Self-hosted network operations

From Horizon
to Resolution.

EventHorizon unifies assurance, automation, and inventory on your own infrastructure. EventResolve turns the findings into closed tickets. AI runs on local Ollama models — no external API calls.

Explore the Suite
Suite composition 02 components
01 EventHorizon assurance · automation · inventory · AIOps 02 EventResolve ITSM · service desk · incident response
01 → 02 findings become tickets; approvals stay with your engineers
The two halves

One runs your network. The other closes the tickets.

Service assurance

Anomaly detection and root-cause isolation across alarms, syslog, and flow data, with a live inventory underneath.

EventHorizon

Automation & orchestration

No-code runbook editor and job scheduler. Every execution lands in the logbook with a diff viewer — and every run requires your approval.

EventHorizon

ITSM and service desk

Email, web, chat, Slack, and REST feed one ticket stream. Reply drafting and summarization run on a local Ollama model.

EventResolve
The EventSuite platform

Two products. One perimeter.

EventHorizon watches and automates the network. EventResolve handles the tickets that come out of it. Both run entirely on your infrastructure.

7 → 1
Telemetry protocols unified in one platform
~5 sec
Automatic failover with HAProxy + Keepalived
0 bytes
Network data leaving your perimeter
What each part does

Platform composition

EventHorizon and EventResolve are separately installable and share no runtime dependency on each other.

Investigation with memory

Semantic search over historic incidents. The AI recalls similar past alarms and how they were resolved — "3 similar incidents last year, each an SFP failure, avg. time-to-clear 6 hours."

EventHorizon · AIOps

AI that stays inside your perimeter

Ollama runs on your own infrastructure. No cloud. No external API calls. Per-task model routing lets you assign different models to chat vs. analysis.

Both products

Findings become tickets

When EventHorizon isolates a fault, the finding goes to EventResolve as a ticket with its evidence attached. Closing the loop doesn't require a human copy-paste step.

01 → 02
The differentiator, stated plainly

What leaves your perimeter

Network data flows in a typical hosted SaaS NMS vs. EventSuite. Rows are categories of operational data the platform processes.
Data category Typical hosted SaaS NMS EventSuite
Alarms, syslog, and trap streams Leaves your network
Ingested by vendor cloud for correlation and AI analysis.
0 bytes leave
Processed on-premises; AI runs on local Ollama models.
Flow records (cFlow, sFlow, IPFIX) Leaves your network
Exported to vendor cloud for top-talker and security analytics.
0 bytes leave
Spoofing and port-scan detection run locally; exports stay on-disk.
Inventory, CMDB, and IPAM records Leaves your network
Synchronized to the vendor's multi-tenant database.
0 bytes leave
Single on-premises datastore; no external sync.
Ticket bodies and customer PII Depends on vendor
Summarization features typically call external model APIs.
0 bytes leave
Summarization and drafting run against local Ollama models.
AI model inference traffic Leaves your network
Prompts and context sent to third-party model endpoints.
0 bytes leave
Inference happens on your own GPU/CPU hardware.
Deployment topology Vendor-hosted
Requires persistent outbound connectivity.
Air-gap deployable
No runtime internet dependency; fonts and models bundled.
Security architecture

Nothing leaves your perimeter unless you decide it should.

Self-hosted AI (Ollama) Models run on your own hardware, per-task routed.
Zero external API calls No third-party model endpoints in any code path.
TLS 1.3 everywhere In transit, including syslog over TLS.
Human-approval gates Write actions expire after 2 minutes, no bypass.
Full audit trails Every approval and execution is logged.
PDPA / GDPR aligned Data residency inside your jurisdiction.
Air-gap deployable No runtime internet dependency.
Role-based access control Scoped roles across both products.

See it on your own network.

A 30-minute walkthrough on your telemetry — not a canned demo tenant.

Product 01

EventHorizon

Service assurance, automation, and inventory — powered by a self-hosted AI agent that investigates across every domain and asks before it acts.

