What changed before an incident
what_changedCompares an incident window against the equal preceding baseline to reveal changes in exceptions, network, jank, logs, and memory, with directional evidence for each dimension.
Instructions
Evidence from the window leading up to a failure, plus a baseline comparison: the incident window measured against the equal window before it, per dimension (exceptions, network volume/failures/latency p50/p95, jank ratio, log errors, memory) with directions new/spiked/increased/decreased and citable evidence. Anchors on the given eventId, or the most recent exception, or the current time. Network uses interval matching, so a request that started before the window but failed inside it still counts. When the baseline predates observation, directions are unknown rather than fabricated.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| eventId | No | Anchor on this event (e.g. 'exc_00142'). Defaults to the most recent exception. | |
| windowMs | No | How far back to look, in milliseconds. |