For a typical workday, how much time do L1 and L2 engineers usually spend testing, troubleshooting, identifying issues, performing root-cause analysis, and documenting their findings? Do they ever investigate application code deeply when necessary, or do they generally stay focused on infrastructure and standard procedures?
I'm preparing to apply for L1 and L2 support roles and freelance work. I'm building case studies that demonstrate how I investigate and document issues involving WordPress servers, Nginx, Apache, and OpenLiteSpeed. Is this a worthwhile way to build a technical portfolio, and what kinds of work should I emphasize?
4 Answers
L1 and L2 engineers should understand more than just infrastructure when the problem requires it. They may inspect application logs, web-server behavior, permissions, dependencies, database connectivity, and basic code or configuration, but they usually aren’t expected to develop major software changes. The important skill is knowing how far to investigate and when to escalate with evidence.
L2 generally handles more complex troubleshooting. They correlate logs and metrics, inspect configurations, reproduce failures, compare working and broken systems, apply controlled fixes, and may write scripts or queries to investigate further. They often identify the likely cause, but formal root-cause analysis and long-term corrective actions are commonly owned by L3, senior engineers, or the development team. L2 may still contribute heavily to the investigation and documentation.
Those case studies are a good portfolio idea. Make each one practical: describe the symptoms, scope and impact, your investigation steps, relevant commands or logs, the suspected root cause, the fix or workaround, validation after the change, and prevention recommendations. Be clear about whether it was a simulated lab, a personal project, or a real incident, and remove sensitive information. A few detailed cases are more convincing than a long list of technologies.
It varies a lot by company, product, and incident volume, so there isn’t a reliable percentage for every role. L1 usually follows documented procedures: gathering symptoms, checking dashboards and logs, reproducing basic problems, testing common fixes, recording what happened, and escalating with useful details when the issue is beyond their scope. They may spend a large part of the day troubleshooting, but not necessarily doing deep investigations.
L1 work is more than simply forwarding tickets. Good escalation notes include the timeline, affected systems, error messages, tests already performed, and the results of each test.

The boundary is not universal. In a smaller organization, an L2 engineer might perform the complete RCA, while in a larger operation L2 may stabilize the service and hand the deeper analysis to a specialist.