<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>scryops — observability decoded</title><link>https://scryops.dev/</link><description>An independent publication on modern observability engineering. Trends, deep dives, how-tos, and open questions.</description><language>en</language><image><url>https://scryops.dev/feed-icon.png</url><title>scryops — observability decoded</title><link>https://scryops.dev/</link><width>144</width><height>144</height></image><lastBuildDate>Sat, 03 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://scryops.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>The Alert Body Template</title><link>https://scryops.dev/alert-body-template/</link><guid>https://scryops.dev/alert-body-template/</guid><pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate><description>A copy-paste alert body that answers four questions before the on-call has to ask: what's broken, how fast it's getting worse, what's already been checked, and the first three steps.</description><category>Alerting</category><category>On-Call</category><category>SLOs</category><category>Prometheus</category><category>How-to</category></item><item><title>OpenTelemetry: What It Is and How It Fits Together</title><link>https://scryops.dev/guides/opentelemetry-overview/</link><guid>https://scryops.dev/guides/opentelemetry-overview/</guid><pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate><description>OpenTelemetry is a single instrumentation layer that produces traces, metrics, and logs in a vendor-neutral format. This guide explains what each signal is for, how the SDK and Collector relate, and where to go next.</description><category>OpenTelemetry</category><category>Observability</category><category>Tracing</category><category>Metrics</category><category>Logs</category></item><item><title>Writing Runbooks That Work at 3am</title><link>https://scryops.dev/guides/runbook-authoring/</link><guid>https://scryops.dev/guides/runbook-authoring/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A runbook that's hard to follow under pressure isn't a runbook. It's a liability. Here's the anatomy of one that actually shortens incident response, and how to keep it true.</description><category>On-Call</category><category>Alerting</category><category>SLOs</category><category>Reliability</category><category>Operations</category><category>Best Practices</category></item><item><title>Why are my structured logs still unstructured strings?</title><link>https://scryops.dev/qa/structured-logging-antipatterns/</link><guid>https://scryops.dev/qa/structured-logging-antipatterns/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Three patterns that look like structured logging but aren't, in C#, Java, Go and Python, and what to write instead.</description><category>Logs</category><category>Structured Logging</category><category>Best Practices</category></item><item><title>What's the real difference between profiling and tracing?</title><link>https://scryops.dev/qa/profiling-vs-tracing/</link><guid>https://scryops.dev/qa/profiling-vs-tracing/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Tracing tells you which path a request took and how long each hop took. Profiling tells you what your CPU was actually doing during those hops. They're complementary — use both.</description><category>Profiling</category><category>Tracing</category></item><item><title>What is an SLI and how do you choose one?</title><link>https://scryops.dev/qa/what-is-an-sli/</link><guid>https://scryops.dev/qa/what-is-an-sli/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>An SLI is a quantitative measure of service behaviour from the user's perspective. Choose the metric that, when it degrades, users notice — not server-side proxies that feel measurable but don't map to user experience.</description><category>SLOs</category><category>Reliability</category><category>Observability</category></item><item><title>Telemetry Data Sovereignty: Where Your Data Lives Matters</title><link>https://scryops.dev/guides/data-sovereignty-and-residency/</link><guid>https://scryops.dev/guides/data-sovereignty-and-residency/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A system that spans continents produces telemetry that spans legal jurisdictions. Here's how to keep traces and logs where the law wants them, and still see your whole system.</description><category>Compliance</category><category>Privacy</category><category>GDPR</category><category>Multi-Cloud</category><category>OpenTelemetry</category><category>Collector</category><category>Observability</category></item><item><title>Structured Logging: Teaching Machines to Read</title><link>https://scryops.dev/guides/structured-logging-machine-readable/</link><guid>https://scryops.dev/guides/structured-logging-machine-readable/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Logs were designed for humans grepping text files at 2am. Now they also have to feed query engines, correlation and anomaly detection. Here's what that changes about what you write, and which field names to use.