Skip to main content

Accelerate Root Cause Analysis and Incident Response with Change Detection

When users report outages, login failures, application issues, or unexpected behavior, identifying the root cause often requires technicians to manually compare settings across multiple systems and determine what changed.

Use LiongardIQ's change detection, timeline history, asset visibility, and AI-powered search capabilities to quickly identify configuration drift, correlate related changes, and accelerate root cause analysis.

Step 1: Start the Investigation in LiongardIQ

Open the PSA ticket generated by Liongard Actionable Alerts, or begin your investigation directly in LiongardIQ.

Use Global Search or AI-Enriched Search to quickly locate the affected user, device, server, application, or environment.

Examples:

  • "What changed on the accounting server yesterday?"

  • "Which users don't have MFA enabled?"

  • "Are there any backup failures today?"

This provides immediate context before beginning a deeper investigation.

Step 2: Review the Affected Asset or System

Navigate to the impacted Environment, Asset Inventory record, or Inspector.

Review relevant information such as:

  • User account status

  • Device information

  • Microsoft 365 licensing

  • MFA status

  • Backup coverage

  • Security controls

  • Related assets and dependencies

Use the centralized view to understand the complete operational context without switching between multiple tools.

Step 3: Investigate What Changed

Open the Inspector associated with the affected system and select Timeline.

Compare:

  • Today vs yesterday

  • Today vs the last known good state

  • Previous and current values

Look for:

  • Firewall rule changes

  • Policy modifications

  • Group membership changes

  • Configuration drift

  • System setting changes

Determine exactly what changed, when it changed, and whether the timing aligns with the reported issue.

Step 4: Correlate Related Changes

Review nearby timeline events and related systems to identify potential downstream impacts.

Investigate connected technologies such as:

  • Microsoft 365

  • Azure AD

  • Teams

  • SharePoint

  • Backup platforms

  • Endpoint management tools

  • Security platforms

Build a complete timeline of environmental changes to identify the most likely root cause.

Step 5: Validate with Historical Comparisons

Use LiongardIQ's side-by-side metric comparison capabilities to validate whether a meaningful configuration change occurred.

Review:

  • Latest values

  • Historical values

  • Date-to-date comparisons

Identify:

  • What changed

  • When it changed

  • Whether no configuration change occurred at all

This helps distinguish true configuration drift from unrelated incidents and reduces unnecessary escalations.

Step 6: Document Findings and Confirm Resolution

Add investigation findings, detected changes, timestamps, and remediation actions to the PSA ticket. Confirm whether the change was authorized or unexpected. After remediation, verify the corrected state appears in LiongardIQ following the next inspection cycle.

Why It Matters

  • Reduce time spent manually reconstructing incidents

  • Quickly answer "What changed?" without searching across multiple tools

  • Identify configuration drift before it causes prolonged outages

  • Accelerate root cause analysis with historical change visibility

  • Improve escalation workflows with evidence-backed investigations

  • Reduce mean time to resolution (MTTR)

  • Resolve incidents faster with complete operational context

When troubleshooting issues that "worked yesterday," LiongardIQ provides the historical evidence needed to move from assumptions to answers.

Did this answer your question?