At this point, you should have discovered what the problem is and how it manifested based on the following issues:
- Service outage/inaccessible
- Slow service
- Logging issues
- Dropped sessions
- Data corruption
The next step is to find the cause of the problem, for example:
- Cabling problems
- Connectivity between an Access Layer switch and a Distribution Layer switch, either in the server room or in the wiring closet
- DoS attack on a system (e.g., router, switch, or server)
- Software issue (user misconfiguration or user adding some type of application)
- IP addressing issue (DHCP problem)
You should ask everyone involved in the incident what the last change in the system was and try to obtain details on this. In this troubleshooting phase, you should consider every possible cause but you should put them in order (based on the symptoms) and start with the most obvious things first. In the end, you will know exactly what you should test to solve the particular issue.