MULTI-SOURCE INVESTIGATION

Follow the evidence.
Find the thread.

Explore logs, events, and time-series observability data across your Elasticsearch and ClickHouse sources. Investigate incidents with AI and evidence you can inspect.

Open source · Bring your own data · Choose your AI provider

THE IDEA

One place to move from a signal to its supporting records.

Operational evidence is spread across indices, tables, and services. InvestiGenie gives teams a shared way to explore logs, events, and metric-like time-series records, inspect matching data, and ask focused questions without handing a model unrestricted access to a data system.

A CLEAR PATH THROUGH THE DATA

Connect. Explore. Investigate.

01 — 03
01

Connect your sources

Add Elasticsearch or ClickHouse connections. Credentials stay on the server and are encrypted in storage.

SOURCES
02

Explore the records

Use saved Data Views, time windows, source-side sorting, histograms, and cursor-based paging to inspect results.

DISCOVER
03

Investigate a question

Choose Data Views and a saved AI profile. The server validates structured filters, scans in batches, and returns findings with cited record IDs and scope.

EVIDENCE

BUILT AROUND INSPECTION

Useful answers should come with a trail.

Queries stay bounded

AI proposes structured filters. InvestiGenie validates them and builds source queries; arbitrary model SQL is not accepted.

Evidence stays inspectable

Results include source scope, record references, confidence, and caveats. Explore remains available for checking the underlying data.

Investigations span batches

Matching records are scanned sequentially and compacted into bounded analysis cycles. More distinct evidence can mean more provider calls.

A NOTE ON TRUST

Evidence is still data.

The question and selected source examples are sent to the configured AI provider. Connection credentials are not. Review your provider’s retention and processing terms before using sensitive data. InvestiGenie does not yet include built-in user authentication or authorization; put it behind a trusted authenticated gateway.

INVESTIGATE WITH CONTEXT

Start with the data you have.

Visit GitHub