</description><category>Logs</category><category>OpenTelemetry</category><category>Structured Logging</category><category>AI</category><category>Observability</category></item><item><title>On-Call Procedures: From Page to Postmortem</title><link>https://scryops.dev/guides/on-call-procedures/</link><guid>https://scryops.dev/guides/on-call-procedures/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A page is just the starting gun. What happens between the alert firing and the postmortem closing determines whether your team gets better or just gets tired.</description><category>On-Call</category><category>Alerting</category><category>Reliability</category><category>Observability</category><category>Operations</category></item><item><title>Logging Foundations</title><link>https://scryops.dev/guides/logging-foundations/</link><guid>https://scryops.dev/guides/logging-foundations/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>What logging is for, how it fits next to metrics and traces, and what to log, where and how. The mental model to have before touching a logging framework, and the starting point for the rest of the logging guides.</description><category>Logs</category><category>Observability</category><category>OpenTelemetry</category></item><item><title>Log Levels: When to Whisper, Speak, or Shout</title><link>https://scryops.dev/guides/log-levels-and-severity/</link><guid>https://scryops.dev/guides/log-levels-and-severity/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Log levels are the emotional register of your system's voice. How to use ERROR, WARN, INFO, DEBUG and TRACE consistently, how they map onto OpenTelemetry's severity numbers, and what each one costs you.</description><category>Logs</category><category>Observability</category><category>Best Practices</category></item><item><title>Is eBPF production-ready for observability use cases?</title><link>https://scryops.dev/qa/ebpf-production-ready/</link><guid>https://scryops.dev/qa/ebpf-production-ready/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>For profiling and network observability on a modern Linux kernel, yes. Cilium, Parca, Pixie and Tetragon all run in production. The caveats are kernel version and BTF support, the privileges the agent needs, and application-level tracing, which still trails what an SDK gives you.</description><category>eBPF</category><category>Kubernetes</category><category>Profiling</category></item><item><title>How to Wire Trace IDs Into Your Logs</title><link>https://scryops.dev/howtos/wire-trace-ids-into-logs/</link><guid>https://scryops.dev/howtos/wire-trace-ids-into-logs/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Logs and traces live in separate worlds until you connect them. Put the trace ID on every log line in .NET, Java, Go or Python, check where each runtime actually writes it, and make the field name a contract your backend can use.</description><category>OpenTelemetry</category><category>Logs</category><category>Tracing</category><category>Python</category><category>How-to</category></item><item><title>How to Set Up Your First SLO and Burn Rate Alerts</title><link>https://scryops.dev/howtos/set-up-slo-burn-rate-alerts/</link><guid>https://scryops.dev/howtos/set-up-slo-burn-rate-alerts/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A step-by-step walkthrough: define an SLI, calculate your error budget, write Prometheus recording rules, and wire up multi-window burn rate alerts that page you before users notice.</description><category>SLOs</category><category>Alerting</category><category>Prometheus</category><category>Grafana</category><category>How-to</category></item><item><title>How to Instrument a Java Spring Boot Service with OpenTelemetry</title><link>https://scryops.dev/howtos/instrument-java-service-opentelemetry/</link><guid>https://scryops.dev/howtos/instrument-java-service-opentelemetry/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Instrument a Spring Boot service with the OpenTelemetry Java agent or the Spring Boot starter: traces, metrics and logs with no code, then your own spans and metrics, the Micrometer bridge and log correlation. All verified against a local Collector.</description><category>OpenTelemetry</category><category>Tracing</category><category>Observability</category><category>How-to</category></item><item><title>How to Instrument a .NET Service with OpenTelemetry</title><link>https://scryops.dev/howtos/instrument-dotnet-service-opentelemetry/</link><guid>https://scryops.dev/howtos/instrument-dotnet-service-opentelemetry/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Add OpenTelemetry to an ASP.NET Core service: traces, metrics and logs in one setup block, manual spans and metrics for business logic, Serilog, and the zero-code agent for services you can't change. All verified against a local Collector.