What the project solved
The sponsor had one Level 1 admin responsible for a FortiGate 60E, a FortiSwitch 424E, and a Ruckus R650 AP. There was no central place to look. Triage meant logging into three vendor consoles and reading raw syslog, and by the sponsor's estimate it took 45 to 60 minutes to work through a single batch.
The hard constraint was that the gear sat on a live client network. Anything that touched real telemetry had to stay on-prem. No cloud LLM API, no SaaS SIEM, nothing that called out to the internet for analysis.
PlainSight became the single pane that sat in front of all of that. Telemetry came in, got normalised, got scored, got summarised by a local model, and got presented in a form a Level 1 could actually act on. A one-click PDF on the way out covers management reporting.
Outcome: Triage time dropped from 45 to 60 minutes down to under 10 seconds for AI-summarised batches in lab testing. The number that matters more to me is that the dashboard gives you a starting point that is not "go read all the logs".