GUIDES › MeshServerWatch
Other languages English · 日本語 · 한국어 · 简体中文
MeshServerWatch
Server monitoring for Windows and Linux: an agent on each server, a Manager you run yourself — 1.0.0
In this version
- First release. Two programs: MeshServerWatch Manager (a service with a browser console) and MeshServerWatch Agent for Windows and Linux servers.
- Windows: a setup wizard for each — the Manager's ends by showing its address and certificate fingerprint; the Agent's asks for those values, with Test connection. For many servers, the Agent’s setup also installs silently with one line.
- Agents report CPU, memory and every disk every 10 minutes, and error-level event log / journald lines within about 30 seconds.
- HTTPS by default: the Manager generates its own certificate and agents pin it by its SHA-256 fingerprint.
- The Manager decides threshold and silence alerts, sends email, and keeps 30 days of charts per server.
- Optional forwarding of alerts and one status row per server to MeshWatch Central 1.3.9 or newer.
- Both install only after you accept the licence agreement. The Windows installers are Authenticode-signed and timestamped.
1. Install the Manager
The Manager is the one machine every agent reports to. Install it once, on a server that stays on. It is a single program with no runtime and no database server; one port, 8455, carries both the browser console and the agent API.
- Manager · Windows setup wizard MeshServerWatch-Manager-1.0.0-setup.exe
- Manager · Windows executable MeshServerWatch-Manager-1.0.0-windows-x64.exe
- Manager · Debian/Ubuntu amd64 meshserverwatch_1.0.0_amd64.deb
- Manager · Debian/Ubuntu arm64 meshserverwatch_1.0.0_arm64.deb
- Manager · RHEL/Rocky/Alma x86_64 meshserverwatch-1.0.0-1.x86_64.rpm
- Manager · RHEL/Rocky/Alma aarch64 meshserverwatch-1.0.0-1.aarch64.rpm
Verify what you downloaded. The published checksums — one file for every Manager and Agent package — are at MeshServerWatch-SHA256SUMS.txt
On Linux:
shasum -a 256 meshserverwatch_1.0.0_amd64.deb
On Windows:
Get-FileHash -Algorithm SHA256 MeshServerWatch-Manager-1.0.0-setup.exe
The Windows installers are Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.
The licence agreement
The Manager and the Agent install and run only after you accept the licence agreement (meshwatch.app/terms). Read it before you install: it is on that page, next to each program as EULA.txt after installing (/usr/share/doc/meshserverwatch/EULA.txt and /usr/share/doc/meshserverwatch-agent/EULA.txt on Linux), and meshserverwatch eula or meshserverwatch-agent eula prints it. How you accept it: a checkbox in the setup wizards (Next stays disabled until it is ticked), /ACCEPT_EULA=1 for a silent setup, --accept-eula on the command line (or type yes when asked in a terminal), and a required box when you create the first administrator. Without it, nothing is installed and the installers stop with exit code 2. The acceptance is recorded in eula.json in the data or state folder; a new version of the agreement asks again.
Windows Server: the setup wizard
Windows Server 2016, 2019 or 2022, x64. Run MeshServerWatch-Manager-1.0.0-setup.exe; it asks for administrator rights.
- Welcome, then Licence Agreement: tick I accept the terms of the licence agreement. Next stays disabled until you do.
- Settings: the port (default 8455) and Allow this port through Windows Firewall, ticked by default, which adds the inbound TCP rule MeshServerWatch Manager. On an upgrade the port already in use is filled in.
- Install folder (default
C:\Program Files\MeshServerWatch Manager), then Install. The wizard saves the configuration, generates the self-signed certificate, and registers and starts the Windows service MeshServerWatch. If that step fails, it shows the program's message and rolls back. - Finish shows the Manager address (
https://<computer name>:8455) and the certificate fingerprint — select them to copy; your agents need both — and offers Open MeshServerWatch in the browser. The browser warns once about the self-signed certificate; continue, then create the first administrator.
The wizard adds the program folder to PATH, a Start-menu folder (Open MeshServerWatch, MeshServerWatch Manager status, Uninstall) and an entry in Settings > Apps. Running a newer setup over an installed Manager upgrades it in place and keeps the configuration and data.
Program: C:\Program Files\MeshServerWatch Manager\meshserverwatch.exe, with EULA.txt next to it. Configuration: C:\ProgramData\MeshServerWatch\Manager\manager.json. Data: C:\ProgramData\MeshServerWatch\Manager\data\. The Manager logs to the Application event log (source MeshServerWatch) and to data\logs\manager.log (5 MB × 2).
