Measure the queue, inspect a message, and decide whether a delivery retry is appropriate.
Confirm filesystem pressure, find the largest consumers, and check whether inode exhaustion is involved.
Find the process owning a local port and verify reachability from another host.
Inspect container state, resource pressure, logs, and configuration without restarting workloads.
Understand the working tree before discarding, restoring, or recovering changes.
Compare recursive and authoritative DNS answers before changing resolver or application configuration.
Separate CPU saturation, memory exhaustion, reclaim pressure, and a recent OOM kill.
Confirm device or process I/O pressure before blaming CPU, memory, or the application.
Find the critical boot chain, failed units, and kernel warnings without rebooting again.
Inspect failed units, dependency impact, and recent logs before attempting a restart.
Correlate service status and logs with host pressure before any restart or configuration edit.
Review identity, failed logins, and sudo audit evidence without changing accounts or policy.
Inspect SNI, certificate chain, expiry, and negotiated protocol before bypassing verification.
Separate DNS, connect, TLS, redirect, upstream, and application response time.
Measure loss across the path and correlate it with local interface errors.
Confirm the selected route, source address, gateway, and neighbor reachability.
Prove listener, route, and remote-port state before changing firewall policy.
Separate DNS, transport, host-key, client configuration, and authentication failures.
Inspect context, warning events, restarts, and resource pressure before changing a workload.
Confirm context, deployment images, rollout status, and warning events before rollback.
Separate public HTTP failure, local listener state, upstream reachability, and service logs.
Separate DNS, port, listener, authentication, and host resource failures without changing data.