SNMP MONITORING FOR MACOS, WINDOWS & LINUX

It learns your network, then tells you when it changes.

DeviceWatch polls your switches, routers, firewalls, access points and servers over plain SNMP — no agents to install, no collector to stand up, no cloud account. It watches reachability, every interface, traffic, errors, CPU, memory, disk, temperature, fans and power supplies. Then it does the part that thresholds cannot: it learns what normal looks like on each interface at this hour of this day, and speaks up when reality disagrees.

On-device AI Any SNMP brand Up to 250 devices 30-day free trial No cloud, no agents

DEMO

See it in action

ON-DEVICE AI

Three things it does, and none of them leave your computer.

Every vendor now writes "AI" on the box. Here is exactly what ours does, so you can judge it. There is no language model and no cloud inference — this is statistics that run on your own machine, on your own data, and keep running when the internet is down.

1. It learns what each interface normally carries

A static threshold is wrong twice. Set it at 80% and the backup link that always runs at 90% pages you nightly; set it high enough to silence that and you miss the access port that quietly went from 2 Mbps to 40. DeviceWatch instead builds a baseline per interface, per direction, at three levels at once: an overall moving average, a weekday-versus-weekend profile, and a per-weekday profile — each in 30-minute slots. Monday 09:00 is compared against what Monday 09:00 has looked like, not against a number someone typed in a year ago.

In a 21-day simulation over 30,240 samples with four injected faults, it found all four and raised zero false alarms. That number matters more than the detection rate: an anomaly detector that cries wolf gets muted within a week, and a muted detector detects nothing.

2. It learns which alarms you ignore

This is the part most monitoring tools never do. DeviceWatch watches what you do with each alarm. If you dismiss the same one five times, or acknowledge it within two minutes without acting, it learns that this alarm is noise on this device — and stops emailing it. It keeps showing it on screen; it just stops waking you.

It also learns the opposite. If a particular alarm keeps being followed by that device going down within the hour, DeviceWatch marks it a precursor and tells you so the next time it fires — the port errors that always come before this switch drops.

Two rules keep this honest. It never silences a device outage, no matter how often you dismiss one. And only your actual decisions are stored — the statistics are rebuilt from the event log every time, so nothing drifts into a black box you cannot audit or reset.

3. It forecasts when you run out of room

Robust trend regression over the stored history projects when a link, a disk or a memory pool reaches capacity. Robust, specifically, so that one bad afternoon does not become a fictional crisis three months out.

COVERAGE

Any brand that speaks SNMP.

Reachability, interfaces, traffic, errors and link state come from IF-MIB, which is identical on every manufacturer. CPU, memory, temperature and power have no such standard, so DeviceWatch carries vendor profiles — and we mark plainly which ones we have confirmed against real hardware and which come from vendor documentation alone.

Confirmed against actual devices: Cisco IOS / NX-OS, Cisco Small Business, Fortinet FortiGate, HP / Aruba ProCurve, Dell iDRAC / OpenManage, Silver Peak / Aruba EdgeConnect, and the standard MIBs that cover servers, Linux, Windows and appliances such as Palo Alto. Juniper, MikroTik and Huawei profiles ship from documentation and are labelled as unconfirmed inside the app.

A profile that turns out to be wrong costs you nothing — the device answers "no such object" and that one reading is simply absent. And when a device genuinely exposes no health data at all, as a cloud-managed access point does, DeviceWatch reports unknown rather than green. A device that has told us nothing has not told us it is well.

CAPACITY

How many devices can I add?

The licence covers up to 250 devices, and that is also the number we are willing to stand behind. It is not a marketing figure, but it is a projection: the sustained test ran at 40 devices, and the 250 figure is extrapolated from it. The binding constraint is disk, not polling. If your network is near that number, email us before you buy and we will size it with you.

Projected to 250

250devices

At 24 ports each, on a 30-second polling interval. Extrapolated from the measurements beside this — we have not run 250 devices ourselves.

