See what needs attention.
Start with fleet activity, measured CPU and memory, or a daily AI summary. Pressure highlights the worst stretch in the selected window.
WINDOWS OBSERVABILITY, CONNECTED.
Your fleet is telling a story. Bring Windows events, server performance and IIS requests together to see what changed—and where to look next.
Events and measured performance. One shared view.
ONE PLATFORM. THE WHOLE PICTURE.
Move from a fleet-wide view to the event that matters. Every layer gives you a more useful next question.
Search Windows events and IIS requests together. Narrow by host, drill into message fields, and graph counts without losing your place.
AI THAT KEEPS THE EVIDENCE IN VIEW.
Start with a summary of what changed across your fleet. Investigate a host, scan selected events, or ask what a new event type might mean.
Measured figures sit beside the fleet summary. Saved analyses keep the context available for the next person who picks up the investigation.
LAST 24 HOURS · COMPARED WITH THE DAY BEFORE
WEB-SERVER-02 recorded more 5xx responses during a period of elevated CPU. Review the aligned host timeline to see which events occurred in the same window.
FROM OVERVIEW TO ANSWERS.
A connected workflow for the questions infrastructure teams ask every day.
Start with fleet activity, measured CPU and memory, or a daily AI summary. Pressure highlights the worst stretch in the selected window.
Open a host, line up its signals in time, and drill into the underlying events or requests. Filter, count and visualise the details.
Send a link to the exact search, time range, individual event or saved AI analysis so another team member can pick up where you left off.
A watchlist of 25 security event types, failed sign-ins and account lockouts—with guidance on what each event means and what to check.
Explore IIS status codes, response times and failing pages, then open the surrounding Windows events for the same host.
Trace event volume from hosts through software and providers to severity. See which components are driving the activity.
LATEST IN WINDOWS EVENTS.
Recent improvements connect major changes with identity context, surface unfamiliar events and reveal the files behind your data lake.
Line up service installs, software changes, restarts and account activity with interactive sign-ins. See the account Windows recorded, when available, and who signed in during the hour before.
Explore major events and sign-ins on a shared timeline, zoom into a period, and open the underlying records in Query. Review sign-in methods, source locations, admin accounts, failed sign-ins and lockouts. Recorded accounts and nearby sign-ins stay separate: presence alone does not establish responsibility.
See live table data, older data files, metadata and objects outside your tables. Understand the difference between catalog sizes and total bucket storage.
With the R2 bucket binding configured, a row per table shows where space goes. Older data files can be freed as the snapshots that reference them expire.
Distinguish event types that are new to the fleet from those that are new to an individual host, against at least 30 days of prior history.
Explore a 30-day strip, open events from the flow diagram, and request an AI explanation of new types, likely causes and suggested checks. Analyses can be saved and shared.
Explore a flow from hosts to software to severity. Include or exclude components, then drill into providers and their events.
Software is inferred from each event’s provider, including Windows, SQL Server, IIS, Defender and VMware. Expand the diagram to focus on larger flows.
Ask AI to graph failed logons by account or 5xx errors by page. It creates an editable count query, with results as a table, bars or over time.
Count queries stay visible and editable. The selected chart view is preserved in shared links, and counts can be downloaded as CSV.
Based on the application’s release notes through v2.25.0.
A FEW USEFUL DETAILS.
Windows event logs, measured host CPU and memory, and IIS requests. The explorer queries data held in R2 Data Catalog as Apache Iceberg tables using R2 SQL.
Yes. Fleet views, manual search, filters, counts, charts and drill-downs work independently of AI. AI assists with query writing, summaries and explanations when you choose to use it.
Links preserve views such as the tab, time range, search and open host. Saved analyses can also be linked when storage is configured. Recipients still need access to the application; a shared link does not grant access.
No. The visuals here use illustrative data to explain the product. Open the application to explore your environment with your existing access.
Identity shows the account recorded by Windows when the event includes one, separately from people who signed in to the host during the preceding hour. A nearby sign-in is context for an investigation, not proof that the person caused the change.
YOUR NEXT INVESTIGATION STARTS HERE.
Windows events. Real performance. Connected context.