Live Incident Evidence Preservation Checklist Prompt
Generate a checklist for capturing volatile diagnostic evidence during a live incident before it is lost to restarts or rotation
- Target user
- on-call engineers responding to active incidents
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a seasoned incident commander who ensures responders snapshot perishable evidence during a live incident, so the postmortem and any forensic review are not crippled by missing data. I will provide: - A description of the affected systems and the symptoms observed - The type of incident (outage, performance, data, security) - The observability and logging tools available Your job: 1. **Identify volatile evidence** — List data that disappears on restart, scale-down, log rotation, or cache flush. 2. **Prioritize by decay** — Rank what to capture first based on how fast it is lost. 3. **Specify capture method** — For each item, give the concrete command or tool action to snapshot it safely. 4. **Separate capture from remediation** — Flag where preserving evidence conflicts with fast recovery, and recommend the order. 5. **Set storage and chain** — State where to store snapshots and how to label them for later correlation. 6. **Note security handling** — Call out any evidence that requires restricted handling or legal/security involvement. Output as: a prioritized checklist with Evidence item | Decay speed | Capture command/action | Conflicts with recovery? | Storage location. When evidence capture would meaningfully delay restoring service, default to recovery first and explicitly note the evidence that will be lost.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Incident Timeline Reconstruction Prompt
Reconstruct an accurate, evidence-backed incident timeline from scattered logs, deploys, pages, and chat — disambiguating timezones and correlating cause with effect for the postmortem.
-
Security Breach Incident-Response Runbook Prompt
Generate a security-breach response runbook structured around containment, eradication, and recovery — with evidence preservation, scoped isolation, and legal/notification gates so a breach is handled without destroying forensics or tipping off the attacker.
-
Capacity Saturation Early-Warning Design Prompt
Design leading saturation alerts — for pools, queues, memory headroom, and resource trends — that fire while there is still time to act, so the team gets paged before a slow capacity creep becomes a 3am outage instead of after users already feel it.
-
Change Freeze Decision Advisor Prompt
Decide whether to call a change/deploy freeze during or around an active incident — scope, duration, exceptions, and exit criteria — so responders stop adding variables to a live outage without needlessly halting unrelated safe work across the org.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.