New SERVER MONITORING FOR WINDOWS & LINUX — ON YOUR OWN SERVER

A disk that fills up on Friday night should be an email on Friday night, not a ticket on Monday.

MeshServerWatch is two small programs. An Agent runs as a service on each Windows or Linux server and reports CPU, memory, every disk, and error-level log events. A Manager you run yourself receives those reports, keeps 30 days of charts per server, decides when something has crossed a line, and emails you once when it does — and once more when it clears. There is no cloud account, no per-metric pricing and nothing that phones home.

Windows Server 2016+ Ubuntu · Debian · RHEL Self-hosted Manager HTTPS by default Email alerts US$5 per server per month · US$48 per year 30-day trial

DEMO

See it in action

68 seconds, recorded on a real Manager and Agent: the install line, the first report, a disk threshold crossing, and the licence page.

Two pieces, both on your machines

The Manager is a single binary (about 8 MB) with a browser console. It runs as a Windows service or a systemd service, on one port — 8455 — for both the console and the agent API. No runtime, no database server; its data is JSON files on that machine.

The Agent is a single binary (about 7 MB) installed as a service on each server you want watched. It is told the Manager’s address, a token and the Manager’s certificate fingerprint once, at install, and needs nothing else.

What happens every ten minutes

The agent samples CPU every 30 seconds and, every 10 minutes (configurable from 1 to 60), sends one report: CPU average and peak, memory used, each real disk with its percentage, load on Linux, uptime, OS name and agent version. One report also goes out immediately at start.

Error-level operating-system events — the Windows event log at Critical and Error, journald at err and above — are sent within about 30 seconds as one-line summaries. Repeats of the same event are counted, not resent. If the Manager is unreachable, the agent keeps up to 6 hours of metrics and 500 alerts on disk and sends them in order when it is back.

The Manager decides, and says one thing once

Thresholds live in the Manager, not in each agent, so changing them is one edit. Defaults: disk at 90 % is a warning and 95 % is critical; CPU or memory averaging 90 % or more for two reports in a row is a warning; no report for 2.5 × the interval makes the server silent.

An alert is raised when a state changes and an info-level cleared alert when it returns — never one per report, and never again after a restart, because the state is kept on disk. Silent is worded carefully: the Manager only knows that nothing arrived, not that the server is down, and the message says so.

Email that does not flood

SMTP with STARTTLS, implicit TLS or none, with optional authentication. One email per alert, and at most one per minute per server — alerts that arrive inside that minute are folded into the next email as “… and N more”. Send test email does exactly that, and if it succeeds it saves the settings and turns email alerts on, so a working test is never followed by a silent misconfiguration.

Only numbers and one-line summaries

The agent sends percentages, byte counts, a host name, an IP address, the OS name, and for each error event a summary of at most 300 characters — the log, the source, the event id and the first line of the message. The full message text, event XML, user SIDs, process lists, user names and command lines are never sent, and the machine id is a hash, never the raw value. The exact fields are listed in the guide.

HTTPS from the first minute, pinned by fingerprint

On first start the Manager generates its own certificate and shows the SHA-256 fingerprint in its log, in meshserverwatch status and next to every token in the console. Each agent is installed with that fingerprint and refuses to send anything to a Manager whose certificate differs — the token never leaves the server. There is no trust-on-first-use and no option to switch certificate checks off. Your own certificate and key work too, and plain HTTP is available only by an explicit flag, for use behind a reverse proxy.

Central is optional

MeshServerWatch is complete on its own. If you also run MeshWatch Central (1.3.9 or later — ships 13 October 2026; the current 1.3.8 does not yet accept MeshServerWatch data), the Manager can forward every alert and one status row per server — host name, IP, up or silent, and a line such as “CPU 12% · Mem 56% · Disk C: 96%” — so a full disk lands next to what SyslogWatch, DeviceWatch or ConfigWatch saw on the same host. Raw metric series are never forwarded.

Everything stays where you put it

Reports are stored as one file per server per day and kept for 30 days; alerts for 90 days by default, adjustable from 1 to 730. The Manager makes no outbound connection at all unless you configure SMTP or Central, or turn on the once-a-day update check, which is off by default. The licence key is verified against a public key built into the Manager, so it activates on a network with no way out.

THE MANAGER CONSOLE

The screens, as they are

Captures from the 1.0.0 Manager during release testing. Dark, no library, and it works at phone width.

