---
title: Follow a trace
description: Start from a log entry, a span or an error, and move to the other two through the trace id.
type: how-to
product: monitoring
summary: One trace id connects a log entry, its spans and the errors raised inside them
updated: 2026-09-30
order: 2
---

Logs, spans and errors are three collections, and one W3C trace id is what ties
them together. Emit the same `trace_id` on all three and you can begin at
whichever one you have and reach the other two. All three are read inside one
project environment; nothing here crosses into another.

## What carries the id

<KeyValue
	items={[
		{ key: 'Log entry', value: 'trace_id and span_id, both optional', mono: true },
		{ key: 'Span', value: 'trace_id, span_id and parent_span_id', mono: true },
		{ key: 'Error event', value: 'trace_id and span_id, both optional', mono: true },
	]}
/>

`trace_id` is 32 hex characters and `span_id` is 16. A record that omits them is
still stored; it just cannot be reached this way.

## From a log entry to its spans

Query the log entries of a trace, then read the trace itself. The query needs
a bounded interval (`start_time`, at most 31 days before `end_time`) and takes an
[AIP-160 filter](/docs/api/log_entries/query):

```bash
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/log_entries:query" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"start_time":"2026-09-30T00:00:00Z","filter":"trace_id = \"4bf92f3577b34da6a3ce929d0e0e4736\""}'
```

A [Trace](/docs/api/traces) is named `traces/t{trace_id}`. Reading one answers
with every span in start order, and `parent_span_id` rebuilds the tree: it is
empty on the root span.

```bash
curl "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/traces/t4bf92f3577b34da6a3ce929d0e0e4736" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"
```

The trace's `has_error` says whether any span has an error status, so a trace
list can be scanned for the failing ones without reading each.

## From an error to its trace

An [Error Event](/docs/api/error_events) is one immutable occurrence, and
carries the `trace_id` and `span_id` it was raised under, along with its
breadcrumbs, oldest first. List the events of a group, take the `trace_id` of
the occurrence you care about, and read that trace as above. Filter the log
entries by the same id to see what the service said around it.

An occurrence captured without a trace id has no trace to open; propagate the
id into your error capture to close that gap.

## From a span to the rest

Take the span's `trace_id` and use it in the two queries above. The log entries
that also carry the span's `span_id` are the ones written inside that span.

<RelatedDocs
	links={[
		{
			href: '/docs/monitoring/quickstart',
			label: 'Monitoring quickstart',
			description: 'Send one log entry, one span and one error, then read each back.',
		},
		{
			href: '/docs/monitoring/errors',
			label: 'Errors',
			description: 'How occurrences are grouped, captured and triaged.',
		},
	]}
/>
