AKS · Azure SQL · Azure Functions · Service Bus · Azure Monitor

AI SRE for Azure

Sherlocks AI on Azure is an AI SRE that picks up your Azure Monitor alerts, reads the telemetry you already have, and returns a root cause with the evidence attached, in minutes rather than hours. Sixteen investigation agents run read-only inside your VNet, and your data never leaves your Azure subscription.

sherlocks / azure production
sre@prod-bastion ~ $ sherlocks investigate --source azure-monitorSOURCE        SIGNAL              CORRELATEDazure-sql     p99 100ms -> 1s     N+1 after deployazure-sql     pool saturated      query holding connsaks           pod CrashLoopBack   env var missingservice-bus   backlog growing     subscriber OOM sre@prod-bastion ~ $ sherlocks explain celery-crashloop-amqp-broker

Investigate incidents across your entire Azure stack

Modern Azure environments generate telemetry from everywhere. Azure Monitor metrics. Application logs in Log Analytics. Kubernetes events on AKS. Azure SQL query stats. Azure Functions invocation traces. Service Bus queue depths. When a real incident happens, the signal is almost always there. Finding it takes forty minutes of correlating dashboards, tabs, and Slack threads.

Sherlocks AI compresses that forty minutes into a few. Sixteen specialized investigation agents read your existing Azure telemetry, correlate signals across services and time, and return a root cause with the evidence attached. The Watson data agent runs inside your VNet with read-only access. Nothing gets modified, nothing gets executed, and no raw application data ever leaves your Azure subscription.

Supported Azure services

(08 Categories)

Sherlocks AI integrates natively with the Azure services your production stack actually runs on.

Compute

Azure Virtual Machines metrics, resource utilization, and state changes.

Databases

Azure SQL Database and Azure Database for PostgreSQL/MySQL query performance, connection pools, replication lag, and slow query patterns.

Serverless

Azure Functions invocation metrics, error rates, cold start patterns, and function-level tracing.

Storage

Azure Blob Storage request metrics, error rates, latency, and access patterns.

Monitoring and logging

Azure Monitor metrics and alerts, Log Analytics workspace queries, and Application Insights distributed traces across your entire Azure footprint.

Containers

AKS cluster health, pod status, deployment tracking, service dependencies, and resource metrics.

Messaging

Azure Service Bus queue depth, message age, and DLQ stats. Event Hubs consumer lag.

LLM hosting

Azure OpenAI Service as a private LLM deployment option, keeping all AI reasoning within your Azure subscription.

How Sherlocks AI works on Azure

(04 Steps)
  1. 1Step 1: Deploy Watson to your AKS cluster.

    Watson runs as read-only pods inside your existing Kubernetes environment. No new infrastructure to provision, and nothing is installed on your workloads. We will walk your platform team through the deployment that fits your Azure estate.

  2. 2Step 2: Grant read-only Azure RBAC roles.

    Give the identity Watson runs as a read-only role on the subscription or resource groups it investigates. That gives Watson read access to Azure Monitor, Log Analytics, Azure SQL metadata, and the other Azure APIs Sherlocks AI integrates with. Cannot modify infrastructure. Cannot execute commands. Cannot access secrets in Key Vault.

  3. 3Step 3: Connect your existing tools.

    Slack or Microsoft Teams for incident channels. Datadog, New Relic, or Prometheus if you use them. GitHub or Azure DevOps for deployment correlation.

  4. 4Step 4: First investigation in Slack or Teams.

    Tag Sherlocks AI in any incident channel or ask it directly. Most teams see their first AI-led investigation within an hour of finishing setup.

Deployment options for Azure

(02 Options)

Two ways to run Sherlocks AI on Azure. Pick based on your security posture and compliance requirements.

SaaS

Fastest to start

The agents run in the Sherlocks AI cloud. Watson runs inside your VNet and is the only component that touches your systems.

Sherlocks AI cloud
The Sherlocks AI agents
Knowledge graph
Model inference
Encrypted metadata and metrics. PII redacted by Watson before it leaves.
Your VNet
Watson, the data agent. Read-only, on demand.
Cloud, monitoring, ITSM, repositories, hosts
What leaves
Encrypted metadata and metrics only
Typical fit
Teams already running public SaaS tooling

On-premise

Strict residency

Everything runs inside your VNet, the model included. A deployment choice, not a reduced version of the product.

Your VNet
The Sherlocks AI agents
Knowledge graph
Model inference, on models you run
Watson, the data agent. Read-only, on demand.
Cloud, monitoring, ITSM, repositories, hosts
What leaves
Nothing
Typical fit
Regulated teams, or data that cannot leave your Azure subscription
In both options
  • Read-only. No write, delete or modify permission is requested anywhere.
  • No business data. No table rows, message contents, customer PII or secrets.
  • Encrypted. TLS 1.3 in transit, AES-256 at rest, keys separated per customer.
  • SOC 2 Type 2. Report available on request.

Security and compliance

Enterprise Azure buyers care about specific things. Sherlocks AI answers each of them directly.

Read-only Azure RBAC roles across every integration.

Watson cannot modify infrastructure, databases, or application state. Cannot execute commands or deploy changes. Cannot access secrets in Key Vault. Even if compromised, Watson cannot modify your systems or exfiltrate application data.

