Deterministic event correlation

Turn an alert storm into an investigation path

RouteGuard sits above the monitoring you already have and groups related network, cloud and security alerts into one evidence-led incident.

See the probable starting point, what it affected, what changed beforehand and what to check first.

Topology-awareExplainable confidenceChange correlationOutside routing view
RouteGuard incident showing 116 alerts correlated into one WAN failure, starting with an interface drop on the Manchester router
116 alerts. One incident.RouteGuard identifies the probable starting point and keeps the dependent symptoms in context.
Cause, not noiseTopology and routing context separate the first failure from its symptoms.
What changed?Recent config changes, commits and cloud maintenance are ranked by relevance.
The outside viewPublic looking-glass and RIPE RIS checks add internet routing context.
Auditable reasoningEvery confidence point has evidence. Time alone never links two alerts.

Causal timeline

See the first thing that broke and what followed

RouteGuard orders the initiating event first, then groups BGP, IP SLA and downstream device symptoms beneath it using topology and protocol context.

RouteGuard timeline with the initiating interface failure first and BGP, IP SLA and device alerts grouped beneath it
Incident timelineCause first, dependent symptoms beneath, recovery shown in sequence.

Change correlation

Check what changed before chasing every alarm

Configuration activity and cloud maintenance from the preceding half hour are ranked by proximity and relevance. In this scenario, a trunk VLAN removal explains sixteen camera outages.

RouteGuard incident tracing sixteen camera outages to a trunk VLAN removal on a distribution switch
What changedRelevant changes are connected to the affected topology and incident timing.

Explainable confidence

No black box behind the diagnosis

RouteGuard shows why a diagnosis gained confidence and which alternatives were considered. Confidence is deliberately capped because probable cause is evidence, not certainty.

RouteGuard confidence breakdown for a DDoS incident, with link congestion listed as a lower-scoring alternative
Confidence breakdownDDoS evidence is explained while ordinary congestion remains visible as an alternative.

Internet routing context

Understand how the incident looks from outside

Scheduled checks against Arelion's public looking glass and RIPE RIS help identify prefix visibility changes, more-specific announcements and possible route hijacks.

RouteGuard incident flagging a more-specific BGP announcement of the customer's prefix by an unauthorised AS
BGP incidentExternal routing evidence is connected to the service impact it may have caused.

Coverage

Network, cloud and security events in one model

RouteGuard understands the protocols and dependencies behind the alerts, so correlation is based on network relationships rather than timing alone.

Routing and topology

BGP, OSPF, EIGRP, IS-IS, BFD and LDP

Includes OSPFv3, HSRP/VRRP events, CDP neighbours and shared-dependency inference.

Access and cloud

PPPoE, Direct Connect and Site-to-Site VPN

Separates line, authentication and keepalive failures and includes AWS maintenance context.

RouteGuard incident list showing each incident's probable starting event, confidence and number of alerts
Incident boardOne line per incident, not one line per alert.

Preview boundary

Built and tested with synthetic incidents

  • Current validation covers thirteen synthetic incident scenarios.
  • RouteGuard identifies a probable starting point, not a guaranteed root cause.
  • Looking-glass checks run every few minutes; they are not a real-time BGP feed.
  • An optional AI summary can only restate facts already present in the incident.