The logs, as they are written
The newest lines from five services. All of them go into the file on site.
Templates learned
Each kind of line becomes a template, with <*> where lines differ. New ones appear at the top.
| # | Service | Level | Lines | Template |
|---|
The dashboard, drawn from what was sent
Six panels, read from the answers that went upstream each minute. Each panel checks every point against a recount of the raw lines.
Alerts sent upstream
A new kind of WARN or ERROR line goes upstream at the next checkpoint, five seconds at most.
What happened
Newest first.
What it costs at Datadog's list prices
The same month of logs sent two ways, at the rate so far. Change the prices to yours.
| GB a month | Events a month | Cost a month |
|---|
List prices checked on 29 September 2026: $0.10 per GB ingested and $1.70 per million log events indexed with 15-day retention, billed annually (datadoghq.com/pricing). Everything sent upstream is counted as log events at the same prices.
Search the logs kept on site
Every line stays in the file for 48 hours, whatever went upstream.
Type a word, such as northpay or 503, and press Search.
The dashboard and its policy
The importer reads the dashboard and writes the policy: one stream from logs per panel, plus every line kept and errors kept whole.
Change the dashboard, then import it with the same Go program that runs the reducer here. The running demo keeps its own policy.
Results
Finishing the two hours at full speed, then checking every panel.
Every panel, checked
What upstream drew from what it was sent, against a recount of the raw lines by separate code that never reads the file.
What is in the file
Ask the file
The reducer's file is plain SQLite: the lines kept on site, the templates and every panel's windows. Pick a question or write your own, then press Run (or Ctrl+Enter, ⌘+Enter on a Mac). It reads while the run is paused or finished.