Insaion Copilot Incident Analysis
Insaion Copilot provides guided incident triage directly from the incident drawer. It combines alarm context, reduced telemetry summaries, and packet-level analysis (when needed) into one continuous investigation flow.What Copilot does during incident analysis
When you launch analysis from an incident, Copilot can:- Build a focused investigation context from incident metadata and alarm rule details.
- Correlate relevant logs, metrics, and signal changes around trigger time.
- Request an MCAP extraction window when baseline evidence is not conclusive.
- Continue automatically with deep packet-level analysis after MCAP artifacts are ready.
- Stream findings into the conversation and persist a structured report for later review.
Start analysis from an incident
- Open the Incidents page.
- Select the incident to investigate.
- Open the action menu.
- Select Analyze with Copilot.
End-to-end analysis flow
- Copilot starts baseline triage on incident context and reduced telemetry.
- If baseline evidence is conclusive, Copilot returns a root-cause summary immediately.
- If baseline evidence is inconclusive, Copilot prepares an MCAP extraction request with a scoped time window and relevant pipelines.
- After approval, the MCAP upload workflow runs and artifacts are registered.
- Copilot resumes deep analysis automatically and streams report updates in real time.
- The final report is stored in the thread and available on reconnect.
Recommended operator workflow
- Confirm incident timing, status, and affected entities.
- Review Copilot summary and suggested related signals.
- Validate key hypotheses in Lichtblick plots and related logs.
- Approve MCAP extraction when requested and monitor upload status.
- Review or export the generated incident report.
- Acknowledge or resolve the incident based on validated findings.
AI credits and limits
Copilot analysis consumes AI credits. If your organization reaches its limit:- New AI-assisted analysis requests are paused.
- Manual analysis remains available with the same incident context.
Best practices
- Keep alarm names and descriptions specific to improve Copilot context quality.
- Add notes and labels during triage to preserve investigation history.
- Resolve incidents only after confirming the underlying condition is cleared.
