Skip to main content
Coverage

Comprehensive data + curation and grading + AI = powerful insights

Explore how signals are curated into actionable insights and correlated with diagnostic themes and workloads. Watch example diagnostic sessions for common IT scenarios to see how AI analyzes curated data to deliver precise root-cause insights.

22feeds and topics
8ticket themes
227curated reasons
32graded conditions
4workloads covered
42intersecting areas
Workload lens
It crashed or hungCrashes and hangsDisk is full or failingStorage and filesystemBackups failingBackup and VSSPatch broke somethingPatching and servicingAccount compromisedSecurity and identityNetwork flakyNetworkWhy is this server slowPerformance and capacityWhat changed on this boxConfiguration drift
Windows event log feeds · curated event streams
System log1 channel · 75 curated reasons
Application log1 channel · 44 curated reasons
Security log1 channel · 60 curated reasons
Microsoft Defender2 channels · 13 curated reasons
App platform channels25 channels · 0 curated reasons · planned
Identity channels33 channels · 0 curated reasons · planned
Management channels42 channels · 0 curated reasons · planned
Network channels43 channels · 0 curated reasons · planned
Platform channels44 channels · 0 curated reasons · planned
Storage channels22 channels · 0 curated reasons · planned
PowerShell3 channels · 3 curated reasons
Device health topics, measured on the machine
System identityMachine identity and posture, including whether a reboot is pending.
DriversThe device drivers installed on the host, and what changes about them between reports.
PerformanceWhole-host CPU and memory posture over a measured window. · planned
ProcessesPer-process cost: CPU, working set, handles and sustained growth. · planned
ServicesService configuration and run state, including automatic services that are not running. · planned
curated today (# of signals)drawn on for this answercovers the chosen workloadcoming soonno signal yet
Connected to SparkLogs
Claude · Copilot · Codex · MCP
Answers name the sources they drew on.Connect your AI

Make IT problems die young

IT Fleet Intelligence
Ask your fleet anything
- what new failures are happening this week we haven't seen before?
- strange IO slowdowns after patch tuesday. why? who's affected?
- we just fixed VPN flakiness on the lakeview ts. anyone else affected?
- bob's account got hacked at 3:43pm. audit everything. impact?
Any question, any scope
One host, one client, or the whole fleet
Logs plus deep system state
CPU, RAM, IO and disk trends, projected forward. Snapshots plus instant deltas: services and VSS, BitLocker, leaks and blue screens, patch and servicing state, installs, event logs
Fleet-wide patterns before they become tickets
Spot issues emerging across clients from curated endpoint data
Agentic RCA · cited evidence
From question to root-cause and ticket-ready report
- ticket 7623 is off track. dig in and write it up
- backups failed on fs-02 three nights running. why?
- why is lakeview file server super slow every afternoon?
- why did dc-01 at northridge reboot at 2am last night?
/sparklogs-investigate writes the report
Your agent queries fleet evidence, follows what it finds, and returns a cited root-cause report in minutes
Works where you work
Claude, Microsoft Copilot, Cursor, Codex, or your own MCP agents
Open-source skills, cited reports
/sparklogs-investigate writes the ticket-ready report; click any claim to verify the evidence; then dive deep into likely root causes and fixes