GUIDES › SyslogWatch

Other languages English · 日本語 · 한국어 · 简体中文

SyslogWatch

Syslog server for Mac, Windows and Linux — 1.3.9

In this version

Full release notes

1. Install

Pick the build for the machine you are installing on. Every file below is the current release; older versions are listed on the release notes page.

Verify what you downloaded. The published checksums are at SyslogWatch-SHA256SUMS.txt

On macOS or Linux:

shasum -a 256 SyslogWatch-1.3.9-macos-arm64.dmg

On Windows:

Get-FileHash -Algorithm SHA256 SyslogWatch-1.3.9-windows-x64-setup.exe

The macOS build is notarised by Apple, so it opens without a warning. The Windows installer is Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

2. First run

  1. SyslogWatch listens on UDP and TCP port 1514 by default. That is above 1024, so it does not need an administrator password.
  2. On the equipment you want logs from — router, switch, NAS, firewall, server — set the syslog destination to this computer’s local IP address and port 1514.
  3. Messages appear as they arrive. If nothing arrives, the firewall is the usual reason; see Troubleshooting.
  4. The port can be changed in Settings → Receiving Server. Ports below 1024 need elevated access.

Every install starts with a 30-day trial of the paid edition. Nothing is asked for up front — no card, no account, no email address.

3. Administration

Encoding

RFC 5424 asks for UTF-8, but many devices and Windows event-log forwarders send the local code page instead. Automatic reads each message as UTF-8 when it is valid and falls back otherwise, which is right for nearly everyone. Pick a specific encoding only when a device sends valid-looking UTF-8 that is actually something else. Detection is not done for you on purpose — we tried it, it guessed wrong, and a wrongly decoded log is worse than an obviously undecoded one.

Alert rules

Rules match on severity, host and text. Free includes up to 3 rules; Pro raises the limit to 50 and adds email delivery.

Retention

Messages are written to disk on this computer and are not deleted to enforce a plan. Retention policy is an Enterprise setting; the default is to keep everything.

Language

Settings → Language. English and Japanese. The encoding names and severity lists are translated too. Received log lines are never translated — what a device sent is what you see.

Where your data lives

Everything SyslogWatch records stays on the computer it runs on. None of it is sent to us, to an analytics company or to an advertising network. Back up that computer and you have backed up SyslogWatch.

Licence keys

The key arrives by email after purchase. Paste it into the app and it is checked on this computer against the public key built into the app, so SyslogWatch never contacts a licensing server — it works on a network with no internet access. When the 30-day trial ends, or a subscription lapses, SyslogWatch keeps running on Free: it keeps receiving and storing every message, with up to 3 alert rules.

4. Firewall

5. Run on a server without a desktop (headless)

The desktop app needs a graphical session. On a Linux server without one it does not start and prints Missing X server or $DISPLAY. For that case the Linux .deb and .tar.gz also include a headless mode: the same receiver, rules, alerts and licence, with the same screen served to your browser instead of a window. The AppImage does not include it.

Try it in the foreground

Install the .deb — the package manager pulls in the libraries it needs — then start the wrapper installed next to the app:

sudo apt install ./SyslogWatch-*-linux-amd64.deb
/opt/SyslogWatch/syslogwatch-headless

It prints the address of the web UI with a one-time token — http://127.0.0.1:8514/?token=…. Open it once; a cookie remembers you, and afterwards http://127.0.0.1:8514/ is enough. Lost it? syslogwatch-headless --show-url prints it again. Send a test message from the same machine to see it arrive: logger -n 127.0.0.1 -P 1514 -d "hello from $(hostname)".

With the .tar.gz from the download page, the wrapper, the unit file and README-headless.txt are in the unpacked folder. Install the libraries listed in README-headless.txt yourself — the wrapper names any that are missing — and note that the unit file expects the app in /opt/SyslogWatch.

Open the screen from your own computer

The web UI listens on 127.0.0.1 only. Tunnel to it over SSH, then open the token address in your own browser:

ssh -L 8514:127.0.0.1:8514 user@server

Or put an HTTPS reverse proxy (nginx, Caddy) in front of it. Do not expose the plain HTTP port to an untrusted network: logs, SMTP credentials and the Central token pass through it.

