Lessons · IT support · ask what changed
What changed? The question that finds half of all faults
A machine that worked yesterday and not today has had something change in between: an update, a move, a new program, a new cable, a new password, a new setting. Find the change and you have usually found the cause.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
'My accounting software will not open' arrives on Tuesday. Twenty minutes of reinstalling later, somebody mentions the overnight update. The update had renamed a folder. The question 'what happened between the last time it worked and now' would have taken thirty seconds and pointed straight at it.
How to think about it
Ask when it last worked, then what happened between then and now, and listen for anything at all: updates, a restart, a move, new software, a plugged-in device, a changed password, somebody else using it. Then check what the user would not know to mention: the update history and the recently installed list. The most recent change is the first suspect, and undoing it is the first test.
Worked example
Last worked: Monday 17:00. Failed: Tuesday 08:30The window. Whatever did it happened in those fifteen hours.
User says: 'nothing changed'Everybody says this. It means nothing they noticed changed.
Update history: a system update installed Monday 22:14Something changed, in the window, that the user could not have seen.
Undo the update on one machine, test: the program opensThe change was the cause. Now the fix is a decision, not a guess.
Your turn
Write the first question to ask about a machine that worked yesterday and does not today.
'When did it work?'
Solve one, graded on the server
The trap
Taking 'nothing changed' as a fact. It is a report of what the user noticed. Updates, policy pushes and the cleaners moving a desk are all changes nobody noticed.