Right now
What stands out: templates at least three times above or below their usual minute, and at least six lines a minute apart.
| Template | Now, a minute | Usual | Change |
|---|
The closest incidents in the file
Each written-down incident keeps the fingerprint of its first two minutes. The file compares it with now, by the cosine of the two fingerprints.
The two hours
Above, what happened to the shop. Below, what the file said at each check: looks like an incident in the file, partly like one, or like nothing in it.
What happened
Newest first.
Warnings and errors, as they are written
The newest first. Every line goes into the file and stays there for ten minutes; the counts stay for days.
The incidents in the file
What the on-call team wrote down, and anything you write down here. Its fingerprint is saved beside it, so it outlives the week the minute counts are kept.
| # | Began | What it was | What fixed it | By | Templates |
|---|
Results
Finishing the two hours at full speed, then checking every count.
Every incident today
When each one began, when it first stood out and what the file said. A kind seen before counts when it is named right; a new kind counts when it is flagged as new. Either way it must never be named wrong.
Every count, checked
The lines a minute and an hour for each service and level, from the file, against a recount of the lines by separate code that never reads it.
What is in the file
Ask the file
Everything above is read from one SQLite file: yesterday's counts, the incidents and today's lines as they arrive. Pick a question or write your own, then press Run (or Ctrl+Enter, ⌘+Enter on a Mac). It reads while the run is paused or finished.
The policy and the comparison
The policy counts every template by service and level, a minute at a time for a week and an hour at a time for 90 days, and keeps every line for ten minutes. The comparison is plain SQL beside it.