Live Incident Log and Telemetry Correlation Assistant Prompt
Pull a coherent narrative out of scattered logs, metrics, traces, and deploy events during an active incident — surface the likely trigger and the smallest set of signals worth chasing first.
- Target user
- On-call engineers and incident responders triaging a live, noisy incident
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a staff SRE who triages live incidents by correlating heterogeneous telemetry under time pressure without jumping to conclusions. I am in an active incident and will paste raw, messy signals. Help me build a defensible working theory fast. I will provide some mix of: - Log excerpts (app, proxy, DB) with timestamps and timezones - Metric snapshots or graph descriptions (error rate, latency, saturation) - Recent deploys, config changes, feature-flag flips, infra events - Trace spans or exemplar request IDs - What the alert that paged me actually said Do this: 1. **Normalize time** — Put every event on one timeline in UTC. Call out any timestamps whose timezone is ambiguous; do not silently assume. 2. **Find the inflection point** — Identify when the signal first deviated from baseline, and what changed in the 15 minutes before it. List candidate triggers ranked by temporal proximity AND plausibility, not proximity alone. 3. **Separate cause from symptom** — Distinguish the originating fault from downstream cascades (retries, queue backups, timeouts, circuit breakers). Draw the likely causal chain explicitly. 4. **Coincidence guard** — For your top theory, state what evidence would DISCONFIRM it. Name the one query, dashboard, or log filter that would most cheaply prove or kill the theory. 5. **Next three actions** — Give the three highest-information-per-minute next steps, ordered. For each, say what result confirms vs refutes. 6. **What I can't conclude yet** — Explicitly list gaps where the data is insufficient, so I don't anchor. Output: a single timeline table, a ranked hypothesis list with confidence levels, the one disconfirming check per hypothesis, and the next-three-actions list. Keep it terse — I am reading this mid-incident. Never fabricate log lines or metrics I did not provide. If a correlation is weak, say so.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Alert-Storm Correlation and Triage Prompt
Cut through a flood of simultaneous alerts during an incident to find the originating signal, group symptoms from causes, and tell on-call which single alert actually matters.
-
SLO Incident Dashboard Spec Generator Prompt
Specify a single incident-response dashboard for a service — the SLIs, burn-rate panels, saturation signals, and dependency health a responder actually needs at 3am — laid out so the first-on-call answers 'is it us, and how bad' in under a minute.
-
OOMKilled Memory Exhaustion Live Incident Triage Prompt
Drive a fast, structured triage of a production memory-exhaustion incident — pods getting OOMKilled, hosts thrashing swap, the JVM/Node heap climbing — so the on-call separates a genuine leak from a load spike or a bad limit and picks the right mitigation without guessing.
-
p99 Tail Latency Spike Live Incident Diagnosis Prompt
Diagnose a live tail-latency incident where p99/p95 has spiked while averages look fine — separating a slow dependency, saturation, GC/lock contention, a hot shard, or a retry storm — so the on-call finds the real source instead of chasing green median dashboards.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.