Windows Server: silent and scripted installs
The setup wizard runs silently with /S; /ACCEPT_EULA=1 is required, /PORT= and /FIREWALL=0 are optional (put /D=<folder> last to change the folder). Exit codes: 0 installed, 2 no /ACCEPT_EULA=1 or an invalid port (nothing installed), 3 the install step failed (rolled back), 4 not 64-bit Windows.
MeshServerWatch-Manager-1.0.0-setup.exe /S /ACCEPT_EULA=1 /PORT=8455
Linux (deb / rpm, systemd)
Ubuntu 20.04+, Debian 11+, RHEL / Rocky / Alma 8+, amd64 or arm64. On Debian or Ubuntu:
sudo apt install ./meshserverwatch_1.0.0_amd64.deb
On RHEL, Rocky or Alma:
sudo dnf install ./meshserverwatch-1.0.0-1.x86_64.rpm
Then, on either:
sudo meshserverwatch install --accept-eula
The package creates the system user meshserverwatch and the unit meshserverwatch.service, which runs with NoNewPrivileges, ProtectSystem=strict, ProtectHome and a 512 MB memory ceiling; the only path it can write is /var/lib/meshserverwatch. install writes /etc/meshserverwatch/manager.json, generates the certificate in /var/lib/meshserverwatch/manager/tls/, enables and starts the service, and prints the console address and the fingerprint. --accept-eula accepts the licence agreement; without it, install asks you to type yes in a terminal, and with no terminal it stops with exit code 2 and changes nothing. The packaged unit runs run --accept-eula, so installing or enabling it means you accept the agreement. Options: --port 8455, --cert /path/cert.pem --key /path/key.pem, --insecure-http, --bind ADDR, --data DIR.
sudo systemctl status meshserverwatch
sudo journalctl -u meshserverwatch
Firewall: TCP 8455
Open TCP 8455 inbound on the Manager, from the servers that will report and from the browsers that will use the console. Agents only make outbound connections; nothing needs opening on them. The Windows setup wizard adds this rule for you unless you untick Allow this port through Windows Firewall. By hand on Windows Server:
New-NetFirewallRule -DisplayName "MeshServerWatch" -Direction Inbound -Protocol TCP -LocalPort 8455 -Action Allow
Ubuntu / Debian with ufw, then RHEL family with firewalld:
sudo ufw allow 8455/tcp
sudo firewall-cmd --permanent --add-port=8455/tcp && sudo firewall-cmd --reload
HTTPS and the certificate fingerprint
On first start the Manager creates a self-signed certificate and prints its SHA-256 fingerprint (AB:CD:…, 32 pairs) in its log as TLS fingerprint (SHA-256): …. You can read it again at any time:
meshserverwatch status
It is also in the console header (click it to copy) and next to every token you issue. Agents are installed with this value and refuse to talk to any Manager whose certificate differs — the TLS handshake is aborted before the token is sent. The certificate is reused on every start, so the fingerprint does not change unless the tls/ folder is deleted.
Your browser will warn about the self-signed certificate the first time you open the console. That is expected; if you want to be sure you reached the right machine, compare the fingerprint the browser shows with the one from meshserverwatch status. To avoid the warning, give the Manager your own certificate with --cert and --key; agents can then trust the CA instead of pinning. Plain HTTP exists only as --insecure-http, for a Manager behind a reverse proxy.
The first administrator
Open https://<manager-host>:8455. The first screen says No accounts yet. Create the first administrator. Read the licence agreement shown there, tick I have read and agree to the licence agreement, and choose a user name and a password of at least 12 characters. That screen appears only once; after that the console asks for a sign-in.
Sessions last 12 hours and are kept in memory, so restarting the Manager signs everyone out. Sign-in is rate-limited to 10 failures per 5 minutes per address and account. Add more users under Settings → Users with one of three roles: admin (everything), operator (acknowledges alerts, cannot change settings) and viewer (read only).
A forgotten password is reset on the Manager host itself — deliberately not over the network. Give it a name that does not exist and it lists the accounts; the new password is asked twice and not echoed, and that user's sessions are ended:
sudo meshserverwatch reset-password admin
2. Install agents
Install the agent on each server you want to watch — including the Manager's own server, if it should be watched too.
