Skip to main content
A Firebolt Engine writes one log record per line. Set logging.format in the Engine YAML configuration to select the field names and structure expected by your log collector:
The format applies to every configured sink. Log records can include a query ID, request ID, query label, component, thread information, source location, region, Instance ID, and active trace context when those values are available.

Formats

Changing the format changes field names and nesting. Update queries, parsing rules, and alert rules that read the previous format before changing logging.format.

Firebolt JSON

The json format uses Firebolt’s own schema:
Empty values remain present in this format. thread_id and source_line are JSON strings.

OpenTelemetry

The otel format projects each record onto the OpenTelemetry Log Data Model. It uses timestamp, severityText, severityNumber, body, traceId, spanId, traceFlags, resource, scope, and attributes. Attribute names follow OpenTelemetry semantic conventions where a convention exists, including thread.id, thread.name, code.file.path, code.line.number, cloud.region, and service.instance.id. Firebolt correlation fields use the firebolt.* namespace. This format is JSON Lines for a console or file collector. Send logs to an OTLP endpoint through an OpenTelemetry Collector or another OTLP exporter; an OTLP endpoint expects a batched OTLP envelope, not individual JSON log records.

Google Cloud

The google_cloud format uses time, severity, and message. It writes source and trace context to these Google Cloud fields when available:
  • logging.googleapis.com/sourceLocation
  • logging.googleapis.com/trace
  • logging.googleapis.com/spanId
  • logging.googleapis.com/trace_sampled
Google Cloud moves these fields into the corresponding LogEntry fields during ingestion. Other Firebolt fields remain in the JSON payload. See Structured logging in the Google Cloud documentation.

Amazon CloudWatch

The aws_cloudwatch format is flat JSON so CloudWatch Logs Insights can discover every field. It uses severityText, severityNumber, traceId, and spanId, which also match OpenTelemetry field names. CloudWatch assigns the log event timestamp during transport; the JSON timestamp field is available for queries but does not replace CloudWatch’s generated @timestamp field. See Supported logs and discovered fields in the CloudWatch Logs documentation.

Azure Monitor

The azure_monitor format writes flat JSON with timestamp, level, and message. Azure Monitor Container Insights uses a top-level level value from a valid JSON log message to populate the LogLevel column in ContainerLogV2. Other fields remain in the dynamic LogMessage value. See Configure the ContainerLogV2 schema in the Azure Monitor documentation.

Trace correlation

The structured formats emit trace fields only when a valid OpenTelemetry span is active on the logging thread. Enabling a structured format does not enable tracing. Configure OpenTelemetry tracing separately with the otel configuration block.