The first step.
WHAT TO CAPTURE
Who is reporting How to contact them What exactly is happening When it started What is affected The exact error, where there is one Urgency and impact
WHY RECORD EVERYTHING
Because whoever picks it up next was not there.
WHAT TO LOG
Every request, including those resolved immediately.
WHY EVEN THOSE
Because unrecorded work is invisible, and recurring problems cannot be identified.
WHAT A GOOD SUMMARY LINE IS
Specific enough to identify the issue without opening it.
WHAT A POOR ONE IS
"Not working", "Problem", "Urgent".
WHAT TO CONFIRM TO THE USER
That it was received, with a reference.
WHY
It ends uncertainty, which is the main cause of chasing.
WHAT TO ESTABLISH AT LOGGING
Whether it is an incident, something broken, or a request for something new.
WHY THAT MATTERS
They follow different processes and different expectations.
WHAT TO AVOID
Logging after the fact, from memory Combining several unrelated issues in one record