CROSS-PRODUCT ALERT CORRELATION · SELF-HOSTED

A config change, a link down, and a log spike on the same switch — that is one incident, not three alerts.

ConfigWatch, CertWatch, DeviceWatch, TrafficWatch, SyslogWatch and TrapWatch each watch their own thing well. None of them can see what the others just saw. Central is the console that can: it takes a one-line summary from each product — never the raw log, config, or certificate — and when two or more of them report on the same device within a short window, it shows that as a single incident with a timeline, not three unrelated rows in three unrelated apps. It runs on your own server, not ours. Enterprise, one edition, 30-day free trial.

Unified alert inbox Device inventory Incident correlation Role-based access Self-hosted Summaries only

DEMO

See it in action

How correlation works

Each product connects to Central with its own revocable token and sends a summary the moment it has something to say: severity, device name, one line of text, nothing else. When two or more products report on the same device within a 30-minute window, Central treats it as one incident and shows the timeline in order — the config change first, then the interface drop, then the log burst it caused. A single product repeating itself is not an incident; that already shows up fine in that product's own screen. Central only adds the connections a person would otherwise have to notice by having five windows open at once.

Only summaries cross the wire

Central never receives a raw log line, a configuration file, a certificate, a private key, or a packet capture — the allow-list is enforced on the receiving end, so a product with a bug can't leak more even by accident. What arrives is a severity, a device name, a kind, and a short sentence like "3 lines changed on GigabitEthernet0/3" or "certificate expires in 4 days." That is also why Central runs on a server you control: a summary you're comfortable generating is not the same as a summary you're comfortable sending to somebody else's cloud.

One inbox instead of six tabs

Every alert from every connected product lands in one list, filterable by product, severity, device, or acknowledgement state, sorted by when it actually happened rather than when it happened to arrive. Acknowledging an alert records who did it and when — the audit trail a solo operator doesn't need and a team of three immediately does.

One device list instead of six

The same switch reported by ConfigWatch and DeviceWatch shows up as one row with both products listed against it, not two rows that happen to share an IP address. Devices reporting a "down" status from any product sort to the top.

Accounts your team can actually share

Three roles: admin (accounts, tokens, settings, licence), operator (acknowledges alerts, can't touch configuration), viewer (read-only — audit, management, the night shift). Every write is checked on the server, not just hidden in the UI, and every acknowledgement and configuration change is logged with who and when.

Products keep working if Central doesn't

Nothing is queued to a server Central doesn't control, and no product depends on Central to do its own job. If Central is unreachable, each product keeps monitoring exactly as it did before Central existed — the connected products lose the shared inbox and correlation, nothing else.

INSTALL

Runs on your server, not ours

Docker · Recommended

One command

Docker has to be installed and running first. Central is meant to sit on a server that stays on, not on a laptop.

Linux server — the straightforward case. Install Docker Engine from your distribution’s packages and run the command below. The image is x86-64 and arm64, so it runs on both.

Windows Server — read this first. The Central image is a Linux image, and Windows Server’s own container mode runs Windows containers, so it cannot run this image directly. You need a Linux environment on that host: WSL 2 with Docker installed inside it, or a Linux VM on Hyper-V. Docker Desktop is not supported on Windows Server. If a Linux host is available, that is the shorter road. If it is not, skip Docker entirely and use the Node bundle below — Node runs natively on Windows Server.

Windows 10 or 11, or macOS — for trying it out rather than running it: install Docker Desktop, start it, and wait until it says Running.

Once Docker is there, nothing else needs installing — the image is self-contained.

docker run -d --name meshwatch-central -p 8443:8443 -v central-data:/data ethan99199/meshwatch-central:1.3.8

Kept on one line on purpose. A backslash-continued version is easier to read but breaks when it is pasted into PowerShell, which does not use backslash to continue a line.

Then open http://<your-server>:8443 — or http://localhost:8443 if you are on the machine itself — and create the first administrator account. That screen only ever appears once.

Note the http://. Port 8443 usually means HTTPS, but Central speaks plain HTTP until you put a reverse proxy in front of it, so https:// will simply fail to connect.

Check it started

You should see Up … (healthy). The image pulls in a minute or two the first time.

docker ps --filter name=meshwatch-central

If the shell answers docker: The term 'docker' is not recognized (or command not found), Docker itself is missing — or you opened the terminal before installing it, in which case a new terminal window will find it.

