Case study · AI agents & RAG
WiFi log intelligence with RAG
A retrieval-augmented diagnostic assistant for WiFi support. It parses raw device logs into sessions and causal chains, remembers how experts resolved past cases, and answers a customer’s question with the specific evidence behind the diagnosis — and what to do next.
- 7analysis passesPattern, event, session, temporal, causal-chain, anomaly and RSSI analysis
- 3vector memoriesAnalyzed sessions, expert memory and feedback memory in ChromaDB
- 1question in, one diagnosis outRanked causes, the evidence lines behind them, and an action
The challenge
WiFi complaints arrive as vague symptoms — “the internet is slow” — while the evidence is buried in thousands of log lines: WiFi events, DHCP messages, ARP requests, reboots. Diagnosis depended on a few senior engineers who knew which patterns mattered, and their past conclusions lived in issue files nobody could search.
Our approach
We split the problem in two. An analysis engine does the deterministic work — grouping events into sessions, detecting temporal patterns and causal chains, interpreting signal strength — guided by a domain dictionary of session types, event patterns, severity levels and anomaly rules. A retrieval layer then combines those findings with an expert memory of past cases, so the language model writes its diagnosis from real evidence rather than general knowledge.
Workflow
How it works, step by step.
The pipeline in 5 stages, from ingest to diagnose. Each stage has a clear input, a clear output and a reason to exist.
- 01
Ingest
Raw device logs — WiFi events, DHCP messages, ARP requests — plus a domain dictionary of session types, event patterns, severity levels and anomaly rules.
- 02
Analyze
Pattern matching, event classification and session grouping, then temporal analysis, causal-chain and anomaly detection, and RSSI interpretation.
- 03
Remember
Analysis results and expert memory — past cases, conclusions, recommended actions — embedded into ChromaDB, with a cache for frequent queries.
- 04
Retrieve
The question is embedded; semantic search pulls matching sessions and similar past cases and assembles the context.
- 05
Diagnose
The LLM receives the assembled evidence and returns a ranked diagnosis with a concrete action; feedback is stored for next time.
Results
What it produced.
Example interaction
Your internet slowness is caused by:
- WAN link flapping detected
- ARP failures — gateway unreachable
- Weak signal (RSSI −75 dBm)
Action: check the cable connection
What the model sees before it answers
- Matching log sessionsReboot bursts, WAN flapping, ARP sequences, disconnect reasons and speed variance found by the analysis engine.
- Similar past casesIssues engineers already solved, with their conclusions, retrieved by semantic search.
- Recommended actionsThe fixes experts applied last time — so the answer ends with something to do.
- Feedback memoryEngineer feedback on earlier answers, stored and reused on the next query.
Stack & techniques
- Python
- RAG
- ChromaDB
- sentence-transformers
- paraphrase-multilingual-MiniLM-L12-v2
- Anthropic Claude API
Delivered by members of the Saerosense founding team. Client names are withheld unless public — references are available on request.
Start a project
Have a similar problem?
Send a few lines about your data and the outcome you want. We reply within two business days with a feasibility read and a proposed scoping plan.
