An incident log read as an inventory rather than as history

Three years of incident notes had been written for the record and never read as a data set.

the questions it answered in an afternoon:

  what breaks most?         deploys, by a distance
  what takes longest to
    resolve?                third-party outages, and
                            there is nothing to do
  what recurred after a
    fix?                    two things, both
                            configuration drift
  what did we never write
    down?                   the 03:00 ones. every
                            incident before 06:00 has
                            a shorter note.

The last finding is the one worth acting on: the notes written at three in the morning are the shortest and describe the incidents most likely to recur. A template with four required fields, filled in the following morning rather than during, made the recent ones usable — and the historical ones stay thin, which is a permanent gap in the data.