Gathering the Evidence

The Scene of the Crime

Very seldom will you have the luxury of investigating a problem where the perpetrators are still on the scene of the crime. Most business systems must continue running whenever possible, and it is rare for the customer/user to be able to hold off on everything else while you are poking around in the database. You'll be lucky to even be able to get access to the system, much less have access to it by yourself. Most often, you'll need to reconstruct what happened from the user's reports, from the logfiles, and from operating system utilities.

Usually, you're really trying to do two things, fix the problem, getting the customer back online, and correct the problem, making sure that the problem doesn't ...

