Structural and Behavioral Patterns for Diagnostics, Anomaly Detection, Forensics, Prognostics, Root Cause Analysis, Debugging

Our tools are only as good as our pattern language.

Analysis patterns for the quality of software diagnostics and observability in endpoint devices, enterprise and cloud environments, AI/ML systems and agentic AI.

Diagnostics Science

Diagnostics is the mother of problem solving.

All areas of human activity involve the use of diagnostics. Proper diagnostics identifies the right problems to solve. We are now a part of a non-profit organization dedicated to the developing and promoting the application of such diagnostics: systemic and pattern-oriented (pattern-driven and pattern-based).

Codesign: Between Code and Design

Codesign with LLMs and the Software Codesigner Profession

PDF: https://www.dumpanalysis.org/files/Codesign_Between_Code_and_Design-Vers...

I now rarely code explicitly and spend much more time on design. I use Codesign to describe this activity between code and design, nearer the design side. Coding assistants produce much of the source text, while I develop requirements, examine proposed implementations, and decide what evidence would support their acceptance.

History of Diagnostics, Observability, and Debugging in Social Sciences

Social evidence and the examination of explanations

PDF: https://www.dumpanalysis.org/files/History_of_Diagnostics_Observability_...

Let us consider a social indicator that appears to improve. The change may come from different behavior, a revised recording procedure, or a new definition of success. Before explaining the result, we need to examine how the evidence was produced.

History of Diagnostics, Observability, and Debugging in Natural Sciences

From recorded observations and laboratory experiments to distributed observatories and computational evidence

PDF: https://www.dumpanalysis.org/files/History_of_Diagnostics_Observability_...

Mathematical Concepts in Software Diagnostics and Software Data Analysis


This book was AI-synthesized from our catalog of mathematical concepts used in memory dump analysis and trace and log analysis.

Applied Set Theory: Foundations and Practice for Computing, Data, and Engineering

This pocket-size book introduces set theory and its applications to computing, data, and engineering. We start with basic concepts such as membership, equality, subsets, relations, and functions. We then consider equivalence, order, cardinality, induction, and recursion. We also discuss infinite sets and the axioms of set theory, along with their consequences for representation and computation.

Category Theory for Software Diagnostics, Observability, and Debugging

This book is AI-synthesized from our published work, including bits and pieces of CT applied to software diagnostics and debugging from 10-15 years ago: https://www.dumpanalysis.org/files/Category_Theory_for_Software_Diagnost... (ISBN-13: 978-1919135014).

Optimization in Software Diagnostics and Observability


AI-synthesized from our published books, Optimization in Software Diagnostics, Observability, Memory Dump Analysis, Trace and Log Analysis, and Debugging: An Evidence-Governed Framework for Better Diagnostic Decisions, is included in the AI-created Optimization Across Disciplines: A Transdisciplinary Field Guide to Better Choices, Designs, Systems, and Works book (ISBN-13: 978-1919135007).

History of Technical Diagnostics, Observability, and Debugging

From proof testing, strain measurement, and failure analysis to nondestructive evaluation, structural health monitoring, digital twins, and AI-assisted prognosis

PDF: https://www.dumpanalysis.org/files/History_of_Technical_Diagnostics_Obse...

History of ML and AI Diagnostics, Observability, and Debugging

From residuals, validation sets, and reasoning traces to model monitoring, mechanistic interpretability, foundation-model evaluation, and agentic observability

PDF: https://www.dumpanalysis.org/files/History_of_ML_and_AI_Diagnostics_Obse...

History of Medical Diagnostics, Observability, and Debugging

From bedside signs, pulse, and urine inspection to laboratory medicine, medical imaging, molecular testing, continuous monitoring, and AI-assisted diagnosis

PDF: https://www.dumpanalysis.org/files/History_of_Medical_Diagnostics_Observ...

History of Hardware Diagnostics, Observability, and Debugging

From sensory inspection, checking circuits, and test points to built-in self-test, remote management, digital twins, and AI-assisted fault isolation

PDF: https://www.dumpanalysis.org/files/History_of_Hardware_Diagnostics_Obser...

History of Software Diagnostics, Observability, and Debugging

From machine fault finding and post-mortem dumps to distributed telemetry, time-travel debugging, and AI-assisted root-cause analysis

PDF: https://www.dumpanalysis.org/files/History_of_Software_Diagnostics_Obser...

Twenty-One Grammars of Diagnostic Evidence

Memory Dumps, Traces, and Logs through Chinese, Korean, Japanese, Arabic, Sanskrit, Russian, German, Irish, French, Classical Greek, Latin, Southern Quechua, Swahili, Turkish, Māori, Cherokee, Tibetan, Tamil, Ancient Egyptian, Basque, and Udmurt

PDF: https://www.dumpanalysis.org/files/Twenty-One-Grammars-Diagnostic-Eviden...

Seven-Layer Observability Design Model: Based on an OSI Analogy

The Seven-Layer Observability Design Model is a conceptual framework for designing observability in modern software systems, modeled on the OSI networking model. It does not claim that observability literally has the same layers as networking. Instead, it uses the OSI-style layered thinking to separate concerns, clarify responsibilities, and make observability systems easier to reason about, build, debug, and evolve.

Layer 1: Signal Source Layer - the lowest layer of the model. It corresponds to where observable events originate.
Layer 2: Instrumentation Layer - turns raw system behavior into explicit observability signals.
Layer 3: Collection Layer - gathers observability signals from different sources.
Layer 4: Transport Layer - moves observability data from collectors to processing and storage systems.
Layer 5: Storage and Representation Layer - stores observability data in forms suitable for retrieval, querying, correlation, and analysis.
Layer 6: Correlation and Context Layer - connects isolated signals into meaningful diagnostic structures.
Layer 7: Interpretation and Action Layer - converts observability data into understanding and response.
Meta-observability: Observability of Observability - A production observability stack should itself be observable across the same seven layers.

Training: Advanced Linux Core Dump Analysis with Data Structures and Generative AI

Software Diagnostics Services organizes this online training course.


Learn how to navigate the process and kernel core memory dump space, and use Linux data structures to diagnose, troubleshoot, and debug complex software incidents. The training uses a unique, innovative pattern-oriented analysis approach to accelerate learning. It consists of practical step-by-step exercises using GDB and the Linux kernel crash utility. Additional topics include kernel structures navigation, practical scripting, kernel modules, drivers, and files. The training builds on the bestselling Accelerated Linux Core Dump Analysis and includes a crash course in essential C for the Linux kernel and a relevant Unified Modeling Language tutorial. The course also covers Generative AI to aid and automate core dump analysis and visualization.

Preview Slides

To avoid repeating some topics and save time, the training includes the Accelerated Linux Core Dump Analysis PDF book.

You get:

Prerequisites:

Basic and intermediate level Linux core dump analysis: the ability to list tasks, threads, libraries, modules, apply symbols, walk through backtraces and raw stack data, diagnose patterns such as heap corruption, CPU spike, memory leaks, segmentation faults, wait chains, and deadlocks. If you are not comfortable with the prerequisites, Accelerated Linux Core Dump Analysis training or the corresponding book (included) is recommended before attending this training.

Audience:

Software technical support and escalation engineers, cloud engineers, DevOps and DevSecOps, site reliability engineers, system administrators, security researchers, reverse engineers, malware and memory forensics analysts, software developers, and quality assurance engineers.

Syndicate content