Stars
Forks
Watchers
Developer links
Keep
Keep is an open-source AIOps and alert management platform built with Python FastAPI and Next.js. It provides a single pane of glass for monitoring alerts from 110+ integrations, alert deduplication, correlation, enrichment, and filtering, YAML-based workflow automation similar to GitHub Actions, AI-powered correlation and summarization, and customizable dashboards for incident management. With 12,100+ GitHub stars, Y Combinator backing, and an Elastic partnership, Keep is the open-source AIOps platform that centralizes alert management across your entire monitoring stack into a single customizable dashboard. Alert deduplication identifies duplicate notifications across providers, correlation groups related alerts into incidents based on rules or AI-powered semantic analysis using pluggable LLM backends supporting OpenAI, Anthropic, and local models via Ollama, and enrichment adds context from external sources like CMDBs and databases. Workflow automation follows a GitHub Actions paradigm with declarative YAML files defining triggers, conditions, and actions that can query MySQL, update Jira tickets, send Slack messages, execute Python scripts, or call REST APIs. Authentication supports no-auth, database, Auth0, Keycloak, OAuth2 Proxy, Okta, and OneLogin. The Common Expression Language enables advanced alert querying, slicing, and rule-based grouping to reduce noise. On RepoCloud, deploy Keep on a dedicated VPS with Docker Compose, root SSH access, and complete control over your alert infrastructure, all under the MIT license.
Benefits
- Unified Alert Management Dashboard
- Centralizes alerts from 110+ monitoring tools including Datadog, Grafana, Prometheus, CloudWatch, and PagerDuty into a single customizable dashboard with real-time filtering using Common Expression Language.
- Intelligent Alert Deduplication and Correlation
- Automatically deduplicates alerts across providers and correlates related notifications into incidents using rule-based grouping or AI-powered semantic analysis with pluggable LLM backends.
- GitHub Actions Style Automation
- Declarative YAML workflows define triggers, conditions, and actions to query databases, update Jira tickets, send Slack notifications, execute Python scripts, or call REST APIs automatically.
- Enterprise-Grade Security and Scaling
- Supports SSO authentication via Auth0, Keycloak, OIDC, SAML, LDAP, Okta, and OneLogin with granular RBAC and ABAC access control, horizontal scaling, and air-gapped deployment options.
Features
- Alert Deduplication Engine
- Identifies and suppresses duplicate alerts across all connected monitoring providers, reducing notification noise with configurable matching rules and grouping criteria.
- Workflow Automation
- YAML-based declarative workflows with trigger events, conditional logic, and configurable actions including database queries, ticket updates, notifications, and script execution.
- Bi-Directional Integrations
- Connects to 110+ monitoring, incident response, ticketing, source control, change management, and CMDB systems with bi-directional synchronization keeping alerts in sync.
- AI Correlation Engine
- Groups related alerts into incidents using AI-powered semantic analysis with pluggable LLM backends supporting OpenAI, Anthropic, Azure, and self-hosted Ollama models.
- Alert Enrichment
- Automatically enriches incoming alerts with context from external sources including CMDBs, databases, and APIs using configurable enrichment rules and mappings.