ICM-EventInsight
Displays Windows server event logs in a form that's easy for operations staff to check.
Windows server event logs are voluminous and require specialized knowledge, so they tend to go unnoticed in normal times. ICM-EventInsight displays high-importance events in a form that's easy for operations staff to check, letting them view details only when needed — an on-premises monitoring tool. There is no automatic external transmission (telemetry) from the product, and it does not use a cloud LLM. If needed, it can also forward events via Syslog to ICM-Syslog for aggregation and analysis. Currently in preview.
Windows Event Logs, in a Form That's Easy to Check An on-premises Windows event monitoring tool
ICM-EventInsight displays Windows server event logs in a form that's easy for operations staff to check, letting them view details only when needed. In daily inspections, staff can grasp high-importance events in a short time.
Collection, Investigation, Forwarding, Notification, and Auditing From grasping events to notification and auditing, in a single tool
Check collected events by health score, and drill into details for notable events using the investigation panel. A single tool covers everything through to forwarding and notifying other systems as needed.
Displays the target server's health score and an importance summary on a single screen. High-importance changes can be checked early.
Aggregates similar events and provides an event list and investigation panel. Information is organized in the order conclusion → evidence → next action, so you can check what happened and whether a response is needed.
Lists the event channels being collected and lets you toggle them on or off. Server-role detection makes it easier to judge which channels deserve attention.
Configure forwarding policies and thresholds for Syslog, and verify connectivity with a test send. ICM-Syslog, the series' own product, is one example destination.
Supports email, Teams, OS notifications, and sound alerts. Thresholds and cooldowns can be configured so important events are notified at the frequency you need.
Check the health of ingestion, processing, and forwarding individually. Also supports audit-log tamper detection and version display, so you can inspect the tool's own status.
Series Integration Forward to ICM-Syslog and aggregate logs from multiple devices
Using ICM-EventInsight's "Forwarding" feature, you can send events that cross a threshold as Syslog to ICM-Syslog. In addition to monitoring that's self-contained within a single server, you can choose a configuration that aggregates logs from multiple devices and servers as the ICM Series and checks them across the board. ICM-EventInsight can be used on its own or as part of the series.
Screenshots (Coming Soon) UI PREVIEW — COMING SOON
Screenshot materials are currently being prepared. They will be posted as soon as the screens are ready.
About the Preview This is a product in a real, early stage.
- This is a real, early stage. ICM-EventInsight is not a concept-stage plan — it is a product actually running as rebuild/v3.
- Specifications may change. As this is a preview stage, the screens, features, and delivery format may change going forward.
- Part of the ICM Series. As the layer that handles Windows events, it's developed under the same design philosophy as ICM-Syslog and ICM-ThreatGuard.
- Ask us about early access. We're happy to discuss trials in your own environment and rollout timing.
Frequently Asked Questions
Does it send data externally?
What's the relationship with the ICM Series?
Can I use it now? What's the price?
Start with a conversation about preview use of ICM-EventInsight.
"We want to make our Windows server event logs easier to understand," "We want to try it on just one server first" — we welcome inquiries like these. We'll explain the current scope and rollout timing individually.