finding patterns

Five questions your notes can answer once they have dates.

How often, alongside what, since when, moving which way, and what you quietly stopped doing.

Search answers one question, and it answers it well: where did I write this word. That is genuinely useful and it is not usually the question you have. The questions people actually arrive with are about rate, company, onset, direction, and absence, and none of those are string matches.

All five become answerable once entries are dated and the things in them have names. Here they are in the order they tend to come up, with what each one looks like when a few months of notes exist behind it.

1. How often does this actually come up.

The impression you carry around is not reliable. Something that ruined two consecutive Fridays feels constant, and something that quietly interrupts you every ten days feels rare, because interruption is memorable and frequency is not.

lessmore
Entries mentioning the checkout tag, by month
MonthDays with an entryMentions of #checkout
April182
May213
June199
July2214
August2016
The heatmap shows writing activity across a year, one square per day. The table below it carries the number that matters: mentions of #checkout went from 2 in April to 16 in August while the number of days written stayed flat at around 20. The rate is climbing, and the flat denominator is what rules out "you just wrote more".

The denominator is the part people skip. A count of mentions rising is meaningless if you also started writing three times as often, so any honest answer to "how often" needs the number of entries beside it.

2. What shows up alongside it.

Two things that keep appearing in the same entry are related in some way, and often in a way nobody wrote down explicitly. This is the question that finds the connection you did not know you had made.

TICK-184212
vpn.internal.example9
INC-90215
@dana4
REQ-03082
Things appearing in the same entry as the checkout tag
Appears alongside #checkoutShared entries
TICK-184212
vpn.internal.example9
INC-90215
@dana4
REQ-03082
Of the 44 entries mentioning #checkout, nine also mention the vpn.internal.example host. That host is not named in the checkout ticket anywhere, and the overlap is the only place the two are connected in writing.

Read that carefully, because it is easy to over-read. The overlap says the two things were on your mind at the same time on nine days. It does not say one caused the other. What it does reliably is tell you where to look, which is worth a great deal when the alternative is remembering.

3. When did this start.

The onset question is the one that arrives during a postmortem, phrased as "how long has this been going on", and it is the question a ticket system answers worst, because the ticket was opened when somebody finally escalated rather than when the problem began.

02/07/2026
First mention, one line at the end of a long entry: vpn.internal.example dropped twice this afternoon, no ticket raised
11/07/2026
Workaround shipped and written into the on-call runbook, still no ticket
19/07/2026
Escalated as TICK-1842 after it hit #checkout latency
04/08/2026
Recurred under a new reference, INC-9021
The ticket system dates this problem to 19 July. The notes date it to 2 July, seventeen days earlier, in a single line nobody thought was significant at the time. Two of the four events on this timeline never had a ticket at all.

The seventeen days are the entire value of keeping the log. They exist because somebody wrote one sentence on a day when it did not seem to matter, and because that sentence contained the hostname rather than "the tunnel".

4. Is the number moving.

A measurement written into an entry is worth more than the entry it sits in, because measurements accumulate into a series. One reading tells you the state on a Tuesday. Thirty readings tell you a direction, and a direction is what supports an argument.

480 ms · p95, most recent reading
Eleven p95 readings pulled out of eleven ordinary entries, in the order they were written: 195, 230, 180, 310, 275, 365, 320, 425, 385, 470, 480 milliseconds. The line wanders, and it has still roughly doubled. No single entry says "this is getting worse", because on any given day it did not look that way.

Note what the chart is made of. Nobody opened a metrics tool or filled in a tracking spreadsheet. Eleven people-shaped sentences happened to contain a number and a unit, and the series was read back out of them afterwards.

5. What did you quietly stop doing.

This is the one nobody asks, because you cannot search for an absence. Search needs a term and the whole point is that the term stopped appearing. It is also the question that most often changes somebody's mind about their own year.

Recurring subjects that stopped appearing in entries
SubjectEntries in the first halfEntries in the second halfLast seen
REQ-0308 and its follow-ups23014/03/2026
#onboarding17228/05/2026
@dana31419/07/2026
#checkout539ongoing

Three of those four rows are things that fell off without a decision being made about them. Some of that is healthy, because work finishes. Some of it is a project that quietly lost its owner, or a person you have stopped talking to, and both of those are worth knowing before somebody else notices.

What none of this gives you.

Every answer above is bounded by what you wrote. The frequency counts are counts of mentions, not of occurrences, so a problem you stopped bothering to write about will look like a problem that stopped. That is a real blind spot and it points the wrong way, because the things you stop writing about are often the things you have given up on rather than the things you fixed.

Co-occurrence is correlation and nothing more. Two names sharing nine entries can mean one caused the other, or that both were symptoms of a third thing, or that they happen to occupy the same afternoon of your week. Treat the overlap as somewhere to look rather than as a finding.

And all five questions need the names to be in the prose. If your entries say "the usual problem", every chart on this page is empty. Naming things as you write is the habit the whole thing rests on, and the first article below is about how to build it.

Keep reading.

blk/txt reads log files you already keep and makes them searchable by date, reference, and tag. The FAQ covers accounts and privacy, and the trial runs on text you have already written, with no account to make first.