</description><category>OpenTelemetry</category><category>Tracing</category><category>Observability</category><category>How-to</category></item><item><title>eBPF Continuous Profiling: A Practical Guide</title><link>https://scryops.dev/guides/ebpf-continuous-profiling/</link><guid>https://scryops.dev/guides/ebpf-continuous-profiling/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Profile every process on a node with one DaemonSet and no code changes. How eBPF profilers work, which tool to pick, a tested Parca deployment, and the privileges, storage and trace-linking limits you need to plan around.</description><category>eBPF</category><category>Profiling</category><category>Kubernetes</category></item><item><title>Context Propagation: How Distributed Traces Stay Connected Across Services</title><link>https://scryops.dev/guides/otel-context-propagation/</link><guid>https://scryops.dev/guides/otel-context-propagation/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A distributed trace is only as complete as its weakest propagation link. One hop that drops the context and the trace splits in two. W3C Trace Context and Baggage, the propagator settings that matter, and the places context gets lost — between services and inside them — in .NET, Java, Go, Python and Node.</description><category>OpenTelemetry</category><category>Tracing</category><category>Observability</category><category>Best Practices</category></item><item><title>Choosing SLIs for Your Service: A Practitioner's Matrix</title><link>https://scryops.dev/guides/sli-selection-by-service-type/</link><guid>https://scryops.dev/guides/sli-selection-by-service-type/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>Availability and latency are the obvious SLIs. But they don't fit every service type. This guide provides SLI selection frameworks for APIs, data pipelines, batch jobs, storage systems, event-driven services, and more.</description><category>SLOs</category><category>Reliability</category><category>Observability</category><category>Metrics</category></item><item><title>Alert Correlation: Finding the Signal in the Flood</title><link>https://scryops.dev/guides/alert-correlation/</link><guid>https://scryops.dev/guides/alert-correlation/</guid><pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate><description>A single failure in a distributed system can trigger dozens of alerts across every layer it touches. Correlation groups the symptoms back into one cause — so the on-call engineer sees a problem, not a storm.</description><category>Alerting</category><category>Observability</category><category>Reliability</category><category>On-Call</category><category>AIOps</category></item><item><title>Your Tagging Standard Is a Wiki Page. That's Why It Doesn't Work.</title><link>https://scryops.dev/articles/opa-observability-governance/</link><guid>https://scryops.dev/articles/opa-observability-governance/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>Every team has a tagging standard. Most of them live in a wiki, enforced by nobody, remembered by almost nobody, and invisible to the CI pipeline. Open Policy Agent fixes the root cause.</description><category>Observability</category><category>Compliance</category><category>CI/CD</category><category>Best Practices</category><category>Operations</category></item><item><title>Your Sampling Strategy Is Lying to You</title><link>https://scryops.dev/articles/sampling-strategy/</link><guid>https://scryops.dev/articles/sampling-strategy/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>A flat 5% sampling rate sounds like a sensible trade between cost and coverage. It isn't. A random slice of your traffic is mostly the requests you'll never look at, and it throws away the rare ones you need at the same rate.</description><category>Tracing</category><category>Sampling</category><category>OpenTelemetry</category><category>Observability</category></item><item><title>SLOs and Error Budgets</title><link>https://scryops.dev/guides/slos-and-error-budgets/</link><guid>https://scryops.dev/guides/slos-and-error-budgets/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>Service Level Objectives and error budgets give reliability a quantitative shape — a target, a budget for deviation, and burn rate signals that tell you when to stop shipping and start fixing.</description><category>SLOs</category><category>Alerting</category><category>Reliability</category><category>Observability</category><category>On-Call</category></item><item><title>How to Configure OTel Collector Tail Sampling</title><link>https://scryops.dev/howtos/configure-collector-tail-sampling/</link><guid>https://scryops.dev/howtos/configure-collector-tail-sampling/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>Move from flat probabilistic sampling to tail-based sampling in the OTel Collector. Keep every error and slow trace, cut health-check noise to 1%, and check that the Collector is doing what you think.