Incident Overview
A customer-facing service is producing intermittent errors. Incident Command has opened a response channel and assigned an incident commander, an operations lead and a communications lead.
The commander asks for a five-minute error trend from the central logging platform before deciding whether to escalate the fictional incident.Ten minutes later, no validated trend has reached the commander. The operations lead says the logging platform is available but believes the application team owns the query.
The application representative says operations owns incident telemetry. A dashboard screenshot in the channel shows a recent fall in error count, while a copied text extract shows several later errors.
Neither item states its query scope, time zone or refresh time.The immediate objective is not to diagnose the application fault. It is to restore a bounded evidence workflow: one named owner gathers a reproducible logging view, another responder validates its scope, and the commander receives a time-stamped result with uncertainty stated.
Investigation Options
Review the available operational moves and select the best immediate action.
Restart the logging collectors to eliminate a possible ingestion fault before assigning an evidence owner.
Declare the screenshot authoritative because dashboards are easier for the command team to interpret.
Ask the incident commander to name one logging evidence owner and one validator, then require a time-stamped query scope and explicit uncertainty.
Pause all incident coordination until the application and operations teams agree which team permanently owns logging.