Investigations
Start with an alert, hunch, or failing service. Investigations turn incident noise into ranked causes and reviewable evidence.
The agent correlates metrics, logs, traces, and notes so responders see the strongest explanation first, not another wall of charts.
- Kick off from an alert, a service name, or a hypothesis and let the agent gather the signals.
- Compare likely causes with the telemetry that supports or weakens each one.
- Hand a reviewer a written trail instead of asking them to reconstruct the incident from dashboards.
When a failure mode repeats, wire it to an alert so the next investigation starts automatically with the right context. See Customization.