HolmesGPT
An incident-investigation agent that queries your existing monitoring instead of asking you to paste logs into a chat
What is HolmesGPT?
The slow part of an incident is not the fix, it is the twenty minutes of pulling up dashboards, matching a spike to a deploy and finding the pod that actually failed. HolmesGPT does that part: it connects to what you already run — Prometheus, Grafana, Datadog, Kubernetes, any REST API — and works through the question in a loop, fetching what it needs and following what it finds, then writes the conclusion back to the alert it came from. Notably it is built for the scale that breaks naive tools: results are filtered on the server, large outputs are streamed to disk and each tool has a memory limit, so querying a big observability dataset does not fill a context window or kill the process. It is a CNCF sandbox project.
What can you do with HolmesGPT?
- Investigate against live data, not a pasted excerpt — It queries the monitoring you already run, so the answer reflects the current state rather than whatever someone happened to copy into a message.
- Write the finding back where the alert came from — Alerts are read from AlertManager, PagerDuty, OpsGenie or Jira and the conclusion is written back, so the investigation lands in the ticket rather than in a chat window.
- Survive a large query — Server-side filtering, per-tool memory limits and streaming of big results to disk keep an investigation from being defeated by the size of the dataset.
- Watch without being asked — An operator mode runs continuously, checking service health on a schedule or after a deploy and raising what it finds instead of waiting for a human to notice.
- Cover more than Kubernetes — Virtual machines, cloud services, databases and SaaS platforms are all reachable, so it fits an estate that was never fully containerised.
- Add a source it does not know — Any REST API can be registered as a toolset, so an in-house monitoring system does not put the whole approach out of reach.
Before you choose HolmesGPT
- It is only as good as what it can reach — an estate whose useful signal lives in dashboards nobody exported, or in an undocumented internal system, gives it little to work with until those are wired up.
- The always-on operator mode itself runs in Kubernetes, so teams on other infrastructure get the on-demand investigation but not the unattended monitoring half without more work.
Frequently asked questions
Is HolmesGPT free for commercial use?
HolmesGPT is released under the Apache-2.0 licence — OSI-approved open source, which permits commercial use.
How can HolmesGPT be deployed?
HolmesGPT is available as Self-hosted / Runs locally.
Documentation
Reproduced from the HolmesGPT/holmesgpt README, published under Apache-2.0. Read the original ↗
Open-source AI agent for investigating production incidents and finding root causes. Works with any stack — Kubernetes, VMs, cloud providers, databases, and SaaS platforms. We are a Cloud Native Computing Foundation sandbox project. Originally created by Robusta.Dev, with major contributions from Microsoft.
New: Operator Mode — Find Problems 24/7 in the Background
Most AI agents are great at troubleshooting problems, but still need a human to notice something is wrong and trigger an investigation. Operator mode fixes that — HolmesGPT runs in the background 24/7, spots problems before your customers notice, and messages you in Slack with the fix. Connect the GitHub integration and it can even open PRs to fix what it finds.
While the operator itself runs in Kubernetes, health checks can query any data source Holmes is connected to — VMs, cloud services, databases, SaaS platforms, and more.
- Deployment verification — Deploy a health check alongside your app to verify the new version is healthy
- Scheduled health checks — Continuously monitor services and catch regressions automatically
Features
- Petabyte-scale data: Server-side filtering, JSON tree traversal, and tool output transformers keep large payloads out of context windows
- Memory-safe execution: Per-tool memory limits, streaming large results to disk, and automatic output budgeting prevent OOM kills when querying large observability datasets
- Deep integrations: Prometheus, Grafana, Datadog, Kubernetes, and many more—plus any REST API
- Bidirectional alert integrations: Fetch alerts from AlertManager, PagerDuty, OpsGenie, or Jira—and write findings back
- Any LLM provider: OpenAI, Anthropic, Azure, Bedrock, Gemini, and more
- No Kubernetes required: Works with any infrastructure — VMs, bare metal, cloud services, or containers
How it Works
HolmesGPT uses an agentic loop to query live observability data from multiple sources and identify root causes.

