{"repo":"jonny-jhnson/EventSight","free":true,"listed":false,"github":"https://github.com/jonny-jhnson/EventSight","clone":"git clone https://github.com/jonny-jhnson/EventSight.git","description":"AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve accuracy over time, and share learnings across your team. CLI and MCP server interfaces.","language":"Python","stars":37,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"EventSight AI-powered Windows Event Log analyzer that learns from analyst feedback. Project Structure This repository contains two related projects: Why Two Projects? Eventsight Eventsight-MCP --- ---------- -------------- Interface Command-line (CLI) MCP Server (Claude Code) RAG Type Standard RAG Agentic RAG Use Case Direct analysis & reporting Interactive analysis with Claude Feedback Manual commands Natural language via Claude Shared Resources Both projects share the same learnings database, meaning: - Learnings created in either project benefit both - Correlation rules are shared - Analysis improvements compound over time The shared data lives in Eventsight/data/learnings/ : - learnings.db - Analyst learnings, correlation rules, and analysis history - events.db - Stored events from analyses (indexed by Event ID, timestamp, provider) - embeddings.npy - 384-dimensional vector embeddings for semantic search - event embeddings.npy - Event embeddings for semantic event search Eventsight (CLI) The standalone command-line tool for Windows Event Log analysis. Features: - Parse and analyze EVTX files - Batch processing with streaming output - Continuous monitoring mode with live HTML report (auto-refreshing dashboard) - Standard RAG for fast, deterministic learning retrieval - Interactive feedback mode - HTML/Markdown report generation Quick Start: See Eventsight/README.md for full documentation. Eventsight-MCP (Claude Code Integration) MCP server that brings EventSight capabiliti","default_branch":null,"files":null,"tree":[],"storefront":"/r/jonny-jhnson","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/jonny-jhnson/EventSight/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}