Engineer calmly working through terminal session during Linux incident response — AV Services Mumbai, onsite within 2-4 hours

What Happens Between “Server Down” and “Server Back Up”

AV Services · avservices.in · Mumbai, India

Most businesses find a sysadmin when something breaks. Retainer clients already have one. The difference shows in the first 5 minutes.

2hr
Onsite response
within Mumbai
4hr
Remote response
anywhere in India
24hr
Written RCA
after every incident
25+
Years managing
Linux infrastructure

This page covers the process , how an incident gets diagnosed, contained, resolved, and prevented from recurring. If your server is down right now and you need someone on the phone, go to Linux Emergency Response.


The First 5 Minutes

The shape of an incident is decided before most people have finished typing the first message. A specialist who has been monitoring your server for months can eliminate 6 of 10 possible causes immediately , because they know your stack, your history, and what changed in the last patch window.

That context is what separates a 45-minute resolution from a 4-hour one.

Linux incident response workflow diagram showing 7 steps: alert triggered, arun notified within 2 hours, system diagnostics, root cause analysis, fix applied, verification, and incident report

During the Incident

No tickets. No acknowledgement queues. The moment you reach out , WhatsApp, phone, email , the response begins.

You get updates at regular intervals: what has been investigated, what has been ruled out, current best estimate on resolution. Plain language. No jargon.

If remote diagnosis is insufficient , hardware failure, physical access needed , onsite response is available within 2 hours in Mumbai, 24 hours nationwide.

Incident escalation and response protocol diagram showing severity assessment branching into low/medium and high/critical paths with different response times and actions

The Written Record

Within 24 hours of resolution, every retainer client receives a written root-cause analysis.

This goes into the server’s permanent documentation. The next engineer who touches the server , Arun, Krishna, Sanjay, or anyone else , inherits the full history.


The Incidents That Don’t Happen

The most useful incident response number for any AV Services client is zero.

Monthly patching, continuous monitoring, log analysis, backup verification, security reviews , these remove the conditions that produce most production incidents. The retainer model is built around making proactive management routine so incident response stays rare.

See failures prevented since 1999 and how downtime gets prevented on managed Linux infrastructure.


The Saturday Night Call

A real incident. Nobody was watching the server. What happened next, and what it cost.

Read the Incident →

What the Retainer Covers

Incident response under a retainer is not a separate billable event. It is included. The response time commitment , 2-hour onsite Mumbai, 4-hour remote , is in the service agreement, not subject to capacity or availability at the time of the incident.

Non-retainer emergency response is available subject to current capacity. Response time is best-effort. See pricing for retainer tiers, or the full incident response SLA.


Service Continuity

Arun handles all managed infrastructure directly. For hardware emergencies requiring physical presence, Krishna and Sanjay are available as backup cover in Mumbai. Every server has documented handoff notes. Response is never dependent on a single person’s memory.

If your requirement is a 24/7 NOC with rotating staff backed by a 50-person team, AV Services is not the right fit and will say so plainly. If your requirement is a senior specialist who knows your infrastructure deeply, responds fast, and has a documented backup plan , that is exactly what is on offer.


How incident response works: the actual stack

Monitoring

Observium for network and server monitoring. Nagios for service checks and alerting. Cockpit for real-time server visibility. Alerts fire before users notice.

Incident tracking

Dolibarr ticketing module for incident logging and history. Every incident logged with timestamp, root cause, resolution, and prevention action.

Documentation

Per-client plain text config documentation and wiki. Every server history, configuration, and known issues documented.

Post-incident

Written root-cause analysis within 24 hours of resolution. Plain English. What failed, why it failed, what was fixed, what prevents recurrence.

Ready to hand this over?

AV Services manages this for Mumbai businesses on monthly retainer since 1999. Start with a free 30-minute call.

⚡ Check Your Risk Book Free Audit Emergency Response Data Recovery ?

Are Your Cron Jobs Actually Running?

Most businesses assume their scheduled jobs are running. Most have never checked. Here is exactly how to verify cron job execution on a Linux server.

Read: How to Check Cron Jobs →