trajectory
log-forensics-01core-12anyDifficulty tier 2/5

Find the root cause of an outage in 40,000 lines of logs

log-analysisforensicsroot-causedata-extraction

Task parameters

Reference steps
11
Step ceiling
40
Runs
15
Solved
12 of 15
Models
5

What is broken, and what fixed means

A 95 minute window of logs from five services covers a customer facing outage. One configuration change shrank a connection pool from 40 to 4, which exhausted the pool in the inventory service and cascaded into timeouts in checkout and 503s at the gateway. The log also contains three plausible distractions: a certificate expiry warning that fires throughout, a burst of scanner 404s twenty minutes before the incident, and an operator restarting an unrelated service in the middle of it. The deliverable is a findings file in a specified schema, so the answer is checked field by field rather than by eye.

Results by model

One group per model. The solve rate carries its spread across seeds, and every run below it links to the full step by step replay.

stub:hasty

0.0%+/- 0.0% over 3 seeds

3 runs, seeds 0, 1, 2

stub:methodical

100.0%+/- 0.0% over 3 seeds

3 runs, seeds 0, 1, 2

stub:reckless

100.0%+/- 0.0% over 3 seeds

3 runs, seeds 0, 1, 2

stub:sloppy

100.0%+/- 0.0% over 3 seeds

3 runs, seeds 0, 1, 2

stub:thrasher

100.0%+/- 0.0% over 3 seeds

3 runs, seeds 0, 1, 2