What problem does it solve? Diagnosing why an Azure VM rebooted, failed to boot, lost SSH/RDP connectivity, or crashed requires reading scattered guest OS logs, event logs, SAP traces, and packet captures — a slow, error-prone manual process. This Skill applies a senior CSS engineer's mental model to pinpoint root causes from log evidence. ## Core Features & Use Cases - Multi-domain log analysis: Covers Linux syslog/dmesg/journal/waagent/cloud-init, Windows Event Logs/CBS/BSOD bugchecks, SAP HANA/NetWeaver/HSR/Pacemaker traces, and pcap/pcapng network captures. - Format detection and triage: Recognizes sosreport, supportconfig, Inspect IaaS Disk (IID) packages, serial console logs, and engineer pre-analysis files, then routes to the highest-signal log first. - Evidence-based RCA: Builds UTC timelines, correlates events across OS/middleware/app layers, and distinguishes guest-side vs platform-side root causes with verbatim log citations. - Use Case: A customer reports their Linux VM rebooted unexpectedly. Provide the case folder path; the Skill detects the IID package and console log, anchors the reboot timestamp, finds hv_utils: Shutdown request received, and determines whether the shutdown was customer-initiated or platform-driven. ## Quick Start Analyze the logs in my case folder to find out why my Azure VM rebooted unexpectedly yesterday around 14:00 UTC.