Definition

Events record discrete operational occurrences, such as restarts, configuration changes, failovers, and rollouts.

Question it answers

Which changes or lifecycle transitions occurred near the start of the incident?

Role in an investigation

Build a timeline using occurrence time and affected resources. Compare events with telemetry for the same service and environment. A change occurring before errors is a candidate explanation that still needs a plausible mechanism and independent evidence.

Correlation fields

Fields that make the connection possible
Field or dimensionPurpose
occurred_at and observed_atPreserve event ordering and account for delayed delivery.
event ID and change typeDistinguish one occurrence from repeated notifications.
service, environment, and resource identityLimit comparison to systems affected by the occurrence.

Compare a restart with error onset

A database failover event precedes a short checkout error spike. Connection failures in application logs and recovery after reconnection strengthen the failover hypothesis. A timestamp marker alone would not explain the failure path.

Limitations

  • Events can arrive late or use clocks that disagree with application hosts.
  • One change may affect several resources; missing scope makes comparison ambiguous.
  • Repeated delivery can create multiple records of one occurrence.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

  • Grafana — Annotations display events alongside metric time series.

Investigation patterns

Related concepts

Related guides

FAQ

Are deployment events enough for release analysis?

They establish a timeline. Version attributes and affected cohorts are needed to connect a rollout to specific traffic.