Alerts in · Investigation done · Your AI reads it
Infrastructure incidents,
decoded.
Monitoring tools tell you what fired — rarely what's actually going on. AlertINT investigates alerts as they fire, inside your own network — before anyone opens a laptop. And when you do, the whole incident is already waiting in your AI tools.
$ alertint serve
12:19:19INFOalertint startingversion=dev
12:19:19INFOrules loadedbaseline · 3 rules
12:19:19INFOprometheus connectedprometheus:9090
12:19:19INFOlogs connectedloki:3100
12:19:19INFOmcp listening:9912/mcp
12:19:19INFOwebhook listening:9911
12:19:19INFOintegration health: okprometheus
12:21:06INFOwebhook receivedalerts=1 · EndpointDown firing
12:21:06INFOcorrelator: new incidentgroup=cluster=prod
How it works
From alert to resolution
When an alert fires, AlertINT gathers the context around it — correlated alerts, metrics, and logs — then posts a finding to Slack. Your AI agent connects over MCP to inspect live incident state and resolve it.
Read-only
Observes and reports by default, never touches your infrastructure.
Self-hosted
Your alert data and incident context stay inside your infrastructure. We enjoy privacy as much as you do.
Fair Source
The core software is Fair Source and always will be.
MCP-first
Your AI agent inspects real incident state and live data, not pasted text.
Get it
A single self-hosted binary.
Available on GitHub. Run the server, fire the built-in incident drill to watch it produce an AI finding end to end, then point your monitoring tools at it and connect MCP.
Starts the AlertINT runtime — ingress, correlation, triage, MCP server.
Runs a synthetic incident through the real pipeline to an AI finding. See quickstart.