Bring agentic IT diagnostics to your service desk.
An invitation-only program for MSPs to work with us on a data layer for AI so engineers can close hard tickets in minutes, not hours. Built alongside the engineers who actually use it.
The situation
The MSP business problem.
Modern MSPs are squeezed from three directions at once. Today's AI tools help with the easy tickets, not the hard ones that consume precious senior engineer time.
Rising expectations
Clients expect fast resolution, or proactive detection before they ever feel the impact. SLAs keep tightening. Compliance bars keep rising.
Sprawling environments
Endpoints, cloud, SaaS, network appliances. More layers to break, more places to investigate, more vendor portals to log into.
Engineer scarcity
Senior techs are hard to hire and harder to keep. Repetitive diagnostic work is what burns them out fastest.
The shape of the work
How an MSP service desk works today.
Easy tickets flow smoothly. The hard ones bottleneck on senior engineers doing manual archaeology: hours per ticket, one machine at a time.
entry
dispatch
resolve
escalation
senior eng.
escalation
→Manual diagnosis, ticket by ticket
Remote in. Read logs by hand. Tail perf counters. Compare to last week from memory. Hop to switch & storage. Hours per hard ticket.
⚠Signals fragmented & ad-hoc
Event logs, vendor portals, RMM. One machine at a time, one logfile at a time. No unified view across a client, let alone a book of clients.
Text-data tasks
- Categorize and route tickets
- Suggest fixes from past tickets
- Surface KB articles & runbooks
System-state tasks
- Diagnose a hard, escalated ticket
- Identify the root cause of an outage
- Pinpoint what changed and when
What we're building
SparkLogs fills the gap.
Give AI agents eyes into every client system, current and historical, so it can do the gathering and structuring work, while your engineers make every consequential decision.
Client systems ship signals
Endpoints, servers, cloud, across every client in your book.
- Lightweight Windows agent
- Deploys via your RMM (MSI)
- Outbound HTTPS only · no kernel driver
SparkLogs cloud
Per-client logs and structured system state, aggregated with strict multi-tenant isolation.
- Read-only MCP server
- Token-efficient query tools
- Every claim cites verifiable evidence
MSP AI agent
Runs inside the AI tool your engineers already use.
- Claude Code, Cursor, Copilot, Codex, Gemini
- Skills for investigation and root-cause analysis
- Engineers still make every action decision
Auto-diagnose
Performs the initial diagnostic steps a senior engineer normally does by hand.
Suggest causes
Returns likely root causes with confidence ratings and cited evidence. Not guesses.
Interactive partner
Answers follow-up questions and goes deeper as the engineer investigates.
Before vs. after
Same ticket. 12× faster.
One real-life example. The senior engineer's judgment still drives every decision. They just aren't burning an hour on data collection and reading logs.
Manual today
- Remote into the file server.
- Pull and tail Windows event logs by hand.
- Check perf counters: CPU, disk, network.
- Compare today’s metrics to last week from memory.
- Hop to switch & storage to rule out the network.
- Manually review scheduled jobs and installed software.
- Write up findings and a likely cause.
With SparkLogs + AI
- Agent queries SparkLogs across server + network.
- Agent has SparkLogs diff current state vs. the last-known-good baseline.
- Returns likely cause: backup job overlapping with business hours (84% confidence, cited).
- Engineer asks: "Show me the top 5 IO waits since 8:30"
- Engineer confirms cause and reschedules the backup job.
Six properties, designed together
What we're actually building.
None of these are optional. The platform is only useful for MSP diagnosis if every one of them holds.
Managed agent
Lightweight Windows agent deploys via your RMM. No kernel driver, no remote-execute, outbound HTTPS only.
Captures system health
Software inventory, processes, services, drivers, certs, network state, performance. Not just logs.
Integrated with AI hosts (MCP)
Plugs into Claude Code, Cursor, Copilot, Codex via MCP. Engineer brings their own AI tool of choice.
Read-only by design
The AI queries data. The agent never executes on the endpoint. Your engineer keeps every action decision.
Every claim cited
Each finding links to a verifiable evidence URL one click away. Hypotheses are a separate, opt-in step.
Audit-ready
Every investigation produces a complete audit trail. Service managers review patterns; auditors trace evidence.
Honest scope
Where we are today.
We'd rather ship a narrow product done well than a broad one done poorly. Here's what's live, what's building now in the Foundry, and what's deliberately deferred.
The platform
- Petabyte-scale log management
- Multi-tenant by design: per-client orgs
- 5–10× lower cost than typical SIEMs
- Data in 5 regions: US, CA, EU, UK, AU
- 100s of data sources: HTTPS, syslog, OTLP, Elastic, Loki, OSS log shippers
- Schemaless ingest · search any age of data
- Archive to your own object storage
- HIPAA / PCI / SOX / FISMA-grade retention
The AI diagnostic layer
- Managed Windows agent (MSI · RMM-friendly · minimal system resources)
- Read-only MCP server with token-efficient querying
- /sparklogs-investigate
- /sparklogs-analyze-cause
- Cited findings · audit trail per investigation
- Claude Code primary; Cursor / Codex / Gemini / Copilot rolling in
Deferred on purpose
- macOS & Linux managed agents
- External data: M365, Azure, EDR, RMM APIs
- Proactive anomaly alerts + AI detective
- Cloud-based syslog ingestion
- Cross-host (Hyper-V / VMware) correlation
SparkLogs Foundry · Early access
Join the
Foundry.
Bring agentic IT diagnostics to your service desk, alongside the engineers who use them every day. Free SparkLogs usage, direct founder access, permanent Foundry Partner designation.

