Better Stack

Uptime monitoring, log management and on-call alerting.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Logging

  • Structured objects, not interpolated strings: logger.info('Subscription renewed', { userId, plan }). The fields are what make a log searchable six months later.
  • Never log personal data, tokens, passwords, session ids, API keys, or whole request bodies that might contain them. Logs are retained, replicated and broadly readable.
  • Log levels mean something: error is actionable, warn is suspicious, info is a business event. Do not log everything at error.
  • Flush before process exit, or buffered logs die with the process.

Health endpoints

  • A health check verifies dependencies — database reachable, migrations applied — and returns non-200 when they fail.
  • One that unconditionally returns 200 monitors only that the web server is running, which is rarely the thing that breaks.

Alerts

  • Alert on symptoms users feel: down, elevated error rate, latency doubled.
  • Require consecutive failures. A single failed check is a network blip.
  • Every alert must be actionable. If nobody would act at 3am, it belongs on a dashboard.

Never

  • Never route alerts to a shared inbox with no owner.
  • Never disable a noisy alert without fixing or retuning it.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/betterstack.mdchand-written
---
description: Better Stack monitoring and logging conventions
globs: ["server/**", "api/**", "src/services/monitoring/**"]
alwaysApply: false
---

# Better Stack

## Logging

- Structured objects, not interpolated strings:
  `logger.info('Subscription renewed', { userId, plan })`. The fields are what
  make a log searchable six months later.
- **Never log** personal data, tokens, passwords, session ids, API keys, or
  whole request bodies that might contain them. Logs are retained, replicated
  and broadly readable.
- Log levels mean something: `error` is actionable, `warn` is suspicious,
  `info` is a business event. Do not log everything at `error`.
- Flush before process exit, or buffered logs die with the process.

## Health endpoints

- A health check verifies dependencies — database reachable, migrations applied
  — and returns non-200 when they fail.
- One that unconditionally returns 200 monitors only that the web server is
  running, which is rarely the thing that breaks.

## Alerts

- Alert on symptoms users feel: down, elevated error rate, latency doubled.
- Require consecutive failures. A single failed check is a network blip.
- Every alert must be actionable. If nobody would act at 3am, it belongs on a
  dashboard.

## Never

- Never route alerts to a shared inbox with no owner.
- Never disable a noisy alert without fixing or retuning it.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting Better Stack contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
BETTERSTACK_SOURCE_TOKENrequiredLog source token. Server-side only.
BETTERSTACK_INGESTING_HOSToptionalRegion-specific ingest host, if your source specifies one.
HEALTHCHECK_PATHoptionalPath the uptime monitor calls. Must verify real dependencies.
Dependencies
@logtail/node^0.5.0
Folders
server/monitoring/

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →
Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.