  • ≈ 1.6 GB disk per year of history
  • ≈ 138 MB RAM
  • ≈ 20 ms to poll one device
  • Licence limit, and the number we stand behind

What we measured

0missed polls

40 devices at a 30-second interval, sustained.

  • Real 29-port Catalyst: 12 ms per poll
  • Nine real devices, nine vendors: all under 3 ms
  • 225 KB of disk per interface per year
  • 7.7 KB of memory per learned baseline

Above 250

Talkto us

Larger networks are a conversation, not a checkbox.

  • Custom device count on the licence
  • Sizing guidance for disk and retention
  • Longer polling intervals stretch further
  • Email us before you buy, not after

Installation and administration guide → — first run, settings, firewall rules, and connecting it to MeshWatch Central.

Minimum requirements. macOS 12 Monterey or newer (Apple silicon or Intel), Windows 10/11 or Windows Server 2016 or newer with Desktop Experience (64-bit), or 64-bit x86 Linux with a desktop environment. 4 GB RAM and 2 CPU cores for up to 50 devices; 8 GB RAM and 4 cores for up to 250. Disk grows with history — budget 225 KB per monitored interface per year, so 250 devices at 24 ports is about 1.6 GB annually. UDP 161 outbound to your devices; UDP 162 inbound only if you want to receive traps. The full measured breakdown ships with the app as SYSTEM-REQUIREMENTS.md.

WHAT YOU GET

Seven screens, no upsells between them.

Dashboard — devices monitored, what is not responding, open incidents, ports up, saturated links, and the busiest ports right now. Interfaces — every port with traffic, errors, discards, utilisation and history graphs. Health — CPU, memory, disk, temperature, fans, power supplies and modules, read from wherever that particular manufacturer puts them, using the device's own warning and critical thresholds when it publishes them. Map — a topology built from LLDP and CDP neighbour data, colour-coded so a hardware fault does not look like an unreachable device. Alarms — grouped by cause, so one core switch going down is one entry and not thirteen, with per-type control over what leaves by email and quiet hours that outages deliberately ignore. Reports — PDF export and scheduled delivery. Settings — polling intervals, SMTP, SNMP credentials in the operating system keystore, and full configuration backup.

Discovery takes a single IP, a range, or a CIDR block, tries your community strings in order, and tells you what it found — manufacturer, model, port count, and whether the device supports 64-bit counters, which you want to know before you rely on its traffic graphs on a gigabit link.

The interface is English by default, with Japanese, Korean and Simplified Chinese available.

DOWNLOADS

Get DeviceWatch

Every download is the complete product. It runs for 30 days without a licence key — all features, no device cap during the trial — and then asks for a key. Your collected history is never deleted when the trial ends.

What is new in 1.2.9. After the trial ends, polling really stops (Poll now included), and collected history stays viewable read-only. The trial can no longer be restarted by deleting the data folder, the licence panel explains saved keys, charts fill only where there are samples, map boxes no longer overlap, and changing the language applies at once.

What is new in 1.2.8. Connecting to MeshWatch Central now actually saves the token: a successful Test connection stores the address and token, turns the connection on, shows the connected state, and the button becomes Done. Before, the test passed but nothing was stored, so DeviceWatch never reported to Central. The Windows installer is now Authenticode-signed.

What is new in 1.2.7. The device list can be sorted by status, vendor or name, and the choice is remembered. Vendor is now filled in for devices added by hand, not only for discovered ones. Encrypted settings survive a change in credential storage, and the licence screen points to the Junk folder if the key email is not in the inbox.

What is new in 1.2.3. The dashboard explains itself before any device is added. On a fresh install it showed a row of zeros, which reads as a broken screen rather than an empty one; it now says what Discover does — scans your network for anything answering SNMP — and that read-only SNMP is enough, with nothing installed on the device itself. In English, Japanese, Korean and Simplified Chinese.

