Find the signal in a pile of logs
Separates normal from anomalous across thousands of lines, without looking only at error messages.
| Category | Development › Deploy & operations |
|---|---|
| Tags | AnalyzingSummarizingDeveloper |
Analyze these logs. Do this in order: 1. **Establish normal.** What repeats routinely, at roughly what rate. Everything else is judged against this. 2. **Find the first deviation** — the earliest point where the pattern changes. This is usually earlier than the first error and is the thing worth finding. 3. Frequency shifts — anything that got more common, less common, or stopped entirely. *A log line that stops appearing is as significant as a new error and far easier to miss.* 4. Ordering changes — operations arriving out of their usual sequence. 5. Errors, grouped by kind, with counts and first and last occurrence. Do not list them individually. 6. Distinguish causes from consequences. Timeouts and connection errors are usually downstream of something earlier. Then: - The five lines I should look at, with timestamps. - What is missing from these logs that the diagnosis needs, and where it would be. Rules: - *Do not conclude a root cause from logs alone.* Say what the logs support and what would confirm it. - Where a timestamp gap suggests missing lines, say so rather than reading across the gap. - Quote lines exactly, including timestamps.
After pasting, fill in the fields at the bottom (Logs · Problem occurred at · Normal pattern)
What this prompt does
Reading only ERROR lines misses the cause, which usually sits where the normal pattern changed just before. This looks at frequency and ordering shifts too.