No raw application data.

Sherlocks AI collects metadata and metrics. Database connection counts, query execution times, replication lag, error rates. Never table data, message contents, customer PII, API keys, or source code.

SOC 2 Type 2 certified.

Sherlocks AI cloud environment is annually audited against the SOC 2 Type 2 framework.

Encryption everywhere.

TLS 1.3 in transit. AES-256 at rest. Separate encryption keys per customer with enforced rotation.

Air-gapped deployment.

The On-premise option runs with no external dependencies, which suits regulated deployments that cannot reach the public internet.

Data residency.

With the On-premise option, no telemetry data ever leaves your Azure subscription.

Retention control.

Telemetry metadata is retained for 90 days by default, configurable to match your policies. Data deletion requests honored within 30 days.

Real Azure scenarios where Sherlocks AI helps

(05 Scenarios)
Slow API calls after a deploy.

An Azure SQL query that ran in 100ms yesterday now takes 1 second. Sherlocks AI correlates the latency spike with the recent AKS deployment, identifies an N+1 query pattern introduced in a specific commit, and points to the exact code change. MTTR from hours to minutes.

Partial AKS deployment failure.

Some services deployed successfully, others failed silently. Sherlocks AI correlates CI/CD pipeline failures with missing services in AKS, identifies the failed build step, and links directly to the problematic commit.

Kubernetes crash loop on AKS.

A pod restarts repeatedly. Sherlocks AI analyzes pod logs, identifies a missing environment variable introduced in the latest deployment, and provides the exact fix.

Worked example: Trino CrashLoopBackOff (Missing JVM Arg)
Azure SQL connection pool exhaustion.

Database connection pool saturated, queries timing out. Sherlocks AI detects the saturation, identifies a long-running query holding connections, and correlates with the recent code change that introduced it.

Worked example: DB Connection Pool Exhaustion
Service Bus consumer lag.

Queue backlog growing, message processing falling behind. Sherlocks AI identifies that a subscriber pod is crash-looping due to OOM, correlates with a recent traffic spike, and suggests scaling.

Incidents on Kubernetes and VMs, worked end to end

(03 Published)

Each of these is a real investigation with the evidence trail attached, including the hypotheses that were ruled out along the way.

The full examples section has 20 investigations across AWS, Kubernetes, databases and Linux VMs. The Kubernetes RCA guides cover the failure classes behind them.

Frequently asked questions

(09 Questions)

Does Sherlocks AI work with AKS?

Yes. Sherlocks AI reads pod status, deployment events, service dependencies, and resource metrics across your AKS environment, so AKS incidents such as CrashLoopBackOff, OOMKilled and failed scheduling are investigated the same way they are on EKS and GKE. Talk to us about the deployment that fits your Azure estate.

How does the Watson agent authenticate to Azure?

Watson uses Azure RBAC with a managed identity or service principal that holds a read-only role. No credentials are stored in the cluster. The role can read Azure Monitor, Log Analytics, Azure SQL metadata, and the other Azure APIs Sherlocks AI integrates with, and cannot change anything.

What Azure RBAC permissions does Sherlocks AI need?

A read-only role on the subscription or resource groups Watson investigates. That covers Azure Monitor metrics and Log Analytics workspaces, Azure SQL metadata (INFORMATION_SCHEMA and metadata queries only, no application data), Azure Functions invocation stats, Virtual Machine metadata, Blob Storage request metrics, AKS cluster status, and Service Bus queue attributes. Sherlocks AI never requests write, modify, or execute permissions on any Azure service.

Does Sherlocks AI work with Azure OpenAI as the LLM?

Yes. Azure OpenAI Service is supported as a private LLM deployment option. When you use Azure OpenAI, LLM reasoning runs fully managed inside your Azure subscription, keeping all AI inference within your cloud environment.

Is any data transmitted outside my Azure subscription?

Depends on the option. On-premise, nothing leaves your Azure subscription: agents, knowledge graph, model inference and Watson all run inside your network. SaaS, only encrypted metadata and metrics are transmitted to Sherlocks AI cloud, with PII redacted by Watson before it leaves, never raw application data.

Does Sherlocks AI integrate with Azure Monitor alerts?

Yes. Sherlocks AI reads Azure Monitor metrics, log-based alerts, and alert rules as part of its investigation. When an Azure Monitor alert fires and creates an incident channel in Slack or Teams, Sherlocks AI begins investigating automatically.

Can Sherlocks AI read from Azure SQL without accessing application data?

Yes. Azure SQL integration uses read-only access to INFORMATION_SCHEMA and metadata queries only. Sherlocks AI reads query performance stats, replication status, connection pool metrics, and slow query patterns. Never table contents, PII, or application records.

Does Sherlocks AI work with Microsoft Teams as well as Slack?

Yes. Sherlocks AI integrates with Microsoft Teams for incident channels, in addition to Slack. Teams users can tag Sherlocks AI in any incident thread and receive the same investigation output as Slack users.

Get started with Sherlocks AI on Azure

Try Sherlocks AI free with 30 investigations per month, no credit card required. Book a call and we will size the Azure deployment with your platform engineers on the line.

30
Free investigations / month
$0
No credit card