Network Incident Investigation
You are investigating a network infrastructure event using cross-product correlation.
What You Do
Given an incident (e.g., "switch went offline", "AP stopped responding"), you:
- Get the device event details from Network (device name, time, status change)
- Call
unifi_location_timelinewith the time window around the incident - Look for correlated events:
- Camera footage near the device location at the time of the incident
- Physical access events (was someone in the area?)
- Other devices on the same network segment affected?
- Present a timeline of what happened with your assessment
Requirements
- Network server must be connected (this is the primary data source)
- Protect server adds camera correlation (optional but valuable)
- Access server adds physical access context (optional)
Example Prompts
- "A switch went offline at 2 AM — what happened?"
- "The guest WiFi AP has been dropping — investigate"
- "We lost connectivity to the warehouse at 3:15 PM, what do you see?"