- Agent · Windows setup wizard MeshServerWatch-Agent-1.0.0-setup.exe
- Agent · Windows executable MeshServerWatch-Agent-1.0.0-windows-x64.exe
- Agent · Debian/Ubuntu amd64 meshserverwatch-agent_1.0.0_amd64.deb
- Agent · Debian/Ubuntu arm64 meshserverwatch-agent_1.0.0_arm64.deb
- Agent · RHEL/Rocky/Alma x86_64 meshserverwatch-agent-1.0.0-1.x86_64.rpm
- Agent · RHEL/Rocky/Alma aarch64 meshserverwatch-agent-1.0.0-1.aarch64.rpm
Issue a token
In the console open Agents, type a label — a name you invent, such as Head office servers — and press Issue token. A box shows the token (msw_…) once, in two parts. Install with the setup wizard (one server) lists the three values the agent wizard asks for — Manager address, Agent token and Certificate fingerprint — each with its own Copy button. Install on many servers (silent) gives the ready-made Windows silent-setup line and the Linux command, which already contain those values and /ACCEPT_EULA=1 / --accept-eula. Copy what you need before pressing Done; a lost token cannot be shown again — issue a new one and revoke the old.
One token can go on every server. The Manager tells servers apart by machine id, not by token. Issue several tokens only if you want to be able to revoke one site or team without touching the others. If the address shown is not one your servers can reach — for example localhost — use the Manager's name or IP instead.
Run the command on each server you want to watch, not on the Manager (unless the Manager should be watched too). When it worked, within a minute the server appears on the Servers tab and the token's state turns reporting. The states are waiting (never used), connected (an agent's test succeeded, nothing sent yet) and reporting (metrics or alerts arrived). To check on the server itself, run meshserverwatch-agent status.
Without the console, on the Manager host (token list and token revoke <id> also exist):
sudo meshserverwatch token issue --label "Head office"
Windows, one server: the setup wizard
Install the Manager first. Then run MeshServerWatch-Agent-1.0.0-setup.exe on the server to be watched; it asks for administrator rights.
- Welcome, then Licence Agreement: tick I accept the terms of the licence agreement.
- Connect to your MeshServerWatch Manager: paste the Manager address (
https://manager-host:8455), the Agent token (msw_…) and the Certificate fingerprint from the token box. Press Test connection: one ping with these values, nothing saved; the result shows in green or red. Testing is recommended but not required; Next is enabled once the three values are filled in. If the Manager runs with plain HTTP behind a reverse proxy, tick The Manager uses plain HTTP behind a reverse proxy instead of entering a fingerprint. - If the Manager is installed on the same computer, the page offers Fill in from this computer: it issues a token on the local Manager and fills in all three values.
- Install folder (default
C:\Program Files\MeshServerWatch Agent), then Install: the wizard saves the configuration and registers and starts the service MeshServerWatchAgent. If that step fails, it shows the program's message and rolls back. The token is never shown in full. - Finish: within a minute the server appears on the Manager's Servers tab. Show agent status opens a window with
meshserverwatch-agent status.
The wizard adds the program folder to PATH, a Start-menu folder (MeshServerWatch Agent status, Uninstall) and an entry in Settings > Apps. Running a newer setup over an installed agent upgrades it and keeps its settings — Keep this server's current connection settings is ticked for you. Silent: /S /ACCEPT_EULA=1 /MANAGER=… /TOKEN=… /FINGERPRINT=…; on an already configured server /S /ACCEPT_EULA=1 alone upgrades it.
Windows, many servers: silent setup
The setup wizard also runs silently. In an administrator PowerShell or Command Prompt, in the folder with the downloaded setup:
MeshServerWatch-Agent-1.0.0-setup.exe /S /ACCEPT_EULA=1 /MANAGER=https://<manager>:8455 /TOKEN=<msw_…> /FINGERPRINT=<sha256>
This is the line the token box gives you, with your values filled in, and it is what to put in a GPO or RMM deployment. /ACCEPT_EULA=1 is required and accepts the licence agreement on that server. For a Manager reached over plain http://, use /INSECURE_HTTP=1 instead of /FINGERPRINT=. Exit codes: 0 installed; 2 the licence agreement was not accepted or a value is missing, and nothing was installed.
