GUIDES › SyslogWatch
Other languages English · 日本語 · 한국어 · 简体中文
SyslogWatch
Syslog server for Mac, Windows and Linux — 1.3.9
In this version
- 1.3.9: the 30-day trial now unlocks email alerts and archived-log search, as it should. No other changes from 1.3.8.
- Linux: the
.deband.tar.gznow include a headless mode for servers without a desktop — the same screen in your browser, with a systemd unit. See section 5. - Deleting the data folder no longer restarts the 30-day trial: the trial start is also recorded outside the data folder, and the earliest record wins. The check stays on this computer.
- The licence panel no longer contradicts itself: during a trial it shows the trial and its days left, and a saved key that has expired or is not valid is marked as not in use, with a Remove button.
- Test connection in the MeshWatch Central settings now saves the address and token when it succeeds, and the button becomes Done.
- The Windows installer is Authenticode-signed and timestamped.
1. Install
Pick the build for the machine you are installing on. Every file below is the current release; older versions are listed on the release notes page.
- macOS · Apple silicon SyslogWatch-1.3.9-macos-arm64.dmg
- macOS · Intel SyslogWatch-1.3.9-macos-x64.dmg
- Windows installer SyslogWatch-1.3.9-windows-x64-setup.exe
- Windows portable SyslogWatch-1.3.9-windows-x64-portable.exe
- Linux · Debian/Ubuntu SyslogWatch-1.3.9-linux-amd64.deb
- Linux · AppImage SyslogWatch-1.3.9-linux-x86_64.AppImage
Verify what you downloaded. The published checksums are at SyslogWatch-SHA256SUMS.txt
On macOS or Linux:
shasum -a 256 SyslogWatch-1.3.9-macos-arm64.dmg
On Windows:
Get-FileHash -Algorithm SHA256 SyslogWatch-1.3.9-windows-x64-setup.exe
The macOS build is notarised by Apple, so it opens without a warning. The Windows installer is Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.
2. First run
- SyslogWatch listens on UDP and TCP port 1514 by default. That is above 1024, so it does not need an administrator password.
- On the equipment you want logs from — router, switch, NAS, firewall, server — set the syslog destination to this computer’s local IP address and port 1514.
- Messages appear as they arrive. If nothing arrives, the firewall is the usual reason; see Troubleshooting.
- The port can be changed in Settings → Receiving Server. Ports below 1024 need elevated access.
Every install starts with a 30-day trial of the paid edition. Nothing is asked for up front — no card, no account, no email address.
3. Administration
Encoding
RFC 5424 asks for UTF-8, but many devices and Windows event-log forwarders send the local code page instead. Automatic reads each message as UTF-8 when it is valid and falls back otherwise, which is right for nearly everyone. Pick a specific encoding only when a device sends valid-looking UTF-8 that is actually something else. Detection is not done for you on purpose — we tried it, it guessed wrong, and a wrongly decoded log is worse than an obviously undecoded one.
Alert rules
Rules match on severity, host and text. Free includes up to 3 rules; Pro raises the limit to 50 and adds email delivery.
Retention
Messages are written to disk on this computer and are not deleted to enforce a plan. Retention policy is an Enterprise setting; the default is to keep everything.
Language
Settings → Language. English and Japanese. The encoding names and severity lists are translated too. Received log lines are never translated — what a device sent is what you see.
Where your data lives
Everything SyslogWatch records stays on the computer it runs on. None of it is sent to us, to an analytics company or to an advertising network. Back up that computer and you have backed up SyslogWatch.
Licence keys
The key arrives by email after purchase. Paste it into the app and it is checked on this computer against the public key built into the app, so SyslogWatch never contacts a licensing server — it works on a network with no internet access. When the 30-day trial ends, or a subscription lapses, SyslogWatch keeps running on Free: it keeps receiving and storing every message, with up to 3 alert rules.
4. Firewall
- Windows — Allow SyslogWatch through Defender Firewall on your private network when it asks. If the prompt was dismissed: Windows Security → Firewall & network protection → Allow an app through firewall.
- Linux (Ubuntu/Debian) — sudo ufw allow 1514/udp && sudo ufw allow 1514/tcp
- Linux (Fedora/RHEL) — sudo firewall-cmd --add-port=1514/udp --add-port=1514/tcp --permanent && sudo firewall-cmd --reload
- macOS — Allow incoming connections when macOS asks, or System Settings → Network → Firewall → Options.
5. Run on a server without a desktop (headless)
The desktop app needs a graphical session. On a Linux server without one it does not start and prints Missing X server or $DISPLAY. For that case the Linux .deb and .tar.gz also include a headless mode: the same receiver, rules, alerts and licence, with the same screen served to your browser instead of a window. The AppImage does not include it.