What is new in 1.2.1. DeviceWatch can now connect to a MeshWatch Central server: Settings has a MeshWatch Central section for the address and the token Central issues. Only alarm summaries are sent — never the SNMP data itself. This connection was written earlier but never shipped: 1.1.9 went out without it while this page already described it. That gap is closed. 1.1.9 fixed a bug where switching to the Health or Interfaces tab twice in quick succession (or clicking a chart's date-range button repeatedly) could stack a stale chart render on top of the current one, showing duplicate graphs. 1.1.7 added a Help menu with the running version number, so you no longer need to check the installer filename to tell what you have installed. 1.1.6 added an optional update check (Settings → Updates) — once a day it looks at a small file on this site to see if a newer version exists and tells you, nothing more. It is on by default but built for networks with no internet access: a failed check is silent, is not retried until the next cycle, and can be turned off entirely — including a policy switch for fleet deployments that locks the setting off. Nothing is downloaded or installed automatically. 1.1.1 added a map that shows the neighbours your switches know about but you have not added yet — with their IP address and model, so one click adds them. Devices can be edited and removed from the sidebar. And a long run against 47 real-world walks from around twenty manufacturers removed a class of false alarms: threshold direction and scale are now read the way each vendor actually publishes them, so a switch running at 30°C is no longer reported as critical, an administratively-off power supply is no longer a fault, and Linux cache memory is no longer a full disk. Genuine faults — a power supply that died, an optical link losing signal — still come through.

Signed & notarised · Version 1.2.9 · Apple silicon

macOS — Apple silicon

macOS 12 Monterey or newer. Signed with an Apple Developer ID and notarised by Apple — opens with no warning on double-click. Distributed directly rather than through the Mac App Store.

Download DMG · 114 MB

Signed & notarised · Version 1.2.9 · Intel

macOS — Intel

macOS 12 Monterey or newer on Intel hardware. Same build, same signature, x86-64. Notarised by Apple — opens with no warning.

Download DMG · 119 MB

Signed · Version 1.2.9

Windows — 64-bit

Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway. No administrator rights required.

Download Installer · 95 MB

Linux — portable AppImage

For Fedora, RHEL, Arch, openSUSE and anything else. Make it executable and run it directly.

Download AppImage · 122 MB

Verify your download

Run shasum -a 256 DeviceWatch-1.2.9-arm64.dmg and compare with the published checksum.

Checksums

PRICING

One price. No per-node maths.

Free trial

$030 days

The whole product, not a crippled preview.

  • Every feature unlocked
  • No device limit during the trial
  • No card, no account, no sign-up
  • Your history is kept when it ends
Download

Annual licence

$999/year

Up to 250 devices, every feature, every platform.

  • Up to 250 monitored devices
  • Unlimited interfaces per device
  • On-device AI: baselines, alarm learning, forecasting
  • All vendor profiles, all four languages
  • PDF reports and scheduled delivery
  • macOS, Windows and Linux — same key
  • Email support
Buy a licence

Larger networks

Custom

Above 250 devices, or a longer term.

  • Device count set on your licence key
  • Sizing help before you commit
  • Multi-year terms
Email us

A licence key arrives by email after checkout. It is sent from license@meshwatch.app, usually within a minute — if it is not in your inbox, check your Junk or Spam folder before writing to support. Paste it into the app and it unlocks on that computer. The key carries its own expiry and is verified against a public key built into the application, so activation works offline and DeviceWatch never contacts a licensing server — which also means an outage on our side can never stop your monitoring. One key covers macOS, Windows and Linux. When you renew you receive a fresh key; if a licence lapses, monitoring stops but nothing you have collected is deleted.

FAQ

Common questions

Does it run on a server?

Yes, and that is the expected deployment — Windows Server and Linux both. It is a desktop application in the sense that it has a window, so it needs a session to display in (a logged-in console, RDP, or a desktop environment on Linux). It does not run headless as a service today.

On a Linux server with no graphical session, it will not start and prints Missing X server or $DISPLAY. That is what the message means — nothing is wrong with the install. Either use a desktop environment on that machine, or forward the display over SSH with ssh -X.

