AI SRE for Azure
Sherlocks AI on Azure is an AI SRE that picks up your Azure Monitor alerts, reads the telemetry you already have, and returns a root cause with the evidence attached, in minutes rather than hours. Sixteen investigation agents run read-only inside your VNet, and your data never leaves your Azure subscription.
sre@prod-bastion ~ $ sherlocks investigate --source azure-monitorSOURCE SIGNAL CORRELATEDazure-sql p99 100ms -> 1s N+1 after deployazure-sql pool saturated query holding connsaks pod CrashLoopBack env var missingservice-bus backlog growing subscriber OOM sre@prod-bastion ~ $ sherlocks explain celery-crashloop-amqp-broker
Investigate incidents across your entire Azure stack
Modern Azure environments generate telemetry from everywhere. Azure Monitor metrics. Application logs in Log Analytics. Kubernetes events on AKS. Azure SQL query stats. Azure Functions invocation traces. Service Bus queue depths. When a real incident happens, the signal is almost always there. Finding it takes forty minutes of correlating dashboards, tabs, and Slack threads.
Sherlocks AI compresses that forty minutes into a few. Sixteen specialized investigation agents read your existing Azure telemetry, correlate signals across services and time, and return a root cause with the evidence attached. The Watson data agent runs inside your VNet with read-only access. Nothing gets modified, nothing gets executed, and no raw application data ever leaves your Azure subscription.
Supported Azure services
(08 Categories)Sherlocks AI integrates natively with the Azure services your production stack actually runs on.
Azure Virtual Machines metrics, resource utilization, and state changes.
Azure SQL Database and Azure Database for PostgreSQL/MySQL query performance, connection pools, replication lag, and slow query patterns.
Azure Functions invocation metrics, error rates, cold start patterns, and function-level tracing.
Azure Blob Storage request metrics, error rates, latency, and access patterns.
Azure Monitor metrics and alerts, Log Analytics workspace queries, and Application Insights distributed traces across your entire Azure footprint.
AKS cluster health, pod status, deployment tracking, service dependencies, and resource metrics.
Azure Service Bus queue depth, message age, and DLQ stats. Event Hubs consumer lag.
Azure OpenAI Service as a private LLM deployment option, keeping all AI reasoning within your Azure subscription.
How Sherlocks AI works on Azure
(04 Steps)- 1Step 1: Deploy Watson to your AKS cluster.
Watson runs as read-only pods inside your existing Kubernetes environment. No new infrastructure to provision, and nothing is installed on your workloads. We will walk your platform team through the deployment that fits your Azure estate.
- 2Step 2: Grant read-only Azure RBAC roles.
Give the identity Watson runs as a read-only role on the subscription or resource groups it investigates. That gives Watson read access to Azure Monitor, Log Analytics, Azure SQL metadata, and the other Azure APIs Sherlocks AI integrates with. Cannot modify infrastructure. Cannot execute commands. Cannot access secrets in Key Vault.
- 3Step 3: Connect your existing tools.
Slack or Microsoft Teams for incident channels. Datadog, New Relic, or Prometheus if you use them. GitHub or Azure DevOps for deployment correlation.
- 4Step 4: First investigation in Slack or Teams.
Tag Sherlocks AI in any incident channel or ask it directly. Most teams see their first AI-led investigation within an hour of finishing setup.
Deployment options for Azure
(02 Options)Two ways to run Sherlocks AI on Azure. Pick based on your security posture and compliance requirements.
SaaS
Fastest to startThe agents run in the Sherlocks AI cloud. Watson runs inside your VNet and is the only component that touches your systems.
On-premise
Strict residencyEverything runs inside your VNet, the model included. A deployment choice, not a reduced version of the product.
- Read-only. No write, delete or modify permission is requested anywhere.
- No business data. No table rows, message contents, customer PII or secrets.
- Encrypted. TLS 1.3 in transit, AES-256 at rest, keys separated per customer.
- SOC 2 Type 2. Report available on request.
Security and compliance
Enterprise Azure buyers care about specific things. Sherlocks AI answers each of them directly.
Watson cannot modify infrastructure, databases, or application state. Cannot execute commands or deploy changes. Cannot access secrets in Key Vault. Even if compromised, Watson cannot modify your systems or exfiltrate application data.
Sherlocks AI collects metadata and metrics. Database connection counts, query execution times, replication lag, error rates. Never table data, message contents, customer PII, API keys, or source code.
Sherlocks AI cloud environment is annually audited against the SOC 2 Type 2 framework.
TLS 1.3 in transit. AES-256 at rest. Separate encryption keys per customer with enforced rotation.
The On-premise option runs with no external dependencies, which suits regulated deployments that cannot reach the public internet.
With the On-premise option, no telemetry data ever leaves your Azure subscription.
Telemetry metadata is retained for 90 days by default, configurable to match your policies. Data deletion requests honored within 30 days.