If the container is missing, ask it why:

docker logs meshwatch-central

Without Docker

Node.js 18 or newer, nothing else — Central has no npm dependencies. This is usually the shorter road on Windows Server, where running a Linux container means WSL 2 or a VM but Node runs natively.

Download it, unpack it, start it. No account, no email address, no waiting for us.

It contains a START-HERE-WINDOWS.txt with these steps, and LICENCE.txt. Check it against the published checksums if you like.

Licensed, not open source. Run it on your own servers as much as you like. Redistributing it, or offering it to others as a service, is not permitted — the terms are in the archive.

On Linux and macOS:

MWC_DATA_DIR=/var/lib/meshwatch-central node src/server.js

In PowerShell, the variable is set separately:

$env:MWC_DATA_DIR = "C:\ProgramData\meshwatch-central"; node src\server.js

Connecting a product

In Central, open the Agents tab and issue a token for the product — it's shown once. In that product's own Settings, paste in Central's address and the token. Repeat for each product you want correlated.

Installation and integration guide → — installing on Linux or Windows Server, issuing tokens, and connecting each product.

HTTPS behind a reverse proxy is recommended for anything reachable outside a trusted network — set MWC_SECURE_COOKIES=1 once it is, or session cookies won't be marked Secure and login will not work correctly over plain HTTP with that flag on.

PRICING

One edition. Try it free for 30 days.

Enterprise

$1,188/year

Everything Central does, for as many connected products and devices as you have.

  • Unified alert inbox across all connected products
  • Cross-product incident correlation
  • Unified device inventory
  • Unlimited admin / operator / viewer accounts
  • Full audit log
  • Configurable retention (up to 730 days)
  • Self-hosted — your server, your data
Buy MeshWatch Central

Or install and start the 30-day trial first — no card, no account.

Central is sold separately from the six products it connects to — it does not replace ConfigWatch, CertWatch, DeviceWatch, TrafficWatch, SyslogWatch or TrapWatch, and you don't need all six to use it. It works with however many you have; correlation itself needs at least two reporting on the same device to have anything to show. When the trial or a subscription lapses, Central stops accepting new data from connected products until reactivated — nothing is deleted, and every product keeps monitoring on its own either way.

FAQ

Common questions

Do I need to own all six MeshWatch products?

No. Central works with however many you connect — even one. Owning more products makes the correlation feature more useful, since that needs at least two products reporting on the same device, but nothing about pricing, licensing, or installation requires owning the rest of the line.

Where does Central actually run?

On a server you control — your own hardware, your own VM, your own cloud account. MeshWatch does not host it and cannot see your data. That's also why the licence is checked offline: activation works even on a server with no route to the public internet.

What exactly gets sent to Central?

A severity level, a device name, a short category, a one-line summary, and a timestamp — enforced by an allow-list on Central's receiving side, so a bug in a connected product can't leak more even by accident. Never a raw log line, a configuration file, a certificate, a private key, or a packet capture.

What counts as one incident?

Two or more different products reporting on the same device within a 30-minute window. A single product alerting repeatedly about the same device is not treated as an incident by Central — that repetition is already visible in that product's own screen, and each product manages its own alert fatigue (cooldowns, hourly caps, digests) before anything reaches Central.

What happens if Central goes down?

Every connected product keeps monitoring exactly as before — nothing is queued to Central, and no product depends on it to function. You lose the shared inbox and correlation until Central is back; you don't lose any monitoring.

What happens when the trial or subscription ends?

Central stops accepting new data from connected products — nothing already stored is deleted, and you can still view it. Connected products are unaffected and keep monitoring on their own. Entering a licence key resumes normal operation immediately.

How is a token revoked if a laptop is lost?

Open the Agents tab and revoke it — the token stops working immediately, and nothing else needs to change. Issuing a new token for that product takes one click.

What are the system requirements?

Two ways to run it. The Docker image is a Linux image — it runs on a Linux host, and on macOS or Windows 10/11 through Docker Desktop. It does not run on Windows Server’s own container mode, which runs Windows containers; there you would need WSL 2 or a virtual machine. The alternative is the Node bundle: Node.js 18 or newer and nothing else, which runs natively on Windows Server as well as Linux and macOS.

Central itself is lightweight. The resource to plan for is disk space for retained alerts, which scales with how many devices you connect and how long you keep data.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.