RST AI Copilot for Prometheus
A self-hosted AI gateway for network operations that connects to your existing Prometheus and Alertmanager. Ask for metrics in plain language, triage and investigate alerts, generate alert rules, and get daily and weekly network reports.
Overview
RST AI Copilot for Prometheus is an AI gateway delivered as Docker containers and deployed inside your network. It is built for network operations: metrics from switches, routers and firewalls are collected into Prometheus by snmp_exporter (SNMP) and blackbox_exporter (ICMP, TCP and HTTP probes), and the gateway connects to the Prometheus and Alertmanager you already run. Grafana is optional and only used for links. The gateway does not ship Prometheus, installs no collection agents and keeps no second copy of your time series.
Operators ask questions in plain language. The gateway generates PromQL, validates it against your real Prometheus before running it, and returns charts and tables. Alerts are read from Alertmanager and can be triaged, investigated and silenced; a confirmed fault can be turned into an alert rule that is written back to Prometheus after approval.

Queries against Prometheus are read-only. The gateway writes only two things: its own alert rule file (after approval, with rollback), and Alertmanager silences (creating and expiring them are both audited). Grouping, inhibition and paging stay with your Alertmanager.
The current release is a preview for demos and pilots. It is not recommended for production.
Features
| Feature | What it does | License |
|---|---|---|
| Ask AI | Plain-language questions become PromQL, validated before running and repaired when validation fails; follow-up questions; charts and tables; links to Grafana | Free |
| Alerts and silences | Live alerts from Alertmanager with push updates; silences from an alert's labels; expire silences | Free |
| Network | Network posture, device inventory (auto-discovery, per-interface alert policy), monitoring-coverage baseline | Free |
| Metric dictionary and knowledge base | Descriptions of standard and vendor MIB metrics; built-in network runbooks that queries and investigations cite | Free |
| Masking, audit, notifications | Labels are masked before they reach the model; local audit log; delivery to Feishu, DingTalk, WeCom, email and webhooks | Free |
| Users | Admin, operator and viewer roles. Community is limited to 1 user | Free |
| Alert triage | Clusters alerts by name, ranks them by device vendor, role and site, and has the model score severity and spot noise | Paid |
| Alert investigation | The model queries related metrics on its own and returns a timeline, root-cause assessment, affected objects and actions; export an incident report or push the conclusion | Paid |
| Alert rules | Write rules by hand, validate and submit them for approval, write them back to Prometheus with a hot reload, roll back by version; built-in network rule pack | Free |
| AI alert rule generation | Describe what to watch in one sentence and the model generates the rule; hand-written rules are free | Paid |
| Capacity forecast | Predicts from history when link bandwidth, firewall sessions, CPU, memory and temperature will reach their thresholds | Paid |
| Monitoring health | Checks the health of Prometheus and Alertmanager themselves, with an AI readout | Paid |
| Alert noise reduction | Detects interface flapping, merges duplicate alerts and suggests inhibit rules | Paid |
| Reports | Daily, weekly and monthly reports, generated on a schedule and delivered | Paid |
Every edition uses the same bundle. Without a license it runs as the Community edition and the free features work. Paid features need a Professional or Enterprise license; Professional is licensed per user. A trial license unlocks every Enterprise feature for 14 days on 1 host with up to 10 accounts. Enterprise adds OIDC single sign-on, audit forwarding, multi-provider model failover and offline activation on top of Professional. Upgrading only needs a license import, not a reinstall. See Editions for the comparison and License for activation.
The Community edition is free and includes every free feature. The bundle is on GitHub: Reallysec/RST-AI-Copilot-for-Prometheus.