Definition
Root cause analysis investigates the mechanisms and contributing conditions behind an incident using evidence and tested hypotheses.
Signals
Why use it
Explain why a dependency slowdown caused user-facing failures and identify changes that prevent recurrence.
Common use cases
- Reconstruct incident timelines
- test release hypotheses
- identify contributing dependencies.
Benefits
- Turns incident evidence into specific corrective actions.
Limitations
- Correlated signals can mislead. Missing telemetry, several contributing causes, and hindsight bias limit certainty.
Practical pattern
Define the impact, assemble a timeline, compare affected and unaffected cohorts, and test competing explanations. Document uncertainty and validate corrective actions.
Supported by
Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.
- Grafana with Tempo and Loki — Linked logs and spans support manual investigation; they do not prove causation.
- Datadog — Version comparisons supply evidence for a release-related hypothesis.
Related concepts
Investigation patterns
- Metrics to Traces
- Alerts to Incidents
- Services to Dependencies
- Infrastructure to Applications
- Trace to Profiles
- Service to Database
- Queue Producer to Consumer
Related guides
FAQ
Can correlation prove a root cause?
No. Establish a plausible mechanism, test alternatives, and use controlled comparisons or reproducible evidence where possible.