Chapter 14: Logging and Light Observability
14.6 Searching — find the last error
Whether CloudWatch Logs Insights, console filter patterns, or docker logs | grep:
- Narrow time window around the incident (lunch 12:30–12:45).
- Filter on level or keyword
ERROR/Exception. - Copy one representative line into the incident note.
- Correlate with deploy time / image tag from CI (Chapter 8–9 ideas).
Tiny story. Error rate spike at 12:41. Insights shows ERROR payment timeout. Deploy log shows tag sha-bad111 at 12:39. Rollback to sha-good990. Metrics recover. CCTV + conveyor tags saved lunch.
Steps — five-line incident note
- Write When (IST time window).
- Write Symptom (user-visible + metric if any).
- Write Evidence (one log line + request/correlation id if present).
- Write Action (rollback / restart / config fix).
- Write Follow-up (ticket: add alert, fix root cause, improve test).
What you see: a note another engineer can read at 1 a.m. without calling you.