logging.format in the Engine YAML
configuration to select the field names and structure expected by your log collector:
Formats
Changing the format changes field names and nesting. Update queries, parsing rules, and alert rules
that read the previous format before changing
logging.format.
Firebolt JSON
Thejson format uses Firebolt’s own schema:
thread_id and source_line are JSON strings.
OpenTelemetry
Theotel format projects each record onto the OpenTelemetry Log Data Model. It uses timestamp,
severityText, severityNumber, body, traceId, spanId, traceFlags, resource, scope, and
attributes. Attribute names follow OpenTelemetry semantic conventions where a convention exists,
including thread.id, thread.name, code.file.path, code.line.number, cloud.region, and
service.instance.id. Firebolt correlation fields use the firebolt.* namespace.
This format is JSON Lines for a console or file collector. Send logs to an OTLP endpoint through an
OpenTelemetry Collector or another OTLP exporter; an OTLP endpoint expects a batched OTLP envelope,
not individual JSON log records.
Google Cloud
Thegoogle_cloud format uses time, severity, and message. It writes source and trace context
to these Google Cloud fields when available:
logging.googleapis.com/sourceLocationlogging.googleapis.com/tracelogging.googleapis.com/spanIdlogging.googleapis.com/trace_sampled
LogEntry fields during ingestion. Other
Firebolt fields remain in the JSON payload. See Structured logging
in the Google Cloud documentation.
Amazon CloudWatch
Theaws_cloudwatch format is flat JSON so CloudWatch Logs Insights can discover every field. It
uses severityText, severityNumber, traceId, and spanId, which also match OpenTelemetry field
names. CloudWatch assigns the log event timestamp during transport; the JSON timestamp field is
available for queries but does not replace CloudWatch’s generated @timestamp field.
See Supported logs and discovered fields
in the CloudWatch Logs documentation.
Azure Monitor
Theazure_monitor format writes flat JSON with timestamp, level, and message. Azure Monitor
Container Insights uses a top-level level value from a valid JSON log message to populate the
LogLevel column in ContainerLogV2. Other fields remain in the dynamic LogMessage value.
See Configure the ContainerLogV2 schema
in the Azure Monitor documentation.
Trace correlation
The structured formats emit trace fields only when a valid OpenTelemetry span is active on the logging thread. Enabling a structured format does not enable tracing. Configure OpenTelemetry tracing separately with theotel configuration block.