monitoring-aiops
Use this skill whenever the user needs to operate a network / infrastructure monitoring NOC on SolarWinds Orion (SWIS REST + SWQL), Paessler PRTG (web API), or Zabbix 6.x/7.x (JSON-RPC) — a one-shot NOC overview, canned SWQL answers (nodes down, flapping interfaces, muted, high-CPU nodes, full volumes, unmanaged/scheduled), a validated read-only SWQL passthrough, deduped/rolled-up active alerts, SolarWinds node/interface/volume/application health and top-N, PRTG sensors/devices/groups/history/alarms, Zabbix problems/hosts/host-groups/triggers/events/item-history/maintenances, and guarded writes (acknowledge, mute/unmute, schedule maintenance, unmanage/remanage, remove node, pause/resume sensor, create/delete Zabbix maintenance window). Always use this skill for "SolarWinds", "Orion", "SWQL", "THWACK question", "PRTG", "Paessler", "Zabbix", "Zabbix problem", "Zabbix trigger", "Zabbix maintenance", "NOC overview", "which nodes are down", "flapping interfaces", "interface flap storm", "alert storm", "acknowledge this alert", "worst CPU nodes", "top-N by latency/packet loss", "which volumes are full", "muted alerts report", "unmanaged nodes", "schedule a maintenance window", "unmanage / remanage a node", "pause a PRTG sensor" when the context is monitoring. Do NOT use when the target is something other than a SolarWinds/PRTG/Zabbix monitoring platform (a hypervisor, storage appliance, backup product, Kubernetes cluster, network device config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Governed monitoring operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). PRTG's free Freeware edition and an open-source Zabbix appliance are the easiest live checks; SolarWinds is trial-only past 30 days.
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
0.10.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.10.4release · observed Sep 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:monitoring-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:monitoring-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/monitoring-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-monitoring-aiops/snapshot"
Documentation
CLAWHUB
150,948 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: monitoring-aiops
slug: monitoring-aiops
displayName: "Monitoring AIops"
summary: "Governed SolarWinds Orion + PRTG + Zabbix ops: SWQL, alert rollup, health, 42 tools."
license: MIT
homepage: https://github.com/AIops-tools/Monitoring-AIops
tags: [aiops, mcp, governance, monitoring]
description: >
Use this skill whenever the user needs to operate a network / infrastructure monitoring NOC on SolarWinds Orion (SWIS REST + SWQL), Paessler PRTG (web API), or Zabbix 6.x/7.x (JSON-RPC) — a one-shot NOC overview, canned SWQL answers (nodes down, flapping interfaces, muted, high-CPU nodes, full volumes, unmanaged/scheduled), a validated read-only SWQL passthrough, deduped/rolled-up active alerts, SolarWinds node/interface/volume/application health and top-N, PRTG sensors/devices/groups/history/alarms, Zabbix problems/hosts/host-groups/triggers/events/item-history/maintenances, and guarded writes (acknowledge, mute/unmute, schedule maintenance, unmanage/remanage, remove node, pause/resume sensor, create/delete Zabbix maintenance window).
Always use this skill for "SolarWinds", "Orion", "SWQL", "THWACK question", "PRTG", "Paessler", "Zabbix", "Zabbix problem", "Zabbix trigger", "Zabbix maintenance", "NOC overview", "which nodes are down", "flapping interfaces", "interface flap storm", "alert storm", "acknowledge this alert", "worst CPU nodes", "top-N by latency/packet loss", "which volumes are full", "muted alerts report", "unmanaged nodes", "schedule a maintenance window", "unmanage / remanage a node", "pause a PRTG sensor" when the context is monitoring.
Do NOT use when the target is something other than a SolarWinds/PRTG/Zabbix monitoring platform (a hypervisor, storage appliance, backup product, Kubernetes cluster, network device config, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill.
Governed monitoring operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). PRTG's free Freeware edition and an open-source Zabbix appliance are the easiest live checks; SolarWinds is trial-only past 30 days.