</description><category>OpenTelemetry</category><category>Sampling</category><category>Collector</category><category>Tracing</category><category>How-to</category></item><item><title>Enrich Logs with Business Context in .NET</title><link>https://scryops.dev/howtos/enrich-logs-with-business-context-dotnet/</link><guid>https://scryops.dev/howtos/enrich-logs-with-business-context-dotnet/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>A log line that says 'payment failed' tells you something broke. One that says 'payment failed, enterprise customer, checkout-v2 experiment' tells you what to do about it. Here's how to add that context to every log event in a .NET service, safely, with Serilog.</description><category>Logs</category><category>Structured Logging</category><category>OpenTelemetry</category><category>Best Practices</category><category>How-to</category></item><item><title>An Alert Without a Next Step Is Just Noise</title><link>https://scryops.dev/articles/alert-design-principles/</link><guid>https://scryops.dev/articles/alert-design-principles/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>The alert fires. The on-call is up. Now what? If the answer is 'check the dashboard', the alert isn't finished. The alert body is where the fix starts, or where you lose an hour chasing context.</description><category>Alerting</category><category>On-Call</category><category>SLOs</category><category>Reliability</category><category>Observability</category></item><item><title>Alert Severity Levels, Rebuilt for Burn Rate</title><link>https://scryops.dev/guides/alert-severity-levels/</link><guid>https://scryops.dev/guides/alert-severity-levels/</guid><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><description>The P0-P4 framework was built for a world of static thresholds. Here's how to reconnect it to SLO burn rates — so severity reflects actual user impact, not arbitrary lines.</description><category>Alerting</category><category>SLOs</category><category>On-Call</category><category>Reliability</category></item><item><title>What is synthetic monitoring, and how does it differ from RUM?</title><link>https://scryops.dev/qa/synthetic-monitoring-vs-rum/</link><guid>https://scryops.dev/qa/synthetic-monitoring-vs-rum/</guid><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><description>Synthetic monitoring runs scripted tests on a schedule. RUM captures what real users actually experience. They answer different questions, and you need both.</description><category>Observability</category><category>RUM</category><category>Monitoring</category><category>Reliability</category></item><item><title>The dashboard was green, but the request was broken.</title><link>https://scryops.dev/articles/distributed-tracing-dashboard-was-green/</link><guid>https://scryops.dev/articles/distributed-tracing-dashboard-was-green/</guid><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate><description>Metrics tell you how the crowd is doing. Logs tell you what one service saw. A trace tells you what one request went through, and at 2 a.m. that is usually the question you are asking.</description><category>Tracing</category><category>Observability</category><category>OpenTelemetry</category><category>Sampling</category><category>Debugging</category></item><item><title>Scrub PII from Application Logs in .NET</title><link>https://scryops.dev/howtos/scrub-pii-from-application-logs-dotnet/</link><guid>https://scryops.dev/howtos/scrub-pii-from-application-logs-dotnet/</guid><pubDate>Sat, 26 Sep 2026 00:00:00 +0000</pubDate><description>Keep personal data out of your .NET logs before they leave the process: classify fields so the logger erases or pseudonymises them, scrub free text and exception messages in an OpenTelemetry processor, and prove nothing leaks.</description><category>GDPR</category><category>Privacy</category><category>Security</category><category>Logs</category><category>Compliance</category><category>OpenTelemetry</category><category>How-to</category></item><item><title>Log Context Enrichment: Adding Meaning to Your Events</title><link>https://scryops.dev/guides/log-context-enrichment/</link><guid>https://scryops.dev/guides/log-context-enrichment/</guid><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><description>Enrichment turns isolated log records into connected business events. Here is the architecture that makes it work — static resource attributes, background-refreshed caches, and per-request scopes — without taxing the request path.</description><category>Logs</category><category>Observability</category><category>OpenTelemetry</category><category>Structured Logging</category><category>Best Practices</category></item><item><title>Common Logging Pitfalls and How to Avoid Them</title><link>https://scryops.dev/guides/common-logging-pitfalls/</link><guid>https://scryops.dev/guides/common-logging-pitfalls/</guid><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><description>The same logging mistakes turn up in every team and every stack: inconsistent field names, values buried in message strings, missing trace context, personal data and secrets in error logs, and loops that log the same thing ten thousand times. Here is where to look and what to fix.