Stripe webhook retries: what evidence belongs in the incident timeline?

I am drafting a reusable incident workflow for duplicate and out-of-order Stripe events. Which identifiers, delivery facts, and application decisions make a later investigation fast without logging sensitive payloads?

Include the event ID, endpoint, attempt number, received timestamp, object version, and local idempotency result. Explain why the application accepted, ignored, or deferred the event without retaining the full customer payload.