How many devices can I actually add?

The licence permits 250. We measured 40 devices at a 30-second polling interval with zero missed polls, roughly 20 ms of work per device, and 225 KB of disk per interface per year. Extrapolated to 250 devices at 24 ports each, that is about 1.6 GB of disk per year and 138 MB of memory — comfortable on ordinary hardware.

The limit is disk and retention, not polling speed. If your devices have far more ports than 24, or you want years of history, size the disk accordingly or lengthen the polling interval. If you need more than 250 devices, email us before buying and we will size it with you.

Is the "AI" a language model?

No, and we would rather say so plainly than let the word do work it has not earned. It is statistical learning that runs entirely on your own computer: exponentially weighted baselines with three levels of seasonality for traffic, behavioural learning of which alarms you dismiss or acknowledge without acting, and robust trend regression for capacity forecasting. Nothing is sent anywhere, nothing needs an internet connection, and there is no per-token cost buried in your renewal.

Will the alarm learning hide a real outage from me?

It cannot. Device-down alarms are permanently excluded from suppression, and even for the alarm types it does learn, suppression only affects email — everything still appears on screen. It also requires a pattern before acting: at least five occurrences and an 80% dismissal rate. And because only your decisions are stored, with the statistics rebuilt from the event log each time, you can inspect or reset what it has learned.

Which SNMP versions are supported?

v1, v2c and v3. For v3, MD5/SHA/SHA-2 authentication and DES/AES/AES-256 privacy. Credentials are encrypted at rest using the operating system keystore — macOS Keychain, Windows DPAPI — and are excluded from configuration backups by default.

Do I need to install an agent on each device?

No. That is the point of SNMP. Enable it on the device, give DeviceWatch a community string or v3 credentials, and it polls over UDP 161. There is nothing to install on the monitored equipment, and nothing to keep updated there.

My device is not a brand you list. Will it work?

Reachability, interfaces, traffic, errors and link state will work, because those come from IF-MIB and every SNMP device implements it. CPU, memory and temperature depend on whether that vendor's profile is present, and the standard MIBs cover a surprising number of appliances on their own. Send us an snmpwalk from the device and we will add a profile — that is exactly how the confirmed profiles were built.

Does it need to run all the time?

To collect history, yes — it polls on a schedule and it can only record while it is running. It sits in the tray and can start at login. A gap in the graph means the application was not running; DeviceWatch does not fill in gaps with invented data.

Where is my data stored?

Only on your own computer, in your user data directory. Time series are fixed-size ring files, so disk use is predictable and does not creep. Nothing is sent to us. The one outbound connection DeviceWatch makes on your behalf is alarm email through the SMTP server you configure, and only if you set it up.

What happens when the trial ends?

Monitoring stops — devices are no longer polled, Poll now included — and the window asks for a key. You can close that screen with View collected data: interface and health graphs, alarms and reports stay viewable read-only. Nothing you collected is deleted — enter a licence and monitoring resumes with the history all still there.

Why is the macOS version not on the Mac App Store?

App Store distribution would restrict the local network access this application depends on and add a review cycle to every fix. It is distributed directly as a DMG signed with an Apple Developer ID instead.

Can I move my licence to another computer?

Yes. The key is not tied to hardware. Enter it on the machine you want to run monitoring from.

Does it work with MeshWatch Central?

Optionally. Connect DeviceWatch to your own MeshWatch Central server and its alarms join whatever ConfigWatch, CertWatch, TrafficWatch, SyslogWatch and TrapWatch are reporting into one shared inbox — an interface going down on the same device ConfigWatch just saw change shows up as one incident, not two unrelated alerts in two unrelated apps. DeviceWatch sends Central a one-line summary like “Gi0/3 link down” — never the SNMP data itself, never device credentials. Central is a separate product you run on your own server; DeviceWatch works exactly the same with or without it.

CONTACT

Questions, sizing help, or a walk from a device you would like supported? Email support@meshwatch.app or open a topic on the Support page.