🪺Structured JSON Log Format Guide

Pick fields to get one JSON record and its bytes

No field-name set is presented as the right answer. Widely used conventions such as ECS and OpenTelemetry exist, and their names differ. Pick the fields you want and the tool builds one record and its byte size.

recs

You Might Also Need

How big one record gets once you pick the fields

Structured logging stores keys and values instead of a human sentence so the records can be searched and aggregated. Tick the base fields, add your own, and the tool builds the single-line JSON your collector ingests plus a readable form, then reports the UTF-8 bytes of one record and the volume per day and over 30 days. It also shows the share the field names alone take.

There is no single field-name standard. The Elastic Common Schema and the OpenTelemetry semantic conventions are both widely used and their names differ, so this tool presents neither as correct and only rewrites your names as snake_case, camelCase or dot notation. The timestamp can be an RFC 3339 string or epoch milliseconds, as of October 2026.

The volume is an estimate based on your example values. Real value lengths, metadata the pipeline adds, compression and index size are not included. Keep personal data and secrets out of the fields. Nested objects and arrays are not supported, and a duplicate field name is reported as an error.

Frequently Asked Questions

Which field-name standard should I follow?

There is no single standard. The Elastic Common Schema and the OpenTelemetry semantic conventions are both common and their names differ, so picking one and staying consistent inside your team helps searching more than the choice itself.

Why add a correlation id?

When one request crosses several services its logs scatter. Putting the same id on every line for that request lets you group them and replay the flow, which cuts investigation time sharply.

Does the calculated volume match what gets stored?

No. It is an estimate from your example values and leaves out metadata the pipeline adds, compression and search index size. Use it to compare how much adding a field costs.