I am curious about how people are managing accuracy with incidents.
With manual creation of incidents, during the creation of those incidents you may not have all the details of exactly when an outage has occurred. Only after things are restored and teams review logs they can determine the actual down time.
For example:
- 12:25am - person on call gets alert and starts doing initial triage
- 12:30am - person creates Statuspage incident specifying major outage.
- 12:35am - person begins restoration process
- 1:15am - person completes sanity tests to ensure service has been restored and updates the Statuspage incident specifying service has been restored.
According to incident creation & resolution, the downtime is calculated as 45 minutes (12:30am to 1:15am)
That said, after looking at the logs, we find that the service outage really started at 12:15am and that the servers were fully functional at 12:45am (which was when sanity testing started)
According to the logs, the downtime was actually 30 minutes.
Do you go back and edit the incident either by editing the incident times or do update the down time directly on the component uptime history? Are there other options?
Thanks in advance!