion in the collection pipeline are not modelled, and no log file is read. Raising a level also has to leave enough behind for an investigation later, so do not decide on the numbers alone. Personal data and secrets belong at no level at all.
Frequently Asked Questions
There is no authoritative share, because it depends on the service and its traffic. The tool therefore recommends nothing and only reports the mix of what you log today and how much raising the level removes.
By whether a person has to act. Work that failed and needs attention is ERROR, while a signal that passed now but will bite later is WARN. If nobody has anything to act on, it is neither.
Check its share in the table first, because it grows volume quickly. Turning it on for a while to chase a problem can still be reasonable. At any level, personal data and secrets stay out.