Skip to content

About

AI-Powered Incident Response Bot: A production SRE tool automating log analysis via Python & Docker. It monitors AWS CloudWatch, uses a PII Scrubber for privacy, and leverages Amazon Nova Micro (AWS Bedrock) for root-cause analysis. Actionable fixes are sent to Slack, showcasing secure, modular, and automated DevOps remediation.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

14 Commits

Folders and files

Repository files navigation

🤖 AI-Powered Incident Response Bot

An automated SRE (Site Reliability Engineering) Assistant that transforms passive log storage into an active incident response system. This bot monitors AWS CloudWatch, scrubs sensitive data for privacy, and leverages Amazon Nova Micro via AWS Bedrock to deliver actionable fixes to Slack in under 60 seconds.


🚀 Key Features

Feature Description
Real-time Log Polling Continuously monitors CloudWatch Log Groups for ERROR, Exception, or Fail patterns
Privacy-First Scrubber Uses Regex to mask PII (IP addresses & Emails) before data leaves your environment
AI Root-Cause Analysis Leverages Amazon Nova Micro to generate human-readable explanations and 3-step remediation plans
Cross-Region Integration Fetches logs from any AWS region (e.g., ap-south-1) while utilizing AI models in us-east-1
Slack Automation Delivers instant alerts to your team's channel, significantly reducing MTTR (Mean Time To Repair)

📂 Project Structure

incident-response-bot/
├── main.py            # The "Heart"          — Orchestrates the main execution loop
├── analyzer.py        # The "Brain"          — Handles AWS CloudWatch & Bedrock logic
├── scrubber.py        # The "Shield"         — Privacy logic to mask sensitive data
├── config.py          # The "Nervous System" — Environment variable management
├── trigger.py         # The "Spark"          — Test script to simulate cloud incidents
├── .env               # Secrets (AWS Regions, Slack Webhooks — Git Ignored)
├── requirements.txt   # Python dependencies
└── Dockerfile         # Containerization blueprints

🛠️ Setup & Installation

1. Prerequisites

Before getting started, ensure you have the following:

  • Python 3.10+ installed on Ubuntu
  • AWS CLI configured with the appropriate permissions:
    • CloudWatchLogsReadOnlyAccess
    • AmazonBedrockFullAccess
  • Amazon Bedrock access enabled for the Nova Micro model in us-east-1
  • A Slack Incoming Webhook URL

2. Virtual Environment Setup

# Create and activate environment
python3 -m venv venv
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

3. Configuration (.env)

Create a .env file in the root directory:

AWS_REGION=ap-south-1
LOG_GROUP=/aws/lambda/production-logs
SLACK_URL=https://hooks.slack.com/services/YOUR/WEBHOOK/URL

🚦 Usage

Start the Monitoring Bot

python3 main.py

The bot will begin polling CloudWatch every 60 seconds. You should see:

🚀 Monitoring /aws/lambda/production-logs for incidents...

Simulate an Incident

In a separate terminal, run the trigger script to inject a fake error:

python3 trigger.py

About

AI-Powered Incident Response Bot: A production SRE tool automating log analysis via Python & Docker. It monitors AWS CloudWatch, uses a PII Scrubber for privacy, and leverages Amazon Nova Micro (AWS Bedrock) for root-cause analysis. Actionable fixes are sent to Slack, showcasing secure, modular, and automated DevOps remediation.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages