1
Entry point. A request, a command or a scheduled task. If it is sampled in, its whole trace is kept; if not, none of it.
2
Child events. Queries, cache hits, dispatched jobs, outgoing requests, mail, exceptions and logs, linked to the parent.
3
Sample, filter, redact. Rates per entry point; Nightwatch::ignore(); sensitive headers and payload fields removed before sending.
4
Buffer. Up to 500 events, then flushed to the agent over TCP, with half-second connect and send timeouts.
5
Agent. nightwatch:agent, one resident process per application, listening on port 2407 and shipping to Nightwatch.
6
Nightwatch. The hosted side: timelines, issues made from exceptions, alerts; data in the US, EU or Australia.