SlideShare a Scribd company logo
1 of 21
Heather O’Sullivan,
Dan Cundiff (@pmotch),
Eric Helgeson (@nulleric)
Target Corporation

LOGGING AND MONITORING APIS
Context: APIs @ Target
• RESTful APIs
• APIs across all domains in our business
  • Products (inventory, price, description, etc.)
  • Locations
  • Promotions, etc.
• Used by mobile, applications, partners on the
  outside, etc.
• Constantly evolving, rapidly improving, all the time

                                                         2
API story: Guest price matching an Xbox
                  1                   2               3                4                5                              6




                                   Daily                         Product
          Catalogs                          Products                                 Locations
                                   Deals                        Availability                                       API Gateway

Step   Guest Experience                    API                                 Result
 1     Opens Target Mobile App             Catalogs, Daily Deals
 2     Scans barcode                       Products
 3     Views product page                  Products                            Xbox item description, image and price of $179
 4     Checks store availability           Products, Product Availability      Xbox available at the Nicollet Mall Target
 5     View store location on map          Locations                           Map
 6     LOD checks price on iPad Price      Products                            Validates $179 price, instead of $189 that was listed on the Xbox in-store
       Checker app
Problem
• First API go-live:
  •   Millions of log events per day, logs everywhere
  •   Needed end to end visibility of APIs
  •   Needed ability to discover information in logs
  •   Can we be pro-active? React faster?
• Looming horizon:
  • BILLIONS of log events coming
  • Questions changing everyday from business, ops,
    execs, developers
                                                        4
Log all the things
•   Consumer apps
•   Provider systems
•   External API gateway logs
•   Anything in between (OS, firewalls, proxies)
•   Correlate with logs from apps degrees removed
    (e.g. .com web logs)
Metrics for APIs
 Traffic Metrics                     Service Metrics                     Support Metrics
 –   Total calls                     –   Performance                     – Support tickets
 –   Top methods                     –   Availability                    – Response time
 –   Call chains                     –   Error rates                     – Community metrics
 –   Quota faults                    –   Code defects
                                                                         Business Metrics
 Developer Metrics                   Marketing Metrics                   –   Direct revenue
 – Total developer count             – Developer                         –   Indirect revenue
 – Number                              registrations                     –   Market share
   of active developers              – Developer portal                  –   Costs
 – Top developers                      funnel
 – Trending apps                     – Traffic sources
 – Retention                         – Event metrics


(source: http://blog.programmableweb.com/2012/08/02/the-api-measurement-secret-know-what-metrics-matter/)
Normal volume?
Normal response times?
Normal error rates?




                      9
404s
•   ~1700 404s every Tuesday
•   404s for stores that don’t exist
•   Who are they?
•   Bot?
•   Competitor? Individual?
•   Reach out to understand



                                       10
Understanding consumers




                          11
Understanding consumers
• Load testing in production?




                                12
API adoption




               13
Monitoring Infrastructure




                            14
Monitoring API Development
• Story: Practice code as documentation. Every commit, Jenkins runs,
  extracts documentation from code, puts it in the respective wiki pages
  (automated / no humans)
• Monitor documentation changes using the MediaWiki API




                                                                           15
16
Business intelligence from APIs
•   Where are people searching?
•   Where should we build our next store?
•   How far are people traveling?
•   What time of day?
•   Mobile vs website?
•   iOS vs Android?
•   International?

                                            17
Glass




        18
Catch-all
•   Logging in JSON
•   API perspectives: API, method, version, env
•   Monitor load testing
•   Make your logging system testable
•   Apdex (not averages)
    • = (# Satisfied Req + # Tolerated / 2) / (Total Req)
• Automated onboarding

                                                            19
Lessons
 • Centralize your logging
 • Logs @ scale == Big Data problem
 • They’re your logs; you’re best suited to monitor them




                                                           20
We’re hiring
(come talk to us)


                    21

More Related Content

Recently uploaded

Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
FIDO Alliance
 

Recently uploaded (20)

UiPath manufacturing technology benefits and AI overview
UiPath manufacturing technology benefits and AI overviewUiPath manufacturing technology benefits and AI overview
UiPath manufacturing technology benefits and AI overview
 
Design Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptxDesign Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptx
 
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data Science
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
 
AI mind or machine power point presentation
AI mind or machine power point presentationAI mind or machine power point presentation
AI mind or machine power point presentation
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
 
WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024
 
Introduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptxIntroduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptx
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Top 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development CompaniesTop 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development Companies
 
Overview of Hyperledger Foundation
Overview of Hyperledger FoundationOverview of Hyperledger Foundation
Overview of Hyperledger Foundation
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджера
 
Intro to Passkeys and the State of Passwordless.pptx
Intro to Passkeys and the State of Passwordless.pptxIntro to Passkeys and the State of Passwordless.pptx
Intro to Passkeys and the State of Passwordless.pptx
 
Event-Driven Architecture Masterclass: Challenges in Stream Processing
Event-Driven Architecture Masterclass: Challenges in Stream ProcessingEvent-Driven Architecture Masterclass: Challenges in Stream Processing
Event-Driven Architecture Masterclass: Challenges in Stream Processing
 