The differentiator

Ask anything. Approve everything.

Its only write capability is executing orchestration runbooks.

A cross-domain AI assistant investigates across alarms, syslog, inventory, CMDB, IPAM, NetFlow, and historic incidents — all at once. Ask "which devices have the most critical alarms, and what are the top talkers on those devices?" and get a grounded answer.

AI agent console — illustrative session

which devices have the most critical alarms, and what are the top talkers on those devices?

3 devices with critical alarms: core-sw-01 (4), edge-rtr-07 (2), dc-sw-12 (1). Top talkers on core-sw-01: 10.20.4.11 (1.2 Gbps), 10.20.4.31 (890 Mbps).

have we seen this before?

3 similar incidents last year, each an SFP failure, avg. time-to-clear 6 hours.

Proposed action: runbook RB-118 "SFP check + failover" on core-sw-01 — awaiting your approval, expires in 2:00

Every action requires your explicit approval with a 2-minute expiry, no bypass, and a full audit trail.

7 → 1
Telemetry protocols unified in one platform
~5 sec
Automatic failover with HAProxy + Keepalived
0 bytes
Network data leaving your perimeter
Ingested natively

Every protocol. One platform.

  • 01 SNMP polling v1 / v2c / v3 · v3 with certificates
  • 02 SNMP traps all vendors
  • 03 Syslog UDP / TCP / TLS
  • 04 Flow cFlow / sFlow / IPFIX
  • 05 BMP BGP route monitoring
  • 06 gNMI streaming telemetry
  • 07 Cisco MDT streaming telemetry
Key capabilities

Not a monitoring tool. An operations platform.

AI agent console

Cross-domain investigation in natural language across alarms, syslog, inventory, CMDB, IPAM, NetFlow, and historic incidents. Write actions require human approval.

Human-in-the-loop

Have we seen this before?

Semantic search over historic incidents. The AI recalls similar past alarms and how they were resolved — "3 similar incidents last year, each an SFP failure, avg. time-to-clear 6 hours."

AIOps

AI that stays inside your perimeter

Ollama runs on your own infrastructure. No cloud. No external API calls. Per-task model routing lets you assign different models to chat vs. analysis.

Self-hosted

Live charts, alarm-linked

WebSocket-driven alarms, traps, and syslog update live. 8 chart views, chain-view topology maps, treemaps, and gauges that recolor with alarm status. Click any alarm to jump to the metric chart at that exact moment.

Real-time

Flow data as a security sensor

Beyond top talkers: spoofing detection, port-scan detection, and distinct-port profiling. Savable filters and exports up to 100,000 records.

NetFlow security

Automation without code

No-code flowchart runbook editor, calendar-view job scheduler, pending-job management, and bulk groups for mass operations. Every execution lands in the logbook with a diff viewer.

Visual orchestration

CMDB, config backup & compliance

Full CMDB with documents, facets, relationships, version history, and rollback — plus config backup, diff viewer, compliance analysis, Layer 2 topology mapping, and discovery that feeds itself.

Single source of truth

IPAM, without the spreadsheet

Full IPv4/IPv6 management with hierarchical pool trees, utilization dashboards, bulk operations, full audit trail, and a duplicate manager that finds and merges resources across pools.

Integrated IPAM
Under the hood

Enterprise-grade HA. Zero single points of failure.

A hardened virtual appliance sized for 5000+ device deployments — on VM or in containers.

IMDG clustering

Split-brain protection. No single point of failure anywhere in the stack.

~5 second failover

HAProxy + Keepalived VIP with automatic switchover. Users barely notice.

Horizontally scalable

NoSQL data lakes replication. Scale workers as your network grows.

Full visibility. Human-approved action.

On your own infrastructure, with ~5s failover underneath it.

Product 02

EventResolve

ITSM and service desk, with AI that runs on the same server as your tickets.