Advanced: without an installer, copy meshserverwatch-agent.exe to a permanent folder and run, as Administrator:
meshserverwatch-agent install --manager https://manager.example.com:8455 --token msw_... --fingerprint AB:CD:... --accept-eula
Linux (apt / dnf)
Debian / Ubuntu, then the install line from the token box:
sudo apt install ./meshserverwatch-agent_1.0.0_amd64.deb
sudo meshserverwatch-agent install --manager https://manager.example.com:8455 --token msw_... --fingerprint AB:CD:... --accept-eula
RHEL / Rocky / Alma:
sudo dnf install ./meshserverwatch-agent-1.0.0-1.x86_64.rpm
The package creates the system user meshserverwatch-agent (member of systemd-journal, and of adm where it exists, so it can read logs) and the unit meshserverwatch-agent.service, which runs with NoNewPrivileges, ProtectSystem=strict, ProtectHome and a 100 MB memory ceiling. install records your acceptance of the licence agreement (--accept-eula, or type yes when asked in a terminal), writes /etc/meshserverwatch/agent.json and enables and starts the service. The agent and the Manager can share a server: each package touches only its own files in /etc/meshserverwatch/ and /var/lib/meshserverwatch/.
Check it: test and status
meshserverwatch-agent test
test checks the configuration, the Manager's certificate and version, the token, and the clock; collects one sample, prints it, sends it and prints the Manager's answer. test --send-alert also sends one info-level test alert, which shows up on the Alerts tab. To check values before installing — what the wizard's Test connection does — use test --no-config: one ping with the values you give, nothing read or saved; it prints one line, OK: … or FAIL: ….
meshserverwatch-agent test --no-config --manager https://manager.example.com:8455 --token msw_... --fingerprint AB:CD:...
meshserverwatch-agent status
status shows the service state, the last successful send, the queue, where error events are read from, the last sample, and the last problem in plain words. On Windows, run both in a new administrator prompt so the updated PATH is picked up. Exit codes: 0 OK, 1 a problem was found, 2 usage or configuration error, 3 (status only) the agent is not running.
To change one setting later, run install again with only that option — the others keep their values. A new --manager URL drops the old fingerprint, so give the new one with it.
sudo meshserverwatch-agent install --interval 300
3. Servers and charts
The Servers tab
One row per server: state, CPU average, memory, the fullest disk, last report, OS and agent version. The states are ok; warning (a threshold crossed); critical (a disk above the critical threshold, or silent); silent (no report for longer than the silent factor × that server's interval); unlicensed (its reports are refused — see section 6); and waiting (licensed, nothing received yet).
A server's page
Click a row. The top lists OS, IP, the names it is also known as, last report and interval, uptime, CPU, memory, load (Linux), agent version, first seen and machine id. Below are charts for CPU (average over the interval and peak), memory, and every disk separately, with the warning and critical lines drawn in. 24 hours shows every report; 7 days groups them by hour and 30 days by four hours. A break in a line means no report arrived — the chart never draws a point it did not receive. Hover or touch a chart to read values. Further down: the server's last 20 alerts, the thresholds in force for it, and Remove server.
Overview and Alerts
Overview shows servers by state, alerts in the last 24 hours by severity and by hour, the noisiest servers, the licence line and the latest alerts. Alerts lists every alert and filters by severity, source (agent or thresholds), server and state; Acknowledge records who and when, nothing more; Export CSV downloads what the filters show.
Retention
Reports are kept for 30 days, one file per server per day, and old files are deleted whole. Alerts are kept for 90 days by default; change it under Settings → Data retention (1 to 730 days). The sweep runs at start and once a day.
4. Alerts and thresholds
Two kinds of alert
Agent log lines (eventlog-error on Windows, journal-error on Linux): one-line summaries of error-level events, sent by the agent as they happen — the Windows System and Application logs at Critical and Error, journald at err and above. The same event is sent at most once per 10 minutes; repeats are counted and sent as one summary ending in (repeated N times in 10 min), and at most 20 alerts go out per 30-second batch. Thresholds are decided by the Manager from the reports.
Events collected
- Windows — the System and Application event logs, level Critical (sent as critical) and Error (sent as error).
- Not collected on Windows — Warning and Information events, and the Security log.
- Linux — journald entries at priority
errand above (emerg, alert and crit are sent as critical, err as error). Without journald,/var/log/syslogor/var/log/messages— see section 9. - The agent's own log lines are never turned into alerts. To collect metrics only, set
"collectErrors": falseinagent.json.
Default thresholds
- Disk — 90 % or more: warning; 95 % or more: critical.
