Ravindra BagaleCourses & study guides

Chapter 14: Logging and Light Observability

14.6 Searching — find the last error

Whether CloudWatch Logs Insights, console filter patterns, or docker logs | grep:

  1. Narrow time window around the incident (lunch 12:30–12:45).
  2. Filter on level or keyword ERROR / Exception.
  3. Copy one representative line into the incident note.
  4. Correlate with deploy time / image tag from CI (Chapter 8–9 ideas).

Tiny story. Error rate spike at 12:41. Insights shows ERROR payment timeout. Deploy log shows tag sha-bad111 at 12:39. Rollback to sha-good990. Metrics recover. CCTV + conveyor tags saved lunch.

Steps — five-line incident note

  1. Write When (IST time window).
  2. Write Symptom (user-visible + metric if any).
  3. Write Evidence (one log line + request/correlation id if present).
  4. Write Action (rollback / restart / config fix).
  5. Write Follow-up (ticket: add alert, fix root cause, improve test).

What you see: a note another engineer can read at 1 a.m. without calling you.