Reading logs, errors and timestamps as evidence
Use logs and error messages as evidence: line up times across time zones, read HTTP status codes and severity levels correctly, follow one request through the log, find the first error rather than the loudest, and share log extracts without leaking secrets.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Convert timestamps between UTC and a local offset and line up events from different sources
- Interpret common HTTP status code classes and codes (401, 403, 404, 429, 500, 502, 503, 504)
- Use syslog severity levels and request or correlation IDs to filter a log
- Identify the first meaningful error in a sequence rather than its knock-on effects
- Redact passwords, tokens and unnecessary personal data before sharing a log extract
Course outline
- 1.Logs and timestamps as evidenceVideo · 3 min
- 2.Time: the thread that joins the evidenceLesson · 15 min
- 3.Reading error messages and status codesLesson · 17 min
- 4.Working through a logLesson · 16 min
- 5.Reading logs, errors and timestamps as evidence: knowledge checkKnowledge check · 17 questions
- 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- IETF RFC 3339: Date and Time on the Internet: Timestamps (Z and numeric UTC offsets)
- IETF RFC 5424: The Syslog Protocol (severity levels 0-7, timestamps)
- IETF RFC 9110: HTTP Semantics (section 15, status codes)
- IETF RFC 6585: Additional HTTP Status Codes (429 Too Many Requests)
- General technical-support practice
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.