AI root-cause analysis

For every incident Lemwatch correlates recent deploys, DNS diffs, cert changes, and upstream provider status pages to pinpoint the likely cause.

Quick answer

We cross-reference the incident timestamp with your last deploy, DNS diff, cert change, and upstream cloud provider status pages, then rank the top 3 causes by likelihood.

Signals correlated

Where to find it in Lemwatch

Incident detail → Likely cause. Each candidate has an evidence link.

How to fix

  1. Read the top-ranked cause and its evidence.
  2. If wrong, click "Not this" — the model learns per-org over time.
  3. When confirmed, click "Add to postmortem" to seed the incident report.

FAQ

What if it can't find a cause?

You'll see "No correlated changes in the last 60 minutes" — start with outage triage.

Does it access my server logs?

No — it uses only signals Lemwatch already collects.

Related