Precomputing Live demo: Incident déjà vu How to run it

Answers ready before you ask

When trouble starts, the file says what it looks like and what fixed it last time

Loading SQLite, the Engine and yesterday's file

Loading SQLite, the Engine and yesterday's file.

0
lines today, on 24 hours of history
–
templates
–
incidents written down
0
checks, one every 10 seconds
–
a check takes, on average
–
lines a second at full speed on this device

Right now

Loading

What stands out: templates at least three times above or below their usual minute, and at least six lines a minute apart.

TemplateNow, a minuteUsualChange

The closest incidents in the file

Each written-down incident keeps the fingerprint of its first two minutes. The file compares it with now, by the cosine of the two fingerprints.

The two hours

Above, what happened to the shop. Below, what the file said at each check: looks like an incident in the file, partly like one, or like nothing in it.

An incident Looks like one in the file Partly like one Like nothing in the file

What happened

Newest first.

    Warnings and errors, as they are written

    The newest first. Every line goes into the file and stays there for ten minutes; the counts stay for days.

    The incidents in the file

    What the on-call team wrote down, and anything you write down here. Its fingerprint is saved beside it, so it outlives the week the minute counts are kept.

    #BeganWhat it wasWhat fixed itByTemplates

    Ask the file

    Everything above is read from one SQLite file: yesterday's counts, the incidents and today's lines as they arrive. Pick a question or write your own, then press Run (or Ctrl+Enter, ⌘+Enter on a Mac). It reads while the run is paused or finished.

    The policy and the comparison

    The policy counts every template by service and level, a minute at a time for a week and an hour at a time for 90 days, and keeps every line for ten minutes. The comparison is plain SQL beside it.