- CPU — average 90 % or more for 2 reports in a row: warning.
- Memory — 90 % or more for 2 reports in a row: warning.
- Silent — no report for 2.5 × the server's interval (25 minutes at the default 10):
server-silent, critical.
Change them under Settings → Thresholds; they apply to the next report. The disk critical value must be higher than the warning value, and the form says so if it is not.
One alert per change, not per report
An alert is raised when a state changes, and one info-level …-cleared alert when it returns to normal. A disk going 50 → 91 → 96 → 92 → 70 % produces four alerts: warning, critical, warning (on the way down) and cleared — not one per report while it stays full. The state is saved on disk, so a restart of the Manager does not raise the same alert again, and a late report that arrives out of order does not undo a newer state.
What “silent” means
The Manager cannot tell whether a server is down, only that nothing arrived — so it never says “down”. The alert reads like No report from app-03 for 27 minutes (expected every 10 minutes). The cause may be the server, its network, the agent service, or a firewall between them. When reports resume, a server-silent-cleared alert follows, and anything the agent queued meanwhile (up to 6 hours of metrics and 500 alerts) arrives in order.
5. Email alerts
Set it up
Settings → Email alerts (SMTP): SMTP server, port, security (STARTTLS, implicit TLS or None), user name and password if your server wants them (AUTH PLAIN, LOGIN or CRAM-MD5), from address, and recipients separated by commas. Press Send test email: if the message is accepted, the settings are saved and email alerts are switched on in the same step, so a test that worked is never followed by settings that were not saved.
How often it writes
One email per alert, and at most one per minute per server. Alerts that arrive for the same server inside that minute are folded into the next email as “… and N more”, so a burst becomes one message. The counters under the form show how many were sent and how many failed.
The password
The SMTP password is stored in settings.json in the data folder, readable only by the service (mode 0600 on Linux), and is never sent back to the browser — the form only shows that one is set. The Manager is a service, so there are no desktop notifications; email and MeshWatch Central are the ways out.
6. Licence and seats
Trial
30 days with unlimited servers, starting at the first agent report — installing the Manager alone does not start the clock. Overview, Servers and Settings → Licence show the days left. Nothing is asked for up front.
The key
MeshServerWatch is priced per server, with the Manager included and a minimum of 3 servers: monthly at US$5 per server per month (US$15 a month minimum), or annual at US$48 per server per year (20% off, the same as US$4 a month). Charges are generally non-refundable, except where the law requires a refund or where we approve a refund request for a billing error submitted within 14 days of the charge (see the Terms of Use), so use the 30-day trial to evaluate it first; on the Stripe checkout page you choose the number of servers (minimum 3) and tick the licence agreement. After purchase a key starting with MSW1. is emailed to you. Paste it into Settings → Licence and press Activate. The key carries the number of seats and its own expiry and is verified on the Manager against a built-in public key — no licensing server is contacted, so it works on an isolated network.
How seats are counted
One seat per server, counted by machine id in the order servers first reported; the first N are licensed. A new server beyond the seats gets 402 seat-limit, shows as unlicensed, and its agent keeps collecting and retries every hour. A server that is already reporting is never cut off because another one arrived.
When a server is over the limit, a yellow banner on Servers says how many and what to do: add seats to your subscription and enter the new key (Settings → Licence), or remove a server you no longer watch. Its Enter a new key button opens the licence settings; Add seats opens the pricing section of the product page. The new key arrives by email; entering it licenses the waiting server at its next report.
Remove server
On a server's page, Remove server… frees its seat at once and deletes its charts (every stored report, up to 30 days — this cannot be undone). Its alerts stay on the Alerts tab until they age out. If the agent is still running on that server it comes back at its next report as a new server, at the end of the queue — uninstall the agent or revoke its token first.
When the trial or the key expires
Agents are refused with 402 and a reason — trial-ended, licence-expired, licence-invalid, or clock-tampered if the Manager's clock was moved back. The charts and alerts already stored stay visible. Agents keep collecting and retry every hour, so entering a key resumes reporting without touching the servers.
7. Connect to MeshWatch Central
Optional. MeshServerWatch is complete on its own. If you also run MeshWatch Central, the Manager can forward its alerts and one status row per server, so a full disk appears next to what the other MeshWatch products report about the same host.
Requires Central 1.3.9 or newer, which ships on 13 October 2026 — the current Central 1.3.8 does not yet accept MeshServerWatch data. Older Central versions do not have MeshServerWatch in their Agents list, so there is no way to issue a token for it.
