Incident investigation is a Pro feature.
Start an investigation
- From a host’s detail view, click Generate Report.
- Select the hosts involved and a time window (last hour, 6 hours, 24 hours, or 7 days).
- Click Start investigation.
How it works
The assistant gathers evidence using:- Live commands on the selected hosts, run over your existing SSH sessions (or new ones opened for the investigation).
- Historical metrics (CPU, RAM, disk) from Monitoring, for time ranges before the investigation started.
- Security events (failed logins, bans, HTTP brute force), if security event capture was enabled on the host.
The report
Click View report once the assistant has gathered enough evidence. The report includes:
A finding is marked not verifiable from collected evidence if it cites a number that doesn’t appear anywhere in the commands or metrics actually gathered during the investigation.
Save the report to disk or copy it as Markdown from the report dialog.