Run it as a service

A systemd unit is installed next to the wrapper. Create a service user, copy the unit and start it:

sudo useradd --system --home /var/lib/syslogwatch --create-home --shell /usr/sbin/nologin syslogwatch
sudo cp /opt/SyslogWatch/syslogwatch-headless.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now syslogwatch-headless

The web UI address, with its token, is printed in the journal: sudo journalctl -u syslogwatch-headless. The default port 1514 needs no privilege. If you change it to 514 in Settings, uncomment the AmbientCapabilities=CAP_NET_BIND_SERVICE line in /etc/systemd/system/syslogwatch-headless.service, then run sudo systemctl daemon-reload && sudo systemctl restart syslogwatch-headless.

Where the data lives

As a service: /var/lib/syslogwatch/SyslogWatch — settings, logs, the licence and the UI token. Run by hand, headless uses the same folder as the desktop app for that user (~/.config/SyslogWatch), so a licence activated in one is active in the other. The service runs as its own user, so enter the licence key once in its web UI.

A server has no keyring, so the licence key, SMTP password and Central token are stored as files readable only by the service user (mode 0600). Settings says so.

The full notes are in README-headless.txt next to the wrapper; syslogwatch-headless --help lists the options.

6. Connect to MeshWatch Central

Optional. Central gathers alerts from several products into one inbox and correlates them by device. Only severity, host name and a one-line summary are sent to Central. Log contents never leave this computer.

  1. In Central, open Agents, choose SyslogWatch, type any label you like — it is just a name to tell installations apart — and press Issue token. The token is shown once.
  2. Pick SyslogWatch in that dropdown. A token belongs to the product it was issued for, and Central files every report under that product rather than under the application that sent it. A SyslogWatch installation given another product’s token connects and reports successfully, and its data appears under the other product while the SyslogWatch view stays empty — with no error at either end.
  3. In SyslogWatch, open the MeshWatch Central settings and enter Central’s address as http://<central-server>:8443 and the token. Use the server’s address, not localhost, unless Central runs on this same machine.
  4. Press Test connection. When it succeeds, SyslogWatch saves the address and token and switches the connection on by itself; the button at the bottom becomes Done, which closes the dialog.

Alerts raised from then on appear in Central. Past alerts are not backfilled. The full walkthrough is in the MeshWatch Central guide.

7. Troubleshooting

Nothing is arriving

The firewall is the usual reason — see section 4. After that, check that the device is pointed at this computer’s current local IP address; a DHCP lease can move it.

Test connection to Central fails

bad-token means the token is wrong or was revoked — issue a new one. unreachable means the address is wrong or a firewall is in the way; port 8443 must be open on the Central server. Note it is http://, not https://, unless you put a reverse proxy in front of Central. wrong-product means the token was issued for a different product; the message names which one. Issue a token for SyslogWatch instead and revoke the other. If the address looks right but Central is still unreachable, check it for a typo: most mistyped addresses are still valid addresses — 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5 — so the connection quietly goes somewhere else. In the current releases these results are shown as sentences — a token Central refuses is explained as possibly revoked or issued by a different Central — and the code itself appears when you hover over the message.

Central shows this agent as “connected”, but nothing arrives

That is not a failure. connected means the test succeeded and nothing has been sent yet; the row switches to reporting on the first real report, because a product sends only when something happens. SyslogWatch switches to reporting when the first matching log line arrives. A row still reading waiting has never reached Central.

It prints Missing X server or $DISPLAY on a Linux server

That is the desktop app asking for a screen; nothing is wrong with the install. Run it from a desktop session, or on a server without one use the headless mode — see section 5.

Problems that affect every product

A blank window after upgrading, Ubuntu 24.04 refusing to start the app, credentials stored as plain text on Linux without a keyring, alert email not being delivered — these are the same on every product and are collected on the support page.

Still stuck

Write to support@meshwatch.app with the version number and what you expected to happen. First reply within two business days, Monday to Friday.