Docs: What changed?
Documentation / Query & analyse

What changed?

Compare an incident period with a normal period to see which log patterns, latencies and field values moved, without reading raw logs.

What changed? compares a period when something went wrong (the incident) with a period when things were normal (the baseline). It shows what differed: log patterns that appeared, disappeared or changed rate, latency percentile shifts, and changes in field values. It works from OBSESC’s summaries, so it returns quickly without scanning your raw data.

When to use it

  • An alert fired or a chart spiked, and you want to know which log lines are new or more frequent.
  • A deploy went out and you want to compare the hour after with the same hour the day before.
  • You are writing a post-incident review and need a list of what moved, ranked by size.

Running a comparison

You can open What changed? from an incident’s What changed tab, or from the Compare view reached from a chart, search result or service.

  1. Choose the Service to compare.
  2. Set the Comparison period: the time you want to explain.
  3. Set the Baseline period. Shortcuts include Same time yesterday, Same time last week and Previous equal window. The two periods do not need to be the same length.

Each period has a maximum length. The console tells you if a period is too long.

Rates, not counts

A one-hour incident compared with a seven-day baseline would make almost everything look higher on volume alone. So OBSESC compares rates rather than raw counts. By default, each count is shown as a share of all events in its period. Turn on Rates per second when you care about absolute frequency, such as “errors per second doubled”.

Reading the results

SectionWhat it shows
Log templatesLog patterns that are new, vanished or changed between the two periods, ranked by the size of the change.
Numeric fieldsp50, p95 and p99 for each numeric field in both periods, and how they moved.
Fields: value mixFor each field, which values became more or less common, such as one region or status.
Distinct values per fieldHow the number of distinct values changed, for example “distinct user_id fell by 80%”.

Read any notes shown with the result. They explain anything you should take into account.

A typical first read:

  1. Look at new log patterns first. A new error pattern is often the answer on its own.
  2. Check the numeric fields for the latency you care about.
  3. In the value mix, look for a single value (one host, one region, one version) that carries most of the change.
  4. Take the pattern you found and read the actual lines with Search or SQL.

Accuracy

  • Some figures, such as distinct counts and percentiles, are close estimates. Use SQL when you need an exact figure.
  • You can run a comparison while an incident is still happening, but the most recent minutes may not be included yet. See Navigation tier.

See The map and the territory for how OBSESC’s summaries relate to your raw data.