Try it in the foreground
Install the .deb — the package manager pulls in the libraries it needs — then start the wrapper installed next to the app:
sudo apt install ./SyslogWatch-*-linux-amd64.deb
/opt/SyslogWatch/syslogwatch-headless
It prints the address of the web UI with a one-time token — http://127.0.0.1:8514/?token=…. Open it once; a cookie remembers you, and afterwards http://127.0.0.1:8514/ is enough. Lost it? syslogwatch-headless --show-url prints it again. Send a test message from the same machine to see it arrive: logger -n 127.0.0.1 -P 1514 -d "hello from $(hostname)".
With the .tar.gz from the download page, the wrapper, the unit file and README-headless.txt are in the unpacked folder. Install the libraries listed in README-headless.txt yourself — the wrapper names any that are missing — and note that the unit file expects the app in /opt/SyslogWatch.
Open the screen from your own computer
The web UI listens on 127.0.0.1 only. Tunnel to it over SSH, then open the token address in your own browser:
ssh -L 8514:127.0.0.1:8514 user@server
Or put an HTTPS reverse proxy (nginx, Caddy) in front of it. Do not expose the plain HTTP port to an untrusted network: logs, SMTP credentials and the Central token pass through it.
Run it as a service
A systemd unit is installed next to the wrapper. Create a service user, copy the unit and start it:
sudo useradd --system --home /var/lib/syslogwatch --create-home --shell /usr/sbin/nologin syslogwatch
sudo cp /opt/SyslogWatch/syslogwatch-headless.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now syslogwatch-headless
The web UI address, with its token, is printed in the journal: sudo journalctl -u syslogwatch-headless. The default port 1514 needs no privilege. If you change it to 514 in Settings, uncomment the AmbientCapabilities=CAP_NET_BIND_SERVICE line in /etc/systemd/system/syslogwatch-headless.service, then run sudo systemctl daemon-reload && sudo systemctl restart syslogwatch-headless.
Where the data lives
As a service: /var/lib/syslogwatch/SyslogWatch — settings, logs, the licence and the UI token. Run by hand, headless uses the same folder as the desktop app for that user (~/.config/SyslogWatch), so a licence activated in one is active in the other. The service runs as its own user, so enter the licence key once in its web UI.
A server has no keyring, so the licence key, SMTP password and Central token are stored as files readable only by the service user (mode 0600). Settings says so.
The full notes are in README-headless.txt next to the wrapper; syslogwatch-headless --help lists the options.
6. Connect to MeshWatch Central
Optional. Central gathers alerts from several products into one inbox and correlates them by device. Only severity, host name and a one-line summary are sent to Central. Log contents never leave this computer.
- In Central, open Agents, choose SyslogWatch, type any label you like — it is just a name to tell installations apart — and press Issue token. The token is shown once.
- Pick SyslogWatch in that dropdown. A token belongs to the product it was issued for, and Central files every report under that product rather than under the application that sent it. A SyslogWatch installation given another product’s token connects and reports successfully, and its data appears under the other product while the SyslogWatch view stays empty — with no error at either end.
- In SyslogWatch, open the MeshWatch Central settings and enter Central’s address as
http://<central-server>:8443and the token. Use the server’s address, notlocalhost, unless Central runs on this same machine. - Press Test connection. When it succeeds, SyslogWatch saves the address and token and switches the connection on by itself; the button at the bottom becomes Done, which closes the dialog.
Alerts raised from then on appear in Central. Past alerts are not backfilled. The full walkthrough is in the MeshWatch Central guide.
7. Troubleshooting
Nothing is arriving
The firewall is the usual reason — see section 4. After that, check that the device is pointed at this computer’s current local IP address; a DHCP lease can move it.
Test connection to Central fails
bad-token means the token is wrong or was revoked — issue a new one. unreachable means the address is wrong or a firewall is in the way; port 8443 must be open on the Central server. Note it is http://, not https://, unless you put a reverse proxy in front of Central. wrong-product means the token was issued for a different product; the message names which one. Issue a token for SyslogWatch instead and revoke the other. If the address looks right but Central is still unreachable, check it for a typo: most mistyped addresses are still valid addresses — 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5 — so the connection quietly goes somewhere else. In the current releases these results are shown as sentences — a token Central refuses is explained as possibly revoked or issued by a different Central — and the code itself appears when you hover over the message.
Central shows this agent as “connected”, but nothing arrives
That is not a failure. connected means the test succeeded and nothing has been sent yet; the row switches to reporting on the first real report, because a product sends only when something happens. SyslogWatch switches to reporting when the first matching log line arrives. A row still reading waiting has never reached Central.
It prints Missing X server or $DISPLAY on a Linux server
That is the desktop app asking for a screen; nothing is wrong with the install. Run it from a desktop session, or on a server without one use the headless mode — see section 5.
Problems that affect every product
A blank window after upgrading, Ubuntu 24.04 refusing to start the app, credentials stored as plain text on Linux without a keyring, alert email not being delivered — these are the same on every product and are collected on the support page.
Still stuck
Write to support@meshwatch.app with the version number and what you expected to happen. First reply within two business days, Monday to Friday.