</description><category>Logs</category><category>Structured Logging</category><category>Observability</category><category>Best Practices</category></item><item><title>Async Logging: Keeping Your Application Threads Free</title><link>https://scryops.dev/guides/async-logging/</link><guid>https://scryops.dev/guides/async-logging/</guid><pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate><description>A synchronous log write makes the request thread wait on disk or network I/O. Async logging hands that work to a background thread, and quietly adds a queue that can fill up, drop records and lose them at shutdown. How to size it, watch it and flush it, with Serilog, the OpenTelemetry SDK and Python.</description><category>Logs</category><category>Observability</category><category>OpenTelemetry</category><category>Reliability</category></item><item><title>Set Up Log-Based Alerting with Loki and Grafana</title><link>https://scryops.dev/howtos/set-up-log-based-alerting/</link><guid>https://scryops.dev/howtos/set-up-log-based-alerting/</guid><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><description>Turn a LogQL query into a Grafana-managed alert rule that fires on error volume, a specific error type or a failing dependency. Covers the query, the rule settings that trip people up, routing to PagerDuty and Slack, and an end-to-end test.</description><category>Logs</category><category>Observability</category><category>Alerting</category><category>Grafana</category><category>How-to</category></item><item><title>Observability Under Compliance: GDPR, HIPAA, SOC 2, and PCI DSS</title><link>https://scryops.dev/guides/compliance-observability/</link><guid>https://scryops.dev/guides/compliance-observability/</guid><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><description>Regulated industries need observability too. A guide to building telemetry pipelines that satisfy GDPR, HIPAA, SOC 2, and PCI DSS requirements — covering data minimisation, retention mandates, audit trails, and what each framework actually requires.</description><category>Compliance</category><category>Privacy</category><category>GDPR</category><category>Security</category><category>Observability</category></item><item><title>Log-Based Monitoring: Alerting on the Evidence</title><link>https://scryops.dev/guides/log-based-monitoring/</link><guid>https://scryops.dev/guides/log-based-monitoring/</guid><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><description>Logs carry operational state at a resolution metrics can't match. Most teams only open them after something breaks. This guide covers how to query them continuously, turn them into metrics, and alert on what they surface without blowing up cardinality or cost.</description><category>Logs</category><category>Observability</category><category>Alerting</category><category>Structured Logging</category></item><item><title>Implementing Audit Trails with OpenTelemetry</title><link>https://scryops.dev/guides/audit-trail-implementation/</link><guid>https://scryops.dev/guides/audit-trail-implementation/</guid><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><description>An audit trail is not a log. It's a tamper-evident, time-ordered record of who did what, when, and why. Most teams build this wrong. Here is how to do it correctly using OpenTelemetry and append-only storage.</description><category>Compliance</category><category>Security</category><category>OpenTelemetry</category><category>Logs</category><category>Privacy</category></item><item><title>The Evolution of System Understanding</title><link>https://scryops.dev/articles/evolution-of-system-understanding/</link><guid>https://scryops.dev/articles/evolution-of-system-understanding/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>From grepping one log file to querying wide, trace-linked events: how the questions we can ask a running system changed when monoliths split apart, and why OpenTelemetry had to exist.</description><category>Observability</category><category>OpenTelemetry</category><category>Tracing</category><category>Philosophy</category></item><item><title>Observability vs. Monitoring: Why the Distinction Matters</title><link>https://scryops.dev/articles/observability-vs-monitoring/</link><guid>https://scryops.dev/articles/observability-vs-monitoring/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>Monitoring tells you when something you predicted goes wrong. Observability lets you work out what's happening when it's something you didn't. You need both, and the gap between them is where incidents drag on.