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

Logging and Monitoring APIs - API Strategy & Practice Conference 2013

  • 1. Heather O’Sullivan, Dan Cundiff (@pmotch), Eric Helgeson (@nulleric) Target Corporation LOGGING AND MONITORING APIS
  • 2. Context: APIs @ Target • RESTful APIs • APIs across all domains in our business • Products (inventory, price, description, etc.) • Locations • Promotions, etc. • Used by mobile, applications, partners on the outside, etc. • Constantly evolving, rapidly improving, all the time 2
  • 3. API story: Guest price matching an Xbox 1 2 3 4 5 6 Daily Product Catalogs Products Locations Deals Availability API Gateway Step Guest Experience API Result 1 Opens Target Mobile App Catalogs, Daily Deals 2 Scans barcode Products 3 Views product page Products Xbox item description, image and price of $179 4 Checks store availability Products, Product Availability Xbox available at the Nicollet Mall Target 5 View store location on map Locations Map 6 LOD checks price on iPad Price Products Validates $179 price, instead of $189 that was listed on the Xbox in-store Checker app
  • 4. Problem • First API go-live: • Millions of log events per day, logs everywhere • Needed end to end visibility of APIs • Needed ability to discover information in logs • Can we be pro-active? React faster? • Looming horizon: • BILLIONS of log events coming • Questions changing everyday from business, ops, execs, developers 4
  • 5. Log all the things • Consumer apps • Provider systems • External API gateway logs • Anything in between (OS, firewalls, proxies) • Correlate with logs from apps degrees removed (e.g. .com web logs)
  • 6. Metrics for APIs Traffic Metrics Service Metrics Support Metrics – Total calls – Performance – Support tickets – Top methods – Availability – Response time – Call chains – Error rates – Community metrics – Quota faults – Code defects Business Metrics Developer Metrics Marketing Metrics – Direct revenue – Total developer count – Developer – Indirect revenue – Number registrations – Market share of active developers – Developer portal – Costs – Top developers funnel – Trending apps – Traffic sources – Retention – Event metrics (source: http://blog.programmableweb.com/2012/08/02/the-api-measurement-secret-know-what-metrics-matter/)
  • 10. 404s • ~1700 404s every Tuesday • 404s for stores that don’t exist • Who are they? • Bot? • Competitor? Individual? • Reach out to understand 10
  • 12. Understanding consumers • Load testing in production? 12
  • 15. Monitoring API Development • Story: Practice code as documentation. Every commit, Jenkins runs, extracts documentation from code, puts it in the respective wiki pages (automated / no humans) • Monitor documentation changes using the MediaWiki API 15
  • 16. 16
  • 17. Business intelligence from APIs • Where are people searching? • Where should we build our next store? • How far are people traveling? • What time of day? • Mobile vs website? • iOS vs Android? • International? 17
  • 18. Glass 18
  • 19. Catch-all • Logging in JSON • API perspectives: API, method, version, env • Monitor load testing • Make your logging system testable • Apdex (not averages) • = (# Satisfied Req + # Tolerated / 2) / (Total Req) • Automated onboarding 19
  • 20. Lessons • Centralize your logging • Logs @ scale == Big Data problem • They’re your logs; you’re best suited to monitor them 20

Editor's Notes

  1. [H]
  2. [H] Here’s the context for all the material that follows. “Enterprise Services” program is all about…
  3. [H] Guest is at competing retailer and sees an Xbox that he wants to buy. Its $199, but he thinks he can get is cheaper at Target.1, 2: Guest uses iPhone to scans the Xbox bar code; price comes back at $179!The Catalogs API, Daily Deals API, and a few others display the content on the first page and as you start to navigate.3: The Products API: displays the detail around the Xbox item including description, image, and price.The guest likes the idea of saving $20, but they’re not sure where the closest Target is or if there are any available at the store.4, 5: Product Availability API shows our Guest that the Xbox is available at the downtown Target and with another click, a map is displayed using the Locations API.So far, we’ve seen how 4 APIs are used on the iPhone app. If Guest’s buddy had an Android, they would be calling the same APIs and the same data would be displayed. Functionality is developed once and leveraged across multiple platforms.6: Guest arrives at Target, but is surprised to see the Xbox marked at $189 vs. the $179 he had expected. A team member sees the Guest and asks if she can help them find something. Using the Price Checker app on her iPad, the team member confirms the $179 price and helps the Guest check out. Again, leveraging the Products API.
  4. [E] Logsscatted everywhere = complex ecosystemLooming horizon = data explosionStory: going live, millions of hits start coming in, try to figure out what is actually happening
  5. [E]The more you log,the more complete the monitoring picture can be.
  6. [D] Now that we have all of those logs, we can measure things.
  7. [E] Have to know the profile of your APIs over time to understand. Have to know what's normal to know what’s wrong.
  8. [E] APIs behave differently over time, monitor over time. See the problem before it happens.
  9. [E] Same thing for errors, normalize over time; what’s normal and what do you need to investigate further. Batch job that runs every day at 2am? Does that affect our APIs?
  10. [D]
  11. [E]A list of consumers across all APIsover a 24 hour period.Story:Identify bad API key before the developer knew what was wrong.
  12. [D]
  13. [E]What APIs are popular, which ones are growing or shrinking, where do we need to look at scaling?
  14. [D] API might seem healthy but underneath the infrastructure might not be. Monitor it too!
  15. [D] Monitor your development too! Git, Jenkins, etc. The small things add up.
  16. [D]Abig story to draw you in!Anonymizedlat/long data of guest searching for stores in the last 15 minutes.If a store wasn’t nearby those 61 people in Idaho, did they go somewhere else to by Tide, diapers, or socks?Conceptually, maybe we should build a store there (we don’t actually plan our stores with a sole data point like that, but it gives you an idea)?
  17. [D]
  18. [D]Global dashboard summarizing all APIsBI dashboardsExecutive dashboardsEnvironment dashboards for each API:CI,Test,Stage,ProdAlert trending dashboards for each API
  19. [D] [E]
  20. [D]
  21. [D]