Anomaly Investigator

Turns a suspicious alert or unexpected asset change into a clear, evidence-based recommendation using live Lansweeper asset and vulnerability data.

The Anomaly Correlation Agent takes a Lansweeper asset, an alert, or a description of suspicious activity and investigates it end-to-end. It pulls live asset, vulnerability and software data from Lansweeper, correlates the event against recent change, incident and problem records, and weighs criticality against CVE severity and attack vector. It then recommends one of four actions and, with the user’s confirmation, can create the problem or incident record itself.

The agent works inside a live chat, so the investigator can ask follow-up questions, dig into a specific CVE, or ask the agent to check connected assets.

image 148

Requirements

Lansweeper MCP

https://mcp.lansweeper.com/mcp

LLM

Claude 3.5+ via Rovo (Atlassian’s agent platform runs on Claude models) and via the standalone Claude skill build

Designed to work with any ITSM tool connected via MCP, specifically Atlassian Rovo, but also Jira Service Management, ServiceNow, Freshservice.

Lansweeper plan

Starter, Pro, Enterprise

Skills It Uses

  • itsm-anomaly-investigator

    Claude skill — core investigation and recommendation logic

    Lansweeper MCP

    standard instruction (site confirmation, query catalogue, active-asset filtering, dataset reference)

Step by step setup guide

This agent is available on two platforms: Atlassian Rovo and Claude. Steps 1 to 3 are the same shape everywhere; the platform-specific detail is called out where the steps diverge. Follow the column for your platform.

Step 1 — Download

Download the agent package from the location in section 6 below, or ask your Lansweeper contact for the current build.

Step 2 — Open your agent platform

  • Rovo: open Atlassian Rovo from your Atlassian site and go to Agents.
  • Claude: open Claude Desktop or Claude Code.

Step 3 — Load the instructions

  • Rovo: create a new agent, paste the contents of the Rovo instruction set into the agent’s instructions field, and connect the Lansweeper MCP and Jira MCP.
  • Claude: load the itsm-anomaly-investigator skill file into your skills folder (Claude Desktop) or plugin directory (Claude Code). No manual paste needed.

Step 4 — Connect Lansweeper

Authenticate the Lansweeper MCP connection (EU or US endpoint, as required) and confirm you can see your site list. Both platforms need this step; only the connection method in each platform’s settings differs.

Step 5 — Connect your ITSM tool

Connect the Jira MCP. Confirm the agent can search for change, incident and problem tickets before using it live.

Step 6 — First-run configuration (Claude skill only)

The Claude skill asks for six values on first use: your ITSM platform name, what your organisation calls change, incident and problem tickets, which project or queue to create new records in, and which connected MCP to use for your ITSM tool. The Rovo version has these values built into the instructions, so this step does not apply to it.

Step 7 — Run a test investigation

Give the agent a test asset key, hostname, or alert ID and ask it to investigate. Confirm it queries Lansweeper directly rather than relying on alert text alone, searches Jira for a matching change record, and produces all four sections of the output format without fabricating CVE data.