- More information does not always mean greater clarity
- What generative AI brings to IT monitoring
- Dashboards, reports and executive summaries address different needs
- Events, reports and services provide different contexts
- The quality of the context determines the usefulness of the response
- A root cause hypothesis is still a hypothesis
- From technical information to prioritized actions
- How this approach is applied in Pandora AI Summary
- Where it can provide value in IT operations
- Model, prompt and context volume are also part of the analysis
- OpenAI API, costs and governance
- Generative AI, predictive AI and AIOps solve different problems
- AI is more useful when the evidence remains visible
- Frequently asked questions
An IT infrastructure can generate thousands of metrics, events, alerts and status changes. Having access to this information is essential for operations, but the volume of data also introduces another problem: determining what deserves attention, which elements may be related and where it makes sense to start investigating.
This is where one of the most practical uses of applied generative AI in IT monitoring comes into play. Based on information that a monitoring platform has already collected, a language model can help synthesize it, organize it and turn it into a structured interpretation.
For a NOC, an infrastructure manager, a support team or IT management, this capability can reduce some of the work devoted to reviewing fragmented information and make both prioritization and communication of system status easier.
Pandora FMS uses infrastructure monitoring as the foundation for monitoring systems, applications, databases, networks and other components of the IT environment. Different layers of analysis and interpretation can then be built on top of this information. The current Pandora FMS page presents this centralized monitoring of the stack precisely as the foundation of its monitoring approach.
More information does not always mean greater clarity
Monitoring answers specific questions very well: how much CPU is being consumed, when a module changed status, which systems are in a critical state, what events have occurred or what the status of a service is. The difficulty increases when several signals need to be interpreted at the same time. An operator may be faced with dozens of events, several degraded metrics and an affected service. Each piece of data provides part of the explanation, but it is still necessary to decide what is relevant, what may be related and what should be checked first. Events are a good example. Pandora FMS uses them as a record of the occurrences taking place in monitored systems, classifies them by severity and allows filters to be applied and saved in order to work with specific subsets of information. This ability to narrow down the information is especially important when generative AI is introduced. The better defined the context is, the easier it becomes to obtain a response related to the operational question being addressed.
What generative AI brings to IT monitoring
A language model can receive technical information and return it organized in natural language. Applied to IT operations, this opens up several practical uses: summarizing information, highlighting anomalies present in the context, ranking elements by relevance or suggesting lines of investigation. However, the model works only with the information it receives. Its response depends on the available context, how that context has been delimited and the instructions used to analyze it. This is why monitoring continues to play an essential role: collecting and structuring operational evidence. Generative AI adds a different capability, focused on interpreting and synthesizing that evidence. Pandora FMS has already explored this relationship between generative AI and IT operations, including the use of generative models to create narrative summaries of system states and integrate this type of capability with monitoring platforms. The concept is explored in greater detail in Generative AI in IT management.
Dashboards, reports and executive summaries address different needs
A dashboard provides a quick view of multiple indicators. A report brings information together according to a defined structure and makes it easier to review, distribute or analyze periodically. An executive summary generated using AI serves a different purpose: to synthesize the selected context and explain which elements stand out within it. For example, an executive overview may include:
- overall status
- relevant metrics
- alerts and anomalies
- elements requiring attention
- possible relationships between incidents
- hypotheses to guide the investigation
- actions that should be reviewed first
This is useful when the challenge is not accessing the data, but turning it into an overview that can be used quickly to make a decision, begin an investigation or communicate the status of an infrastructure.

Events, reports and services provide different contexts
The usefulness of AI depends largely on the question being answered. Analyzing recent events, summarizing a periodic report or interpreting the status of a business service are different tasks. That is why working with a defined context is more useful than indiscriminately sending all available information.
Event filters
Event filters make it possible to select a specific set of events and reuse saved searches. The current Pandora FMS documentation retains this capability in the current version. For a NOC, this can be used to focus the analysis on events of a specific severity, group, time period or operational scope.

Reports
Pandora FMS reports make it possible to bring together different elements and types of information within a reporting structure. The current documentation, which currently corresponds to version 803, includes elements related to graphs, modules, SLAs, events, inventory, alerts and other sources. Using a report as context opens up a different use case: transforming information already prepared for reporting into a synthesis focused on the main conclusions.

Services
Pandora FMS business services make it possible to group IT resources according to their function and represent how different components participate in a broader service. The current documentation also includes a specific section on root cause analysis. (Pandora FMS) This context is especially useful when the objective is to interpret the infrastructure from the perspective of its operational impact rather than solely from the isolated status of a device or module.

The quality of the context determines the usefulness of the response
Before assessing an AI-generated response, it is important to know what information the model has received. A context that is too broad may introduce irrelevant data. A context that is too limited may leave out information needed to interpret a situation correctly. The challenge is to include what actually helps answer the operational question. This selection also has practical implications: processed volume, query cost, governance and the operator’s ability to subsequently verify how the response was constructed. Pandora AI Summary includes a preview of the content that will be used before generating the summary. This allows the operator to check the selected data and know what context will be sent to the model. In the case of events, the extension also makes it possible to control the maximum number of events included in each request. This visibility is important for another reason: a generated response is easier to evaluate when we know exactly what evidence was available to the model.