Real Azure scenarios where Sherlocks AI helps
(05 Scenarios)An Azure SQL query that ran in 100ms yesterday now takes 1 second. Sherlocks AI correlates the latency spike with the recent AKS deployment, identifies an N+1 query pattern introduced in a specific commit, and points to the exact code change. MTTR from hours to minutes.
Some services deployed successfully, others failed silently. Sherlocks AI correlates CI/CD pipeline failures with missing services in AKS, identifies the failed build step, and links directly to the problematic commit.
A pod restarts repeatedly. Sherlocks AI analyzes pod logs, identifies a missing environment variable introduced in the latest deployment, and provides the exact fix.
Worked example: Trino CrashLoopBackOff (Missing JVM Arg)Database connection pool saturated, queries timing out. Sherlocks AI detects the saturation, identifies a long-running query holding connections, and correlates with the recent code change that introduced it.
Worked example: DB Connection Pool ExhaustionQueue backlog growing, message processing falling behind. Sherlocks AI identifies that a subscriber pod is crash-looping due to OOM, correlates with a recent traffic spike, and suggests scaling.
Incidents on Kubernetes and VMs, worked end to end
(03 Published)Each of these is a real investigation with the evidence trail attached, including the hypotheses that were ruled out along the way.
Celery CrashLoopBackOff from an AMQP broker connection failure that self-healed before it was explained
Celery consumer entered CrashLoopBackOff during startup after failing to establish AMQP/Kombu broker connection. Pod was replaced and deployment self-healed. eaze also affected but root cause not preserved in logs.
payment-gateway OOM kill: a Hibernate session cache leak in a nightly batch job
Hibernate session cache leak in batch reconciliation job grew JVM heap from 4 GB to 14 GB over 6 hours. Linux OOM killer terminated the process, causing 8 minutes of downtime.
CrashLoopBackOff: a release candidate image crashed ad-service before it could bind its port
Fatal mutex assertion failure in runtime triggered by deployment revision 1848, causing repeated pod crashes with 7 restarts.
The full examples section has 20 investigations across AWS, Kubernetes, databases and Linux VMs. The Kubernetes RCA guides cover the failure classes behind them.
Frequently asked questions
(09 Questions)Does Sherlocks AI work with AKS?
Yes. Sherlocks AI reads pod status, deployment events, service dependencies, and resource metrics across your AKS environment, so AKS incidents such as CrashLoopBackOff, OOMKilled and failed scheduling are investigated the same way they are on EKS and GKE. Talk to us about the deployment that fits your Azure estate.
How does the Watson agent authenticate to Azure?
Watson uses Azure RBAC with a managed identity or service principal that holds a read-only role. No credentials are stored in the cluster. The role can read Azure Monitor, Log Analytics, Azure SQL metadata, and the other Azure APIs Sherlocks AI integrates with, and cannot change anything.
What Azure RBAC permissions does Sherlocks AI need?
A read-only role on the subscription or resource groups Watson investigates. That covers Azure Monitor metrics and Log Analytics workspaces, Azure SQL metadata (INFORMATION_SCHEMA and metadata queries only, no application data), Azure Functions invocation stats, Virtual Machine metadata, Blob Storage request metrics, AKS cluster status, and Service Bus queue attributes. Sherlocks AI never requests write, modify, or execute permissions on any Azure service.
Does Sherlocks AI work with Azure OpenAI as the LLM?
Yes. Azure OpenAI Service is supported as a private LLM deployment option. When you use Azure OpenAI, LLM reasoning runs fully managed inside your Azure subscription, keeping all AI inference within your cloud environment.
Is any data transmitted outside my Azure subscription?
Depends on the option. On-premise, nothing leaves your Azure subscription: agents, knowledge graph, model inference and Watson all run inside your network. SaaS, only encrypted metadata and metrics are transmitted to Sherlocks AI cloud, with PII redacted by Watson before it leaves, never raw application data.
Does Sherlocks AI integrate with Azure Monitor alerts?
Yes. Sherlocks AI reads Azure Monitor metrics, log-based alerts, and alert rules as part of its investigation. When an Azure Monitor alert fires and creates an incident channel in Slack or Teams, Sherlocks AI begins investigating automatically.
Can Sherlocks AI read from Azure SQL without accessing application data?
Yes. Azure SQL integration uses read-only access to INFORMATION_SCHEMA and metadata queries only. Sherlocks AI reads query performance stats, replication status, connection pool metrics, and slow query patterns. Never table contents, PII, or application records.
Does Sherlocks AI work with Microsoft Teams as well as Slack?
Yes. Sherlocks AI integrates with Microsoft Teams for incident channels, in addition to Slack. Teams users can tag Sherlocks AI in any incident thread and receive the same investigation output as Slack users.
Get started with Sherlocks AI on Azure
Try Sherlocks AI free with 30 investigations per month, no credit card required. Book a call and we will size the Azure deployment with your platform engineers on the line.