logfmt — Quoting, Escaping and Bare-Key Edge Cases (log)
logfmt lines built to break naive splitting on spaces and equals signs: a value containing an equals sign, escaped quotes, a trailing backslash before the closing quote, a bare key with no value, duplicate keys, non-ASCII values and one unterminated quote followed by a clean line.
ts=2026-03-17T09:14:32.850Z level=info msg="request completed" method=POST route=/api/checkout status=201 duration_ms=148.2
ts=2026-03-17T09:14:32.930Z level=warn msg="value contains an equals sign" filter="status=500" count=3
ts=2026-03-17T09:14:33.010Z level=info msg="quoted value with escaped \"quotes\" inside" user=alice
ts=2026-03-17T09:14:33.180Z level=error msg="value with a trailing backslash" path="C:\\logs\\app\\" retry=true
ts=2026-03-17T09:14:33.240Z level=info msg=unquoted_value_with_no_spaces flag empty= nil=null
ts=2026-03-17T09:14:33.390Z level=debug msg="duplicate key" shard=a shard=b
ts=2026-03-17T09:14:33.520Z level=info msg="unicode value" city="München" note=naïve
ts=2026-03-17T09:14:33.660Z level=info msg="unterminated quote starts here and never closes
ts=2026-03-17T09:14:33.790Z level=info msg="normal record after the unterminated one" ok=true
Specifications
- Lines
- 9
- Value With Equals
- 1
- Escaped Quotes
- 1
- Trailing Backslash
- 1
- Bare Key No Value
- 1
- Duplicate Keys
- 1
- Unterminated Quote
- 1
- Recovery Line
- 1
Testing contract
Expected to recover- Scenario
- Parse each line into key-value pairs and continue after the malformed one.
- Expected result
- The filter="status=500" pair stays one field, the trailing-backslash path does not swallow the following key, and the parser recovers on line 9 rather than consuming the rest of the file inside the open quote.
What is a .log file?
LOG files are plain-text records of events emitted by software, typically one entry per line with a timestamp, severity, and message. There is no single standard, so formats range from unstructured text to structured JSON lines. They are central to debugging, monitoring, and auditing.
How to use this file
Use an example LOG file to test log parsers, timestamp and severity extraction, line-oriented streaming, and ingestion into monitoring or analysis pipelines.
How to use this file for testing
“logfmt — Quoting, Escaping and Bare-Key Edge Cases (log)” is a deterministic Novus Examples fixture for Observability, Log parsing, Encoding detection. Structured and plain-text telemetry with known timestamps, levels, request identifiers, and error states for testing log ingestion, correlation, dashboards, and alert pipelines.
Documented properties for this file: LOG · 882 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
Telemetry fixtures use fixed trace IDs, span IDs, and timestamps so ingestion is reproducible run to run. Point your collector, parser, or query layer at the file and assert the documented span tree, metric families, or severity mix; service and host names are invented.
Code examples
grep -i error logfmt-quoting-edge-cases.log | head
awk '{print $1, $2, $NF}' logfmt-quoting-edge-cases.log | headRelated files
- jsonlStructured Log — Ten Timestamp Formats, One Instant (jsonl)The same instant written ten ways — RFC 3339 at three precisions and with a non-UTC offset, epoch seconds as integer and float, epoch milliseconds and nanoseconds, Common Log Format and the log4j comma-decimal form. What a timestamp autodetector must resolve to one moment.

- jsonlStructured Log — Unicode, RTL, Emoji and Control Characters (jsonl)Log messages in Latin, Japanese and Arabic scripts, an emoji flag and a zero-width-joiner family, NFC and NFD forms of the same accented letter, and escaped tab, newline and carriage return. Everything that makes a log line's byte length and its display width disagree.

- txtProfile — Demangled Symbols That Break the Folded Format (txt)Demangled C++ templates, Rust trait impls, Java generics, lambdas and unresolved hex addresses in the folded format — including one symbol containing a semicolon, which the format has no way to escape. That line is genuinely ambiguous, and how a parser handles it is the point.

- log.NET Exception with an Inner Exception Chain (log)A .NET exception whose inner exception is introduced by the ---> marker and closed by End of inner exception stack trace, wrapped in pipe-delimited log lines. Error groupers that key on the outermost message alone merge two genuinely different faults here.

- jsonlEnvoy-Style Proxy Access Log — JSON Lines (jsonl)Forty service-mesh proxy access records with the fields that make mesh debugging possible: response_flags distinguishing an upstream failure from an overflow, upstream_service_time against total duration, upstream host and cluster, and a request ID for correlation.

- logGo Panic with Full Goroutine Dump (log)A Go panic followed by the runtime's full goroutine dump — four goroutines with their wait states, two-line frames and a created by attribution, separated by blank lines. Blank-line separation defeats multi-line rules that treat an empty line as the end of an event.

Generated by generation/observability.py. Free for any use, no attribution required — license.