A root cause hypothesis is still a hypothesis
One of the most interesting applications of a language model is its ability to relate the available information and propose a possible explanation of what is happening.
That explanation can be very useful for deciding where to begin an investigation.
However, it is important to distinguish between a root cause hypothesis and a confirmed root cause.
The model can reason about the events, metrics and relationships that are part of the context it has received. The actual cause may also depend on a recent change, a configuration, an external dependency, a log, human intervention or any other data that may have been left out of that context.
Technical validation requires comparing the hypothesis against the necessary evidence.
AI can therefore reduce reading time and provide an initial direction for analysis. The responsibility for confirming the diagnosis still lies with the technical team.
This limitation is relevant to any use of generative AI in IT operations: its usefulness increases when the model’s output is interpreted as support for the investigation rather than as an automatic truth.
From technical information to prioritized actions
The synthesis becomes more valuable when, in addition to describing the status, it helps prioritize attention.
Based on the available context, a response can structure information around:
- overall status
- key metrics
- alerts and anomalies
- hypotheses that warrant investigation
- immediate actions
- short-term actions
- elements that should continue to be monitored
This structure is especially useful in scenarios where the first need is to obtain a quick overview and then examine the technical evidence in greater depth.
It can also facilitate communication between profiles that require different levels of detail. The same set of information that an operator reviews metric by metric can be turned into a more manageable synthesis for an infrastructure manager or IT management.

How this approach is applied in Pandora AI Summary
Pandora AI Summary is a Pandora FMS extension that applies generative AI to operational information selected in the console.
The user can choose an event filter, a report or a service as context, review the information that will be included in the request and then generate a synthesis using the configured OpenAI model.
The result may include overall status, relevant metrics, alerts, anomalies, root cause hypotheses and recommended actions.
The functional details —complete workflow, configuration, requirements and available options— are covered on the dedicated Pandora AI Summary page.
Where it can provide value in IT operations
NOC and operations
When the volume of events is high, a synthesis can help quickly identify which elements stand out and what deserves an initial review.
Infrastructure managers
A technical report can be turned into a shorter overview that brings together status, anomalies and points requiring follow-up.
IT management
Information about systems, services and SLAs can be presented in a more accessible way for profiles that need to understand status and impact without reviewing every metric.
Technical support
A synthesis of the available data can provide an initial hypothesis and organize the first checks before going deeper into the investigation.
Model, prompt and context volume are also part of the analysis
The behavior of an application based on generative models does not depend solely on the selected model. It is also influenced by the context it receives and the instructions used to structure the response. Pandora AI Summary allows parameters such as the following to be configured:
- OpenAI API Key
- model
- temperature
- timeout
- maximum event limit
- system prompt
- update of available models
The OpenAI API uses API Keys to authenticate access, and the platform makes it possible to work with different models available for the corresponding account. (OpenAI Platform) The system prompt can be used to adapt, for example, the language, tone or structure of the response. The event limit helps control how much context is included in certain queries.
OpenAI API, costs and governance
Pandora AI Summary requires its own OpenAI API Key and connectivity from the console to the service. The OpenAI API platform is billed and managed separately from ChatGPT. API usage has its own billing system and depends on actual consumption. In a real-world implementation, three variables should be taken into account:
- selected model
It is also necessary to consider what information may be shared with an external provider according to each organization’s policies and requirements. For further technical information about the service, see the official OpenAI API platform.
Generative AI, predictive AI and AIOps solve different problems
The presence of artificial intelligence in IT operations covers very different technologies and use cases.
Generative AI
It works especially well with language and synthesis. In monitoring, it can use existing operational information to produce a structured overview, summarize a set of events or explain which elements stand out.
Predictive AI
It uses historical data and analytical models to estimate trends, detect anomalous behavior or anticipate needs.
Pandora FMS also provides predictive AI for IT management, with capabilities focused on resource forecasting and anomaly detection.
AIOps
AIOps covers a broader field and can combine analytics, correlation, machine learning, automation and operational assistance.
All three areas can coexist within an IT operations strategy, but it is important to keep their functions clear. A summary generated using an LLM is a generative AI use case; a prediction about how storage usage will evolve belongs to a different type of problem.
AI is more useful when the evidence remains visible
The integration of generative AI into monitoring delivers more value when it is based on clearly defined operational information and maintains a clear relationship between evidence and response.
Its practical usefulness lies in reducing some of the work required to interpret a large set of information, highlighting what deserves attention and turning technical data into an overview that helps begin an investigation or communicate the status of the infrastructure.
Pandora AI Summary applies this approach to elements that already exist in Pandora FMS: event filters, reports and services.
The user selects the context and can review it before the synthesis is generated. From there, AI can help organize the information, formulate hypotheses and propose actions that the team can later validate against the technical evidence.
Frequently asked questions
When does generative AI provide value in IT monitoring?
Generative AI is especially useful when there is enough operational information available, but interpreting it requires reviewing numerous events, metrics, reports or service statuses. It can synthesize that context, highlight which elements deserve attention and provide an initial structured overview that facilitates the team’s subsequent work.
How far can an AI-generated root cause hypothesis go?
A model can relate the information included in the context and suggest a plausible explanation. Confirming the cause requires checking it against dependencies, changes, configurations, logs and any other necessary evidence. For this reason, an AI-generated hypothesis can help guide the investigation, but it requires technical validation.
What determines the quality and cost of an analysis using an LLM?
The model used, the amount and relevance of the information sent, the prompt configuration and the frequency of queries all have an impact. Defining the context helps obtain responses that are more closely related to the problem being analyzed and also makes it possible to better control the volume of data processed.
Pandora FMS’s editorial team is made up of a group of writers and IT professionals with one thing in common: their passion for computer system monitoring. Pandora FMS’s editorial team is made up of a group of writers and IT professionals with one thing in common: their passion for computer system monitoring.






