Ten terabytes of logs an hour from host agents through Kafka into tiered OpenSearch and S3, with regex search, live tail and exceptions grouped into issues.
Infrastructure, platform and reliability engineers.
Your approach: Use diagrams or prose to explain responsibilities, state, capacity and failure behavior. Show the calculations requested by the question.
Design a Distributed Logging and Error Tracking System. Ten terabytes of logs an hour from host agents through Kafka into tiered OpenSearch and S3, with regex search, live tail and exceptions grouped into issues. Work from the scoping questions below. State assumptions for any unspecified load, guarantee or target, then trace your design end to end. Explain one difficult case and a credible alternative; the worked example is a reference, not a required implementation.
Resolve the scoping questions for a Distributed Logging and Error Tracking System. Separate stated behavior from assumptions, and identify what is outside your design.
Declare relevant volume, latency, freshness, quality or cost targets with units. Show calculations or an evaluation plan that can test them; unspecified targets are your assumptions, not hidden pass criteria.
Explain how your guarantees hold in a difficult case relevant to this subject. Address: Error tracking? Who pays?
Identify users, required behavior and exclusions. Answer: Volume? What must be fast?
Define the information owned by the system and the inputs, outputs and errors at its boundaries. Resolve: Regex? How real-time?
Estimate the dominant workload and resource demand with units and explicit assumptions. For a learned system, also state how quality is measured and what data is available.
Draw or describe the responsibilities needed for a Distributed Logging and Error Tracking System. Trace a representative request, event or job from its input to a visible result; identify durable state owners.
Walk through a difficult case step by step, including detection and recovery. Consider: How long? Exactly-once? Error tracking? Who pays?
Compare a credible alternative using your chosen workload and guarantees. Explain a remaining risk, a signal to watch and when you would change the design.