The setup most teams starts from

Five inboxes. One overloaded agent.

Requests arrive from email, chat, Slack, and web forms — each in its own silo.

Channel sprawl

Each channel keeps its own history and its own urgent flag. Nobody has one view of what a customer has already said.

SLAs nobody can see

Deadlines live in a spreadsheet next to the queue, so breaches surface in the post-mortem rather than in the queue.

4h → 45m
Average first-response time
5 → 1
Channels unified into one inbox
0 bytes
Customer data leaving your network
EventResolve Kanban board: four columns (NEW, OPEN, PENDING, CLOSED) with ticket cards showing priority chips, SLA markers, and tags
The board — one column per status, live for the whole team. Red SLA markers flag tickets that breached first-response; priority chips P1–P4.
Key capabilities

What makes EventResolve different

One inbox. Every channel.

Email, web forms, live chat, Slack, and REST API — every channel feeds one ticket stream. No tab-switching. No dropped conversations.

Omnichannel

Real-time, not refresh

Server-Sent Events push every change — new tickets, comments, status moves — instantly to every open screen. Kanban, SLA counters, and activity feeds update themselves.

Live

Automation that actually acts

A visual trigger engine fires on every ticket event with multi-criteria AND/OR logic. Bundle multi-step actions into one-click macros — triage happens before a human looks.

No-code

Your data never leaves. Ever.

Ticket summarization and reply drafting run against a self-hosted Ollama model — fully on-premises. Agents get instant context and polished drafts with zero external API calls.

Privacy-first AI

SLA deadlines stamped on the ticket

Per-priority response and resolution deadlines are stamped on every ticket. Overdue tickets flip an escalated flag that surfaces on dashboards and automation rules. Breaches never hide.

Escalation

Smart email routing

Inbound mail is thread-matched by Message-ID with UIDVALIDITY-aware polling — no duplicates, no rescans. An admin-authored, sandboxed JavaScript hook can reroute, discard, or force-append any email.

Scriptable

Customer context, built in

Group customers by company, share tickets within a team, and flag users or entire orgs as VIP — crowns appear everywhere, and automation can match on VIP status.

Organizations

Knowledge without leakage

Internal vs. public articles with strict scoping — internal content is never reachable by a customer through any path. Auto-suggest finds the right article while agents type.

Scoped

Role-aware dashboards

6 KPI tiles for agents, 6 for customers — with live metrics, activity feed, quick actions, and drag-to-rearrange layout that persists per browser.

Per-role
EventResolve agent dashboard: six KPI tiles (waiting time, escalation mood, channel distribution, assigned tickets) with team averages shown in gray, plus a live activity feed
Agent dashboard — six KPI tiles update live over server-sent events. Gray values are the team-wide average, so your numbers stack up against the queue at a glance.
Runtime stack

Self-contained. Reactive. On-prem.

No runtime internet dependency. No bolt-on caches. One JAR, one datastore.

  1. One Spring Boot JAR

    Java 25 + WebFlux non-blocking stack. Drop it in, it runs.

  2. NoSQL data lakes

    A single persistence layer. No JPA. No redundant caches.

  3. Bundled & offline

    Fonts, icons, AI models — all local. Runs air-gapped.

In production

What operators report

"EventResolve reduced our average first-response time from 4 hours to 45 minutes. Our agents finally have a tool that works as fast as they do."
— Director of Support, Global Telecom
"The AI summarization feature is a game-changer. I can catch up on any ticket in seconds."
— Senior NOC Engineer

Deploy it before lunch.

Quick setup with Docker Compose. Fully documented REST API. Enterprise support available.

Legal

Privacy Policy

Legal

Terms of Service

Contact

Book a walkthrough

Tell us about your network — device count, protocols in use, what your current stack misses. We'll run EventHorizon against your own telemetry, not a canned demo tenant.

hours Mon–Fri, SGT business hours
Contact form EVT-CONTACT