Monitoring & Alerts
Paste alerts, metric snapshots, log excerpts, or ticket text into your AI session. Damira correlates them and gives you a ranked diagnosis with the exact commands to run next.
Damira reads what you paste. It doesn't connect to your monitoring stack. Copy what your tools are showing — an alert, a PromQL result, a Grafana panel value, a Loki or syslog excerpt, an incident ticket — into your Cursor or Claude Code session and ask what's going on.
Damira doesn't need credentials to your monitoring systems and can't reach them, so nothing leaves your network unless you paste it.
What Damira does with it
- Correlates the evidence. It lines up timestamps, devices, and interfaces across your alerts, metrics, and logs, and separates the cause from the symptoms.
- Matches it to vendor knowledge. It links log messages and counters to the platform's documented behavior, known bugs for your release, and relevant CVEs.
- Runs a structured diagnosis. You get a ranked list of likely causes, each with the exact
showcommands that confirm or rule it out. Damira recommends the commands and you run them. - Drafts the write-up. Once you know the cause, your AI can write the incident report or the ServiceNow-ready fields (category, priority, affected CI, impact, and resolution notes) for you to paste into the ticket.
What to paste
| Source | What to copy |
|---|---|
| Alerts | Alert name, labels, severity, and when it started firing |
| Metrics | The PromQL query and its result, or a Grafana panel's values over the incident window |
| Logs | Loki query results or raw syslog lines, with timestamps, from a few minutes before the first alert |
| Tickets | The incident description, affected service, and what the reporter saw |
| Device output | Any show output you've already collected |
Include the platform and software version if you know them. Damira's advice is version-specific.
Scrub before you paste. Remove passwords, SNMP communities, keys, and customer names. See Security for how Damira redacts what it receives.
Example prompts
A firing alert
A metric snapshot
Logs around the event
An incident ticket, then the write-up
For the last step, your AI writes the incident report or ticket fields from the diagnosis. Damira supplies the facts and your AI assembles the document. See Documents.
Tips
- Paste the raw output. Unedited alert labels and log lines carry the timestamps and identifiers Damira correlates on.
- Give it a time window. Logs from a few minutes before the first alert usually hold the cause. The alert itself is often a symptom.
- Keep the session going. Paste the output of the commands Damira suggests back into the same session. Each round narrows the diagnosis.
Related
- Troubleshooting: how the structured diagnosis works
- Documents: incident reports, MOPs, and change controls
- Security: what happens to what you paste