Concept and mechanism
Metrics with similar filters can measure different populations. A project-level user-defined metric evaluates received logs matching its filter independently of sink exclusions. A bucket metric uses logs stored in that bucket. Do not automatically add both: they can overlap. A metric created now also does not retroactively create points for all older logs. A gap before creation does not mean zero errors. Before discussing values, write down scope, window, filter, and collection stage. This discipline distinguishes real regression, population change, and failure in instrumentation itself. Retain evidence of when configuration changed.
Guided application
In a fictional application, every request_id became a label and series count rose almost per request. Each value combination distinguishes a series; replacing the ID with a unique hash retains the problem. Use bounded dimensions for aggregation and keep individual identity in appropriate logs or traces with defined classification and access. When investigating latency, interpret nesting: a 900 ms parent span including a 780 ms call does not imply a 1680 ms total. Look for critical path, concurrency, and propagated context. For low-traffic alerts, an isolated percentage can vary greatly from a single request. Combine volume understanding, synthetic tests, and outcome signals without treating absence of traffic as automatic proof of health.
A chart without points at 10:00 can mean the metric was only created at 14:00.
Common pitfalls
Equal filters as equal populations; hash as low cardinality; span sum as duration; gap as zero.
Related topics: Organization, identity, and visibility · Infrastructure, revisions, and environments · Pipelines, promotion, and recovery
Explain population and semantics before interpreting the number.
Reference: Logs-based metrics · Current linked guide; edition date unconfirmed (2026-09-30 inspection)