Definition

Root cause analysis investigates the mechanisms and contributing conditions behind an incident using evidence and tested hypotheses.

Signals

Why use it

Explain why a dependency slowdown caused user-facing failures and identify changes that prevent recurrence.

Common use cases

  • Reconstruct incident timelines
  • test release hypotheses
  • identify contributing dependencies.

Benefits

  • Turns incident evidence into specific corrective actions.

Limitations

  • Correlated signals can mislead. Missing telemetry, several contributing causes, and hindsight bias limit certainty.

Practical pattern

Define the impact, assemble a timeline, compare affected and unaffected cohorts, and test competing explanations. Document uncertainty and validate corrective actions.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

  • Grafana with Tempo and Loki — Linked logs and spans support manual investigation; they do not prove causation.
  • Datadog — Version comparisons supply evidence for a release-related hypothesis.

Related concepts

Investigation patterns

Related guides

FAQ

Can correlation prove a root cause?

No. Establish a plausible mechanism, test alternatives, and use controlled comparisons or reproducible evidence where possible.