</description><category>Observability</category><category>Monitoring</category><category>Philosophy</category><category>Cost</category></item><item><title>How to Benchmark Synchronous vs Channel Logging</title><link>https://scryops.dev/howtos/benchmark-sync-vs-channel-logging/</link><guid>https://scryops.dev/howtos/benchmark-sync-vs-channel-logging/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>Async logging is supposed to take I/O off the request thread. Measure it: a sync-vs-channel benchmark under concurrent producers, in .NET, Go, or Python, and how to read the result.</description><category>Logs</category><category>Python</category><category>How-to</category></item><item><title>High-Throughput Logging: Sampling, Collectors, and the Wire</title><link>https://scryops.dev/guides/high-throughput-log-pipelines/</link><guid>https://scryops.dev/guides/high-throughput-log-pipelines/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>At 1.5 million log events per second you cannot keep, batch, or ship everything the way you did at moderate scale. Content-aware sampling, OTel exporter tuning, Collector-side batching, and cheaper bytes on the wire.</description><category>Logs</category><category>Sampling</category><category>OpenTelemetry</category><category>Collector</category><category>OTLP</category></item><item><title>High-Throughput Logging: Keeping the Hot Path Fast</title><link>https://scryops.dev/guides/high-throughput-logging/</link><guid>https://scryops.dev/guides/high-throughput-logging/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>At hundreds of thousands of requests per second, the logging call itself becomes the bottleneck. Async channels, pooling, batching, and circuit breakers keep log I/O off the request thread.</description><category>Logs</category><category>Reliability</category><category>Observability</category></item><item><title>Distributed Logging: Ten Services, One Story</title><link>https://scryops.dev/guides/distributed-logging/</link><guid>https://scryops.dev/guides/distributed-logging/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>When a request crosses ten services, you get ten log streams that share nothing but a timestamp you can't trust. How to collect them on every node, carry the trace ID through, ship them through the OpenTelemetry Collector, and notice when lines go missing.</description><category>Logs</category><category>Observability</category><category>OpenTelemetry</category><category>Collector</category><category>Kubernetes</category></item><item><title>Data Masking in Telemetry: The Art of Safe Transformation</title><link>https://scryops.dev/guides/data-masking-in-telemetry/</link><guid>https://scryops.dev/guides/data-masking-in-telemetry/</guid><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><description>Telemetry data is just as risky for PII as any database. Here's how to turn sensitive fields into safe, useful signals: hashing, tokenising, coarsening, and picking the right tool for the job.</description><category>Privacy</category><category>OpenTelemetry</category><category>Security</category><category>Observability</category><category>Collector</category></item><item><title>Your Traces Are Leaking User Data</title><link>https://scryops.dev/guides/pii-in-telemetry/</link><guid>https://scryops.dev/guides/pii-in-telemetry/</guid><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><description>Every OTel span that includes a customer email, shipping address, or payment token is a GDPR audit waiting to happen. The fix isn't application code; it's a Collector pipeline.</description><category>OpenTelemetry</category><category>Privacy</category><category>GDPR</category><category>Security</category><category>Observability</category><category>Collector</category></item><item><title>Alert Fatigue Is an Observability Problem</title><link>https://scryops.dev/articles/alert-fatigue-is-an-observability-problem/</link><guid>https://scryops.dev/articles/alert-fatigue-is-an-observability-problem/</guid><pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate><description>Every alert that fires is doing its job. That is the problem. The model is wrong, not the thresholds.</description><category>Alerting</category><category>SLOs</category><category>On-Call</category><category>Observability</category></item><item><title>Observability 1.0 meant forensics. Observability 2.0 means prevention.</title><link>https://scryops.dev/articles/what-is-observability-2-and-why-scryops/</link><guid>https://scryops.dev/articles/what-is-observability-2-and-why-scryops/</guid><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><description>Observability 1.0 taught us to look backward. Observability 2.0 asks us to look forward. Most teams haven’t made that shift yet. That’s why I named this site after a medieval divination practice.</description><category>Observability</category><category>OpenTelemetry</category><category>AI</category><category>Philosophy</category></item></channel></rss>