GUIDES › DeviceWatch
Other languages English · 日本語 · 한국어 · 简体中文
DeviceWatch
SNMP monitoring for switches, routers and servers — 1.2.9
In this version
- After the trial ends, Poll now no longer queries devices; the trial-ended screen can be closed and collected history opens read-only.
- Deleting the data folder no longer restarts the 30-day trial: the trial start is also recorded outside the data folder, and the earliest record wins. The check stays on this computer.
- The licence panel no longer contradicts itself: during a trial it shows the trial and its days left, and a saved key that has expired or is not valid is marked as not in use, with a Remove button.
- Traffic and health charts fill only where there are samples (no more wedge from the left edge), and network map boxes no longer overlap.
- The Windows installer is Authenticode-signed and timestamped.
1. Install
Pick the build for the machine you are installing on. Every file below is the current release; older versions are listed on the release notes page.
- macOS · Apple silicon DeviceWatch-1.2.9-arm64.dmg
- macOS · Intel DeviceWatch-1.2.9-x64.dmg
- Windows installer DeviceWatch-1.2.9-x64.exe
- Windows portable ZIP DeviceWatch-1.2.9-x64.zip
- Linux · Debian/Ubuntu DeviceWatch-1.2.9-amd64.deb
- Linux · AppImage DeviceWatch-1.2.9-x86_64.AppImage
Verify what you downloaded. The published checksums are at DeviceWatch-SHA256SUMS.txt
On macOS or Linux:
shasum -a 256 DeviceWatch-1.2.9-arm64.dmg
On Windows:
Get-FileHash -Algorithm SHA256 DeviceWatch-1.2.9-x64.exe
The macOS build is notarised by Apple, so it opens without a warning. The Windows installer is Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.
2. First run
- Enable SNMP on the equipment you want to watch. Nothing is installed on those devices.
- Give DeviceWatch a community string for v1/v2c, or v3 credentials. Read-only is enough — DeviceWatch never writes to a device.
- Discovery accepts a single IP address, a range, or a CIDR block.
- Polling goes out over UDP 161. Inbound UDP 162 is only needed if you want to receive traps.
Every install starts with a 30-day trial of the paid edition. Nothing is asked for up front — no card, no account, no email address.
3. Administration
Licensing by device count
The paid edition is licensed for up to 250 devices. That number comes from measurement, not marketing: 250 is roughly where a 30-second polling cycle stops having comfortable headroom on disk. Larger networks are a custom arrangement.
Baselines and alarms
DeviceWatch learns what normal looks like for each device and alarms on departures from it. This runs inside the application; nothing is sent anywhere to compute it.
Neighbour map
The map shows neighbours your switches know about but you have not added yet, with IP and model, so one click adds them.
Device list order
From 1.2.7, the control above the device list sorts it by Status (down first) — down, then unknown, then hardware alerts, then up — by Vendor, or by Name. The choice is remembered the next time DeviceWatch opens. Vendor is read from the device’s SNMP system identifier each time it is polled, so devices added by hand have one too, not only those found by Discovery. Devices without a recognised vendor sort after the rest.
Updates
Settings → Updates. Once a day it checks a small file on this site for a newer version and tells you — nothing is downloaded or installed automatically. It can be turned off, including a policy switch that locks it off for fleet deployments.
Where your data lives
Everything DeviceWatch records stays on the computer it runs on. None of it is sent to us, to an analytics company or to an advertising network.
Licence keys
The key arrives by email after purchase. It is checked on this computer, so DeviceWatch never contacts a licensing server. DeviceWatch has no free tier. When the 30-day trial ends, monitoring stops — devices are no longer polled, Poll now included — and everything collected so far (interface graphs, alarms, reports) stays viewable read-only. Enter a key and monitoring resumes.
4. Firewall
- Outbound — UDP 161 to your devices. Most firewalls allow this by default.
- Inbound (traps only) — UDP 162, and only if you want traps. Skip it otherwise.
5. Connect to MeshWatch Central
Optional. Central gathers alerts from several products into one inbox and correlates them by device. Only alarm summaries are sent to Central. The SNMP data itself stays on this computer.
- In Central, open Agents, choose DeviceWatch, type any label you like — it is just a name to tell installations apart — and press Issue token. The token is shown once.
- Pick DeviceWatch in that dropdown. A token belongs to the product it was issued for, and Central files every report under that product rather than under the application that sent it. A DeviceWatch installation given another product’s token connects and reports successfully, and its data appears under the other product while the DeviceWatch view stays empty — with no error at either end.
- In DeviceWatch, open the MeshWatch Central settings and enter Central’s address as
http://<central-server>:8443and the token. Use the server’s address, notlocalhost, unless Central runs on this same machine. - Press Test connection. When it succeeds, DeviceWatch saves the address and token and switches the connection on by itself; the status reads connected and the main button becomes Done, which returns to the dashboard.
Alerts raised from then on appear in Central. Past alerts are not backfilled. The full walkthrough is in the MeshWatch Central guide.
6. Troubleshooting
Nothing is arriving
The firewall is the usual reason — see section 4. After that, check that the device is pointed at this computer’s current local IP address; a DHCP lease can move it.
Test connection to Central fails
bad-token means the token is wrong or was revoked — issue a new one. unreachable means the address is wrong or a firewall is in the way; port 8443 must be open on the Central server. Note it is http://, not https://, unless you put a reverse proxy in front of Central. wrong-product means the token was issued for a different product; the message names which one. Issue a token for DeviceWatch instead and revoke the other. If the address looks right but Central is still unreachable, check it for a typo: most mistyped addresses are still valid addresses — 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5 — so the connection quietly goes somewhere else. In the current releases these results are shown as sentences — a token Central refuses is explained as possibly revoked or issued by a different Central — and the code itself appears when you hover over the message.
Central shows this agent as “connected”, but nothing arrives
That is not a failure. connected means the test succeeded and nothing has been sent yet; the row switches to reporting on the first real report, because a product sends only when something happens. DeviceWatch switches to reporting when a device first changes state or a threshold is crossed. A row still reading waiting has never reached Central.
Problems that affect every product
A blank window after upgrading, Ubuntu 24.04 refusing to start the app, credentials stored as plain text on Linux without a keyring, alert email not being delivered — these are the same on every product and are collected on the support page.
Still stuck
Write to support@meshwatch.app with the version number and what you expected to happen. First reply within two business days, Monday to Friday.