🔊Log Level Choice Guide

Lines per level to volume and what a higher level drops

No recommended share per level is offered, because no authority publishes one. Enter the volume you log today and the tool reports the mix and what raising the minimum level removes.

lines
lines
lines
lines
lines
byte
LevelBelongs hereDoes not belong here
ERRORWork that failed and needs a person: a write that did not land, an outbound call that failed after retries.Rejecting bad input with a 400, which is part of normal flow.
WARNSomething that passed now but will bite later: success after retries, a deprecated call, a threshold nearly reached.Events with nobody to act and nothing to act on.
INFOState changes worth keeping in production: start and stop, config applied, a batch beginning and ending.Per-request detail or anything inside a hot loop.
DEBUGDetail you switch on while chasing a problem: branch conditions, intermediate values, query parameters.Personal data and secrets. They stay out at every level.
TRACETracing finer than DEBUG: one line per iteration, byte level flow.Always-on collection. This is the level that grows volume fastest.

You Might Also Need

What disappears when you raise the level

ERROR, WARN, INFO, DEBUG and TRACE are a convention shared by logging libraries rather than a specification. On the syslog side RFC 5424 defines eight severities, so even the number of steps differs. This tool therefore offers no recommended share per level and instead lays out what belongs at each level and what does not.

What it does calculate is volume. Enter the lines each level writes per day and the average size of one line, and you get the mix, the daily volume, and the lines kept, dropped and removed as a share once the minimum level moves. Volume uses 1 MiB as 1,048,576 bytes, as of October 2026.

The counts are a plain sum of what you type. Sampling, compression and duplicate ingestion in the collection pipeline are not modelled, and no log file is read. Raising a level also has to leave enough behind for an investigation later, so do not decide on the numbers alone. Personal data and secrets belong at no level at all.

Frequently Asked Questions

What share should each level take?

There is no authoritative share, because it depends on the service and its traffic. The tool therefore recommends nothing and only reports the mix of what you log today and how much raising the level removes.

How do I split WARN from ERROR?

By whether a person has to act. Work that failed and needs attention is ERROR, while a signal that passed now but will bite later is WARN. If nobody has anything to act on, it is neither.

Can I run DEBUG in production?

Check its share in the table first, because it grows volume quickly. Turning it on for a while to chase a problem can still be reasonable. At any level, personal data and secrets stay out.