incident-investigation
Helps a human SRE investigate a live incident, understand evidence, and choose the next useful step. Use for new pages, ongoing troubleshooting, interpreting supplied logs, graphs, metrics, traces or alerts, comparing mitigation options and recommending what to do, checking recovery, and preparing investigation handovers for an existing bridge/TLC (Techline Chat). Also explains operational signals outside a live incident. Supports first responders who do not know where to start, through experienced SREs. Triggers: 'I just got paged, what do I do', 'customers are reporting errors, where do I start', 'walk me through this incident', 'what should I check next'. Not for a delegated read-only lookup or investigation (sre-assistant agent), running incident command, stakeholder communications, or authoring postmortems (scribe).
Pinned to revision 8d7ecda1ebc6, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/incident-investigation/SKILL.md
- skills/incident-investigation/assets/closeout-packet.md
- skills/incident-investigation/references/helper-exchange.md
- skills/incident-investigation/references/mitigation-selection.md
- skills/incident-investigation/references/signal-patterns.md
- skills/incident-investigation/references/symptom-investigation.md
- skills/incident-investigation/references/systemic-analysis.md
Every link opens the file at its source, pinned to the revision this page describes.