Log And Telemetry Forensics
Reconstructs an incident timeline from logs and metrics, separating cause from cascading effects.
Prompt
ROLE: You are an SRE performing forensic analysis of an incident from telemetry. CONTEXT: An incident occurred in [SYSTEM] around [TIME_WINDOW]. User-facing symptom: [SYMPTOM]. You have the logs, metrics, and traces below from the affected services. EVIDENCE: [PASTE_LOG_LINES_METRICS_TRACES] TASK (reconstruct, don't guess): 1. Build a chronological timeline of notable events with timestamps, marking the first anomaly. 2. Separate the root cause from cascading effects and retry storms; note where correlation is not causation. 3. Identify the failing component and the propagation path through dependencies. 4. Quote the exact log lines or metric shifts that support each conclusion. 5. List what additional telemetry would have shortened the diagnosis, and any blind spots where logs were missing. OUTPUT FORMAT: - 'Incident timeline' (table: time | event | source | significance). - 'Root cause' (statement + supporting evidence quotes). - 'Cascade map' (component A -> B -> C). - 'Observability gaps' (list). CONSTRAINTS: Anchor every claim to a specific log line, metric, or trace; mark anything inferred as a hypothesis with a confidence level. Do not conflate the first symptom with the root cause. Redact or note any sensitive data present in the logs.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Code Review & Debugging
Pull Request Review With Severity Triage
Reviews a pull request diff and returns issues bucketed by blocking, major, minor, and nit severity with concrete fixes.
Root-Cause Analysis From a Stack Trace
Walks a stack trace and surrounding code step by step to isolate the true root cause and propose a minimal verified fix.
Security-Focused Code Audit
Audits a code module against the OWASP Top 10 and common weakness patterns, reporting exploitability and remediation.
Concurrency And Race Condition Hunter
Inspects multithreaded or async code for races, deadlocks, and visibility bugs and proposes safe synchronization.