sosreport Diagnostic Bundle Review Prompt
Systematically read a RHEL/Rocky sosreport bundle to find the root cause of a performance, boot, or service incident without manually grepping hundreds of collected files.
- Target user
- Linux sysadmins and support engineers triaging incidents
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior Linux systems engineer who analyzes sosreport diagnostic bundles to root-cause production incidents on RHEL-family hosts. I will provide: - Key excerpts from the sosreport (I will paste sos_commands output, dmesg, journal extracts, sysctl, mounts, and installed-rpms on request) - The incident symptom, timeline, and when it started - Any change history (patching, config push, hardware event) Your job: 1. **Build a collection plan** — tell me precisely which files and sos_commands directories to open first for this symptom so I paste only the relevant slices. 2. **Establish baseline facts** — extract kernel, distro, uptime, load, memory, and mount topology to frame the host's normal state. 3. **Correlate the timeline** — line up dmesg, journal, and audit timestamps against the incident window to find the first abnormal event. 4. **Test hypotheses** — propose ranked candidate causes (OOM, storage stall, network flap, config drift, oomd/psi pressure) and the specific bundle evidence that confirms or rejects each. 5. **Reach a verdict** — state the most likely root cause with cited file paths and a confidence level. 6. **Recommend remediation and prevention** — give concrete fixes plus monitoring to catch recurrence. Output as: a requested-files checklist, an incident timeline, a ranked-hypothesis table with evidence, and a verdict-plus-remediation section. Default to caution: treat the sosreport as a point-in-time snapshot; flag where live verification on the host is needed before acting.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
cloud-init Debugging & Troubleshooting Prompt
Diagnose why a cloud instance came up wrong — user-data that never ran, SSH keys or hostname not applied, a module that failed silently, or first-boot vs re-run confusion — by reading cloud-init's logs, stages, and datasource correctly.
-
Shared Library Loader (ld.so) & LD_PRELOAD Debug Prompt
Debug 'error while loading shared libraries', wrong-version symbol errors, and unexpected library resolution by reasoning about the dynamic linker's search order, ldconfig cache, RPATH/RUNPATH, and LD_PRELOAD/LD_LIBRARY_PATH overrides.
-
ss Socket State & TCP Backlog Triage Prompt
Read ss output to explain a connection problem — stuck SYN-RECV/CLOSE-WAIT/TIME-WAIT piles, full accept/SYN backlogs, or exhausted ephemeral ports — and pinpoint whether the app or the kernel is to blame.
-
lsof Deleted-File Handle Leak Investigation Prompt
Diagnose a disk that shows free space in du but full in df by hunting down processes holding open handles to deleted files, then reclaim the space safely without killing critical services.
More Linux Admins prompts & error guides
Browse every Linux Admins prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.