- In Central, open Agents, choose MeshServerWatch, type a label and press Issue token. The token is shown once.
- Pick MeshServerWatch in that dropdown. A token belongs to the product it was issued for. The Manager checks this: with another product's token, Test refuses and names the product the token belongs to — That token was issued for “syslogwatch” in Central … Issue a MeshServerWatch token.
- In the Manager, open Settings → MeshWatch Central, enter Central's address as you open it in a browser —
http://<central-server>:8443unless you put a reverse proxy in front of Central — and the token. - Press Test. A successful test saves the settings and turns forwarding on: Done — Central accepted the token (…). Forwarding is on and saved. Until a test succeeds, nothing is sent.
What is forwarded: every alert — thresholds, silence and the agents' error lines — and one device row per server: the host name as the device, its IP and aliases, status up or silent, and a detail line such as “CPU 12% · Mem 56% · Disk C: 96%”. Device rows are sent at most once per five minutes per server. Raw metric series are never forwarded; the charts stay on the Manager. While Central is unreachable, up to 500 items wait in a queue and are sent in order. The full walkthrough is in the MeshWatch Central guide.
8. Where your data lives, backup and uninstall
On the Manager
Windows: C:\ProgramData\MeshServerWatch\Manager\data\. Linux: /var/lib/meshserverwatch/manager/. Inside: settings.json (thresholds, retention, SMTP and Central settings, mode 0600), alerts.json, servers.json (one row per server with its latest sample), agents.json (token hashes only — the raw token is never stored), users.json (scrypt password hashes), licence.json (the key and the trial record), server-alert-state.json, tls/ (the certificate), metrics/<machine id>/YYYY-MM-DD.jsonl (the reports) and logs/. Every write is atomic: a temporary file, then a rename.
What an agent sends — the data boundary
Only numbers and one-line summaries. Every interval, a report like this:
{
"machineId": "3f2a…",
"host": "web-01", "ip": "10.0.0.21", "aliases": ["web-01.corp.local"],
"os": "linux", "osName": "Ubuntu 22.04.4 LTS",
"agentVersion": "1.0.0", "uptimeSec": 123456, "intervalSec": 600,
"at": 1790000000000,
"cpu": { "avgPct": 12.5, "maxPct": 71.0, "cores": 8 },
"mem": { "totalBytes": 17179869184, "usedBytes": 9663676416, "pct": 56.3 },
"disks": [ { "mount": "/", "fs": "ext4", "totalBytes": 0, "usedBytes": 0, "pct": 0 } ],
"load": [0.5, 0.4, 0.3]
}
machineId is the first 32 hex characters of the SHA-256 of the Windows MachineGuid or Linux /etc/machine-id; the raw value is never sent. Disks are real file systems only (fixed drives on Windows; tmpfs, overlay, network and other virtual file systems are skipped on Linux), fullest first, at most 32. load is Linux only. For each error event: severity, kind, the same host, IP and machine id, the event time, and a summary of at most 300 characters:
System · Service Control Manager 7031 — The Print Spooler service terminated unexpectedly.
journal · sshd — error: kex_exchange_identification: Connection closed by remote host
The full message text, event XML, user SIDs, process lists, user names and command lines are never sent. The token is never logged or printed in full; it appears as msw_abcd…wxyz.
On each server
Configuration: C:\ProgramData\MeshServerWatch\Agent\agent.json (SYSTEM and Administrators only) or /etc/meshserverwatch/agent.json (0600). State — the queue of unsent items, the event-log bookmark or journal cursor so a restart neither resends nor skips events, and status.json: C:\ProgramData\MeshServerWatch\Agent\state\ or /var/lib/meshserverwatch/agent/.
Backup
Copy the Manager's data folder; that is everything. Because each file is replaced atomically, a copy taken while the Manager runs holds complete files; stop the service first if you want every file from the same moment. Keep tls/ with the rest: restoring onto a new machine with the same certificate keeps the same fingerprint, so the agents carry on. Without it the Manager generates a new certificate and every agent needs install --fingerprint <new value>.
Uninstall
Manager: Settings → Apps on Windows (or, silently, "C:\Program Files\MeshServerWatch Manager\Uninstall.exe" /S; the uninstaller also removes the firewall rule), apt remove / dnf remove on Linux, or:
sudo meshserverwatch uninstall
Each stops and removes the service and keeps the configuration and data, so a reinstall carries on where it left off. Agent on Windows: Settings → Apps, or silently "C:\Program Files\MeshServerWatch Agent\Uninstall.exe" /S.