🔗 Data Sources
HolmesGPT integrates with popular observability and cloud platforms. The following data sources (“toolsets”) are built-in. Add your own.
| Data Source | Notes |
|---|---|
| AKS | Azure Kubernetes Service cluster and node health diagnostics |
| Atlassian Rovo | Jira issues and Confluence pages via Atlassian’s hosted server (MCP) |
| ArgoCD | Get status, history and manifests and more of apps, projects and clusters |
| AWS | RDS events, instances, slow query logs, and more (MCP) |
| Azure | Azure resources and diagnostics (MCP) |
| Confluence | Private runbooks and documentation |
| Confluence (MCP) | Private runbooks and documentation (MCP) |
| Coralogix | Retrieve logs for any resource |
| Crossplane | Troubleshoot Crossplane providers, compositions, claims, and managed resources |
| Datadog | Query logs, metrics, and traces |
| Docker | Get images, logs, events, history and more |
| Elasticsearch / OpenSearch | Query logs, cluster health, shard and index diagnostics |
| GCP | Google Cloud Platform resources (MCP) |
| GitHub | Repositories, issues, and pull requests (MCP) |
| GitLab | Projects, merge requests, issues, and CI/CD pipelines (MCP) |
| Jenkins (MCP) | Build status, pipeline logs, and job history (MCP) |
| Grafana | Query and analyze dashboard configurations and panels |
| Helm | Release status, chart metadata, and values |
| Internet | Public runbooks, community docs, etc. |
| Kafka | Fetch metadata, list consumers and topics or find lagging consumer groups |
| Kubernetes | Pod logs, K8s events, and resource status (kubectl describe) |
| Kubernetes Remediation (MCP) | Apply fixes like scaling, rollbacks, and resource edits (MCP) |
| Loki | Query logs for Kubernetes resources or any query |
| MariaDB | MariaDB database queries and diagnostics |
| MongoDB | Query data, diagnose performance, inspect schemas, find slow operations |
| MongoDB Atlas | Cluster health, slow queries, and performance diagnostics |
| NewRelic | Investigate alerts, query tracing data |
| OpenShift | Projects, routes, builds, security context constraints, and deployment configs |
| Prefect (MCP) | Workflow orchestration monitoring, flow runs, and worker health (MCP) |
| Prometheus | Investigate alerts, query metrics and generate PromQL queries |
| RabbitMQ | Partitions, memory/disk alerts, troubleshoot split-brain scenarios and more |
| Robusta | Multi-cluster monitoring, historical change data, runbooks, PromQL graphs and more |
| ServiceNow | Query tables and incident records |
| Sentry | Error tracking, issues, and performance monitoring (MCP) |
| Slab | Team knowledge base and runbooks on demand |
| Splunk | Log search and analysis (MCP) |
| SQL Databases | PostgreSQL, MySQL, ClickHouse, MariaDB, SQL Server, Azure SQL, SQLite |
| Tempo | Fetch trace info, debug issues like high latency in application |
| VictoriaLogs | Query logs from VictoriaLogs using LogsQL |
| VictoriaMetrics | Query metrics from a Prometheus-compatible TSDB (vmsingle / vmcluster) |
| Zabbix | Monitor hosts, problems, events, triggers, and historical metrics |
See the full list of built-in toolsets for additional integrations including Cilium, KubeVela, Notion, and more.
🚀 End-to-End Automation
HolmesGPT can fetch alerts/tickets to investigate from external systems, then write the analysis back to the source or Slack.
| Integration | Status | Notes |
|---|---|---|
| Slack | ✅ | Demo. Available via Robusta |
| Microsoft Teams | ✅ | Available via Robusta |
| Prometheus/AlertManager | ✅ | Robusta or HolmesGPT CLI |
| PagerDuty | ✅ | HolmesGPT CLI only |
| OpsGenie | ✅ | HolmesGPT CLI only |
| Jira | ✅ | HolmesGPT CLI only |
| GitHub | ✅ | HolmesGPT CLI only |
Installation
Read the installation documentation to learn how to install HolmesGPT.
Supported LLM Providers
Read the LLM Providers documentation to learn how to set up your LLM API key.
Using HolmesGPT
See the walkthrough documentation for usage guides, including:
- Interactive mode for asking questions and follow-ups
- Investigating Prometheus alerts
- CI/CD troubleshooting
🔐 Data Privacy
By design, HolmesGPT has read-only access and respects RBAC permissions. It is safe to run in production environments.
Community
Join our community to discuss the HolmesGPT roadmap and share feedback:
Support
If you have any questions, feel free to message us on HolmesGPT Slack Channel
How to Contribute
Please read our CONTRIBUTING.md for guidelines and instructions.
For help, contact us on Slack or ask DeepWiki AI your questions.
Please make sure to follow the CNCF code of conduct - details here.