installer:
kind: uv
package: monitoring-aiops
argument-hint: "[node/sensor id, a SWQL question, or describe your NOC task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["monitoring-aiops","uvx"]},"optional":{"env":["MONITORING_AIOPS_CONFIG","MONITORING_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Monitoring-AIops","emoji":"📡","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed monitoring operations across SolarWinds Orion (SWIS REST + SWQL, port 17774 on Orion 2023.1+ with an automatic one-shot fallback to the legacy 17778, HTTP Basic auth), Paessler PRTG (web API, port 443/8080, API token), and Zabbix 6.x/7.x (JSON-RPC 2.0 at /api_jsonrpc.php, API token as Bearer header on 6.4+/7.x with a legacy auth-field fallback for 6.0). Each target in the config names its own platform, so one config can span all NOCs_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "monitoring-aiops",
"version": "0.10.4",
"publishedAt": 1789601158731
}references/agent-guardrails.md
# Agent guardrails — running monitoring-aiops with a smaller / local model If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose, Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably better results with a short system prompt. This page gives you one, and — more importantly — tells you which guardrails you **no longer need to write**, because the tool now enforces them itself. The distinction matters. A guardrail in a prompt is a request. A guardrail in the harness is a guarantee. Anything below that we could move into the harness, we did. ## Authorization is not this tool's job — decide it where it belongs Whether a write should happen is your decision, or the account's. The tool does not gate it — there is no read-only switch and no approval prompt to configure. The two right places to control read vs write: - **The account you connect with.** Give it a SolarWinds/PRTG/Zabbix login with read-only monitoring scope. A write then fails at the server, which is the only place the permission actually lives — no skill-side flag can be argued around by a model, but a revoked permission cannot be. - **Your agent's system prompt.** If you want an observe-only session, tell the model not to call the write tools (they are clearly tagged `[WRITE]`). What the tool *does* guarantee is that you can always see what happened: ## What the tool enforces — do not waste prompt budget on these | You might be tempted to prompt | Why you don't need to | |---|---| | "Never write to the monitoring database" | `swql_query` accepts a single read-only `SELECT` and nothing else — no verb invoke, no multi-statement, no DELETE. Orion state changes only happen through the named, governed write tools. | | "Don't invent a value when a field is missing" | A column the platform did not return comes back as `null`, never as `""`. An absent Orion `StatusDescription`, a PRTG sensor `message`, a Zabbix host `dns` — all distinguishable from a genuinely empty one. | | "Tell me if the output was cut off" | Every row-capped read returns `returned` / `limit` / `truncated`: `swql_query`, `swql_canned`, `list_events`, `zabbix_events`, `zabbix_item_history`, and `interface_status` with a `top`. Truncation is measured — one row past the cap is fetched, or the full set is counted before the cut — never guessed from a length coincidence. | | "Deduplicate the alert storm before showing me" | `active_alerts` already rolls repeats of the same message into one row with a `count` and up to three `examples`, worst-first. Report the rollup; do not re-count the raw list. | | "Normalise severity across platforms" | Zabbix's 0–5 scale is already mapped to canonical `level` values (`info`/`warning`/`high`/`critical`) alongside the platform's own `severity` name. Use `level` for cross-platform statements and `severity` when quoting the platform. | | "Confirm before anything disruptive" | `remove_node`, `unmanage_node`, `mute_alerts` and the main
references/capabilities.md
# monitoring-aiops capabilities > **42 MCP tools** (30 read, 10 write, 2 undo) across SolarWinds > Orion (SWIS REST + SWQL, port 17774 with a legacy-17778 fallback, HTTP > Basic auth), Paessler PRTG (web > API, port 443/8080, API token), and Zabbix 6.x/7.x (JSON-RPC 2.0 at > `/api_jsonrpc.php`, API token — Bearer header on 6.4+/7.x, legacy `auth` > field fallback for 6.0). Each config target names its own `platform`. > SWIS/PRTG/Zabbix responses are mocked and need live verification. ## SWQL — SolarWinds (read) | Tool | SWQL / path | Returns | |------|-------------|---------| | `swql_library` | (local) | the catalogue of canned queries: `nodes_down`, `flapping_interfaces`, `muted_report`, `high_cpu_nodes`, `volumes_full`, `unmanaged_scheduled` | | `swql_canned` | named SWQL → SWIS `/Query` | rows for the named canned query | | `swql_query` | validated read-only SWQL → SWIS `/Query` | rows for a caller SELECT (SELECT-only; rejected otherwise) | ## Alerts — all platforms | Tool | Risk | Path | Returns / effect | |------|------|------|------------------| | `active_alerts` | read | SWIS `AlertActive`/`AlertObjects`, PRTG `/api/table.json?content=messages`, or Zabbix `problem.get` | active alerts **deduped/rolled up by message** — flap/down storms collapse into one counted entry | | `alert_acknowledge` | write **medium** | SW `AlertActive.Acknowledge` verb / PRTG `acknowledgealarm.htm` / Zabbix `event.acknowledge` (action 6; prior ack state → priorState) | acknowledges an alert / alarm / problem event | ## SolarWinds health (read) | Tool | SWQL / path | Returns | |------|-------------|---------| | `node_status` | `Orion.Nodes` | one node's status, CPU/mem, response time | | `nodes_list` | `Orion.Nodes` | node inventory (status, vendor, IP, last boot) | | `interface_status` | `Orion.NPM.Interfaces` | top-N interfaces by utilisation (in/out, errors, oper status) | | `volume_status` | `Orion.Volumes` | volumes by % used (size, used, type) | | `application_status` | `Orion.APM.Application` (SAM) | SAM application/component status | | `topn` | `Orion.Nodes` metrics | top-N nodes by `cpu` / `memory` / `latency` / `packetloss` | | `noc_rollup` | folds `Orion.Nodes` | down/warning counts + worst-CPU nodes in one call | ## SolarWinds writes | Tool | Risk | Path / verb | Undo / safety | |------|------|-------------|---------------| | `list_events` | read | `Orion.Events` | recent events (read) | | `list_unmanaged` | read | `Orion.Nodes` where Unmanaged | currently-unmanaged nodes (read) | | `list_muted` | read | `Orion.AlertSuppression` | currently-muted objects (read) | | `mute_alerts` | write **med** | `AlertSuppression` (SuppressAlerts) | **time-boxed** (requires end time); records inverse **unmute** undo | | `unmute_alerts` | write **med** | `AlertSuppression` (ResumeAlerts) | un-suppresses alerting | | `schedule_maintenance` | write **med** | `AlertSuppression` window | **requires an end time** (time-boxed maintenance window) | | `unmanage_node` |
references/cli-reference.md
# monitoring-aiops CLI reference
> Covers SolarWinds Orion (SWIS REST + SWQL), Paessler
> PRTG (web API), and Zabbix 6.x/7.x (JSON-RPC); SWIS/PRTG/Zabbix responses are
> mocked and need live verification.
> The CLI is a convenience subset — the full 42-tool surface is via the MCP
> server (`monitoring-aiops mcp`).
## Setup & diagnostics
```bash
monitoring-aiops init # interactive wizard (asks for the platform: solarwinds/prtg/zabbix)
monitoring-aiops doctor [--skip-auth] # config + secret store + connectivity
# SolarWinds: a SWQL query · PRTG: /api/status.json
# Zabbix: apiinfo.version (no auth) + authed host count
monitoring-aiops mcp # start the MCP server (stdio transport)
```
## Secrets (encrypted store ~/.monitoring-aiops/secrets.enc)
```bash
monitoring-aiops secret set <target> [--value <secret>] # store Orion password / PRTG or Zabbix token (hidden prompt if no --value)
monitoring-aiops secret list # names only — secrets never shown
monitoring-aiops secret rm <target>
monitoring-aiops secret migrate # import legacy plaintext env (MONITORING_<TARGET>_SECRET)
monitoring-aiops secret rotate-password # re-encrypt under a new master password
```
## Overview
```bash
monitoring-aiops overview [--target <t>] # NOC summary: platform + active/unacked alert counts + top rollup
```
## SWQL (SolarWinds)
```bash
monitoring-aiops swql library # list the canned queries
monitoring-aiops swql canned <name> # run a canned query: nodes_down, flapping_interfaces,
# muted_report, high_cpu_nodes, volumes_full, unmanaged_scheduled
monitoring-aiops swql query "SELECT ..." # validated read-only SWQL passthrough (SELECT only)
```
## Alerts (all platforms)
```bash
monitoring-aiops alert list [--target <t>] # active alerts, deduped/rolled up by message
monitoring-aiops alert ack <alert_id> # acknowledge an alert / PRTG alarm / Zabbix problem event
```
## Common options
- `--target, -t <name>` — target name from `config.yaml` (omit to use the
default/first target); each target declares its own `platform`
- `overview`, `swql`, and `alert` are the CLI subset; the remaining SolarWinds
health, PRTG, Zabbix, and governed-write tools (mute/unmute,
schedule_maintenance, unmanage/remanage/remove node, PRTG pause/resume,
Zabbix maintenance create/delete) are exposed through the MCP server.
High-risk MCP writes use dry-run + double-confirm; `MONITORING_AUDIT_APPROVED_BY`
/ `MONITORING_AUDIT_RATIONALE` are recorded on the audit row when set.AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/monitoring-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/monitoring-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:22:24.953Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-monitoring-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-monitoring-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T04:22:24.953Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceUrl": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:22:24.953Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.10.4",
"href": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceUrl": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:25:58.731Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-monitoring-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-monitoring-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.10.4",
"description": "monitoring-aiops 0.10.4 - Updated agent guardrails documentation in references/agent-guardrails.md. - Removed redundant skill-card.md file. - No changes to functional behavior or features.",
"href": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceUrl": "https://clawhub.ai/zw008/monitoring-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-16T23:25:58.731Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