This removes the service and program folder and keeps C:\ProgramData\MeshServerWatch\Agent\. On Linux, apt remove stops and disables the agent; apt purge also deletes its configuration, state and user; rpm -e keeps the configuration. meshserverwatch-agent uninstall --purge removes the service and deletes configuration and state on either system. Remember to press Remove server on the Manager to free the seat.
9. Troubleshooting
On a server, start with meshserverwatch-agent test, then meshserverwatch-agent status. The messages below are what they print.
“The Manager's certificate fingerprint does not match the configured one”
Nothing was sent — the connection was closed before the token left the server. Either the Manager was reinstalled (and generated a new certificate) or the URL points at another machine. Read the fingerprint from meshserverwatch status on the Manager and run install --fingerprint <new value>. Do not copy the “presented” value from the message without checking it on the Manager: that is the value of whatever answered. its TLS certificate is not trusted means no fingerprint is set and the Manager uses its self-signed certificate — add --fingerprint.
401 — “The Manager rejected the token (401): it is wrong or has been revoked”
Issue a new agent token on the Manager's Agents tab and run meshserverwatch-agent install --token <new token>. Sending stops until the configuration changes; collection and queueing continue.
402 — the Manager is not accepting server data
The agent names the reason and keeps collecting, retrying every hour: The Manager has no free licence seat for this server — add seats or remove a server on the Manager's Servers tab. · The Manager's trial has ended — enter a licence key on the Manager's Settings tab. · The Manager's licence has expired · The Manager's licence key is not valid · The Manager reports its clock was moved back; the administrator must check the Manager server's clock. See section 6.
403 — “This token is not an agent token”
The Manager answered 403 wrong-product: the value given as the token is not an agent token. Issue one on the Manager's Agents tab and run install --token <new token>.
404 — “MeshServerWatch Manager 1.0.0 or later is required at <url>”
The address does not lead to a Manager's agent API: a wrong port, a reverse-proxy path that does not pass /api/v1/ through, or another web site. Error alerts are still attempted; metrics retry every hour.
“connection refused” or “timed out”
Check that the Manager runs (meshserverwatch status exits with 3 when it is not listening), that the agent uses the right port, and that TCP 8455 is open inbound on the Manager and not blocked between the two — see the firewall step in section 1.
Port 8455 is already in use
The Manager stops with cannot listen on 0.0.0.0:8455: … address already in use, in the journal or the Application event log. Find what holds the port:
sudo ss -ltnp 'sport = :8455'
Get-NetTCPConnection -LocalPort 8455
Stop that program, or choose another port — run the setup wizard again and change it on the Settings page, or run meshserverwatch install --port <other> — and use the new port in every agent's --manager URL and in the firewall rule.
Linux without journald: syslog fallback
Where there is no journal, the agent follows /var/log/syslog or /var/log/messages. If that file carries no priorities, status says no priority in file — errors matched by keyword: errors are recognised by words such as “error”, “failed” and “panic”. For exact priorities, have rsyslog write *.err with <%PRI%> to a file and set errorLogFile in agent.json to it. If neither file can be read, error events are not collected, metrics still are, and status says so. journald: only part of the journal is readable means the service user is not in systemd-journal:
sudo usermod -aG systemd-journal meshserverwatch-agent && sudo systemctl restart meshserverwatch-agent
Windows event log sources
The Manager writes to the Application log with source MeshServerWatch; the agent with source MeshServerWatch Agent, plus C:\ProgramData\MeshServerWatch\Agent\state\agent.log. The agent never reads its own lines back as errors, so its messages do not turn into alerts. To see an alert end to end, create a test error — eventcreate /t error /id 999 /l application /d "MeshServerWatch test" — and it should appear on the Alerts tab within about 30 seconds.
“clock is … ahead of the Manager”
This server's clock differs from the Manager's by more than 5 minutes. The agent shifts its timestamps to the Manager's clock so reports are not rejected, sends one agent-clock-skew warning a day, and status warns. Fix time synchronisation (NTP).
Still stuck
Write to support@meshwatch.app with the versions (meshserverwatch version, meshserverwatch-agent version), the operating systems, and the output of meshserverwatch-agent test with the token left masked as it prints it. First reply within two business days, Monday to Friday.