CreaRack-SL

AI Insights (CNS) and Sentinel Mode

What it is

CreaRack Network Sentinel (CNS) is the AI layer of Network Observatory. It covers three things:

  • AI Insights — when monitoring detects an anomaly, CNS generates a diagnosis: a summary, the probable root cause, a risk level and suggested corrective actions. You review them in the CNS tab.
  • Sentinel Mode — 24/7 monitoring through the Local Agent installed on a machine in your network. With Sentinel on, monitoring keeps running even when your browser is closed.
  • Network Tutor — a chat assistant for networking questions, from CCNA to CCIE level.

How to work with AI Insights

  1. Open Observatory and click the CNS tab.
  2. Each insight has a case number (e.g. CNS-000042), a risk level (HIGH/MEDIUM/LOW), a summary, a root cause and a confidence score.
  3. Filter by status or risk, search by text or case number, and pick a date range. Use Clear to reset filters, Export CSV to download the filtered list, and History to review acknowledged insights.
  4. Click Details on a row to open the full diagnosis. From there you can:
    • Acknowledge — mark it as reviewed, with optional notes.
    • Apply Fix — run the suggested corrective commands through the Local Agent. It needs an Agent online: if none is connected you get a clear message and the insight stays Pending.
    • Explain — ask the AI follow-up questions about this specific insight. The conversation is saved with the case.
    • Revise Diagnosis — have the AI re-evaluate the diagnosis using your conversation.

An insight starts as Pending. It moves to Acknowledged when you review it, or Executing → Applied (or Failed) when a fix runs. Most pending insights expire automatically after 4 hours and become Expired. The exception is a device that stopped responding: that insight stays open as one incident and closes when the device recovers, so a long outage does not open the same alert again and again. It only expires (after 48 hours without a new report) if the Agent stops reporting on that device altogether.

How to enable 24/7 Sentinel Mode

By default Observatory runs in Cloud Only mode: monitoring stops when you close the browser. Sentinel Mode hands the polling to the Local Agent so it never stops.

  1. Install the [[crearack—terminal—local-agent]] on a machine that stays on.
  2. In the Observatory sidebar, expand the Sentinel Mode section.
  3. Click Change and confirm. The label switches from Cloud Only to 24/7 Sentinel and your monitoring targets are pushed to the Agent.

The panel shows two status rows:

  • Monitoring — Active when the Agent is running Sentinel checks.
  • Sync — Online when the Agent is connected to the cloud; Offline means it keeps collecting locally and will sync when the connection returns.

The dot next to the section header summarizes everything: green = healthy, orange = Agent up but not syncing, red = Agent unreachable. When the Agent detects an anomaly, it reports it to the cloud and CNS generates an insight — browser open or not.

How to use the Network Tutor

  1. Click Network Tutor at the bottom of the Observatory sidebar. A chat panel slides in.
  2. Type a question and click Ask, or pick one of the suggested questions.
  3. If you have a device tab open, its name, IP and vendor are sent as context, so answers can be device-specific.
  4. Clear wipes the conversation history; Close hides the panel.

Answers show a “via …” badge with the AI provider used. The Tutor is limited to 20 questions per minute and politely declines off-topic questions.

Troubleshooting

  • Sentinel dot is red / “Agent offline. Monitoring paused.” — the Agent is not reachable. Click Download Agent to install or restart it, then wait for the panel to detect it.
  • Sync shows Offline — the Agent is running but cannot reach the cloud. Metrics are buffered locally and pushed when connectivity returns.
  • “Rate limit” on Explain — follow-up questions are capped per hour for your organization. Wait and retry.
  • “No Agent is connected for this organization” on Apply Fix — fixes run through the Local Agent. Start it (see [[crearack—monitoring—fleet-manager]]) and click Apply Fix again; the insight is still Pending.
  • Sentinel stuck after testing — open the Agent Fleet Manager and click Reset to clear the Agent’s rate limits and cooldowns. See [[crearack—monitoring—fleet-manager]].
  • [[crearack—monitoring—que-es-observatory]] — the Observatory module CNS lives in
  • [[crearack—monitoring—itsm]] — manage insights as incidents with SLAs and notifications
  • [[crearack—monitoring—alertas]] — threshold alerts that feed anomaly detection
  • [[crearack—monitoring—fleet-manager]] — manage the Agents that run Sentinel Mode
  • [[crearack—terminal—local-agent]] — installing the Local Agent

Véase también

  • [[crearack—monitoring—que-es-observatory]]
  • [[crearack—monitoring—itsm]]
  • [[crearack—monitoring—alertas]]
  • [[crearack—monitoring—fleet-manager]]
  • [[crearack—terminal—local-agent]]