MeshServerWatch Manager Overview tab: tiles for servers by state (2 critical), unacknowledged critical alerts, alerts in the last 24 hours, and tokens (1 reporting), above an hourly bar chart of alerts for the last 24 hours.
Overview: servers by state, alerts in the last 24 hours by severity and by hour, token states.
Server page for db-02 (Ubuntu 22.04, critical, disk 96 % full): OS, IP, last report, uptime, CPU, memory and load, then 24-hour charts for CPU average and peak, memory, and each disk with the warning and critical lines drawn on them, recent alerts, the thresholds in force and a Remove server button.
A server page: 24-hour charts for CPU (average and peak), memory and every disk, with the threshold lines drawn in. 7-day and 30-day views are one click away.
Settings tab: licence panel showing the 30-day trial with unlimited servers and a key field, threshold fields with their defaults (disk 90/95, CPU and memory 90 for two reports, silent after 2.5 times the interval), SMTP email alert settings with a Send test email button, alert retention, the optional MeshWatch Central address and token, the update check switch (off by default), password change, and the users table with roles.
Settings: licence and trial, thresholds, SMTP with a test button, retention, optional Central, the update check (off by default) and users with roles.

DOWNLOAD

Get MeshServerWatch

Install the Manager once, on a server that stays on. Then install the Agent on every server you want watched — including the Manager’s own, if you like. Version 1.0.0 throughout.

Manager

Signed · Version 1.0.0

Windows Server — 64-bit

Windows Server 2016, 2019 or 2022. Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway. The setup wizard asks you to accept the licence agreement, lets you choose the port (8455 by default) and opens it in Windows Firewall, starts the service, and ends by showing the Manager address and the certificate fingerprint your agents need. Silent install: MeshServerWatch-Manager-1.0.0-setup.exe /S /ACCEPT_EULA=1 /PORT=8455. Advanced: the executable alone, if you prefer to run its install command yourself.

Linux — Debian, Ubuntu, RHEL

Ubuntu 20.04+, Debian 11+, RHEL / Rocky / Alma 8+. The package creates the service user and the systemd unit; sudo meshserverwatch install --accept-eula then records your acceptance of the licence agreement, generates the certificate, starts the service and prints the console address and the fingerprint.

Agent — one per server

Signed · Version 1.0.0

Windows Server — 64-bit

Windows Server 2016, 2019 or 2022. Authenticode-signed and timestamped. For one server, the setup wizard: accept the licence agreement, then paste the Manager address, the agent token and the certificate fingerprint from the Manager’s Agents tab and press Test connection. When the Manager is on the same computer, Fill in from this computer issues a token and fills in all three. For many servers, the same setup runs silently, so one line installs it through GPO or an RMM tool — the Manager’s Agents tab prints it with your values:

MeshServerWatch-Agent-1.0.0-setup.exe /S /ACCEPT_EULA=1 /MANAGER=https://<manager>:8455 /TOKEN=<msw_…> /FINGERPRINT=<sha256>

For a Manager reached over plain http://, use /INSECURE_HTTP=1 instead of /FINGERPRINT=. Exit code 0 means installed; 2 means the licence agreement was not accepted or a value is missing. Advanced: the executable alone, if you prefer to run its install command yourself.

Verify your download

Run shasum -a 256 <file> on Linux, or Get-FileHash -Algorithm SHA256 <file> in PowerShell, and compare the result with the published checksum. One file lists every Manager and Agent package.

Checksums

Installation and administration guide → — installing the Manager, issuing a token, installing agents with the setup wizard or one line, thresholds, email, licence seats, and connecting to MeshWatch Central.

Licence agreement. The Manager and the Agent install only after you accept the licence agreement (meshwatch.app/terms) — a checkbox in the setup wizards, /ACCEPT_EULA=1 for a silent setup, --accept-eula on Linux, and a required box when you create the first administrator. Every installer also puts it next to the program as EULA.txt.

Every Manager starts with a 30-day trial with unlimited servers, counted from the first agent report. Nothing is asked for up front — no card, no account, no email address.

Manager requirements

Windows Server 2016, 2019 or 2022 (x64), or Ubuntu 20.04+, Debian 11+, RHEL / Rocky / Alma 8+ (amd64 or arm64). One open TCP port, 8455 by default, reachable from the servers that will report — the Windows setup wizard opens it in Windows Firewall for you. No runtime and no database to install. A server that stays on: agents queue for 6 hours while the Manager is away, not longer.

Agent requirements

Windows Server 2016, 2019 or 2022 (x64); Ubuntu 20.04+, Debian 11+, RHEL / Rocky / Alma 8+ (amd64 or arm64) with systemd. It reads the event log or journald with the rights the installer gives it and writes only to its own state folder. On Linux the unit runs with a 100 MB memory ceiling. Outbound HTTPS to the Manager on port 8455 is the only connection it makes.

Optional

An SMTP server for email alerts. MeshWatch Central 1.3.9 or later (ships 13 October 2026) if you want alerts and status rows forwarded there. Your own TLS certificate, if you prefer it to the generated one — agents can then trust the CA instead of pinning a fingerprint.

PRICING

Priced per server. The Manager is included.

Monthly

$5/server /month

Minimum 3 servers (US$15 a month). Billed every month for the number of servers you choose.

  • Manager with the browser console, included
  • Agents for Windows and Linux
  • CPU, memory, every disk, error-level log events
  • 30 days of charts per server
  • Threshold and silence alerts, email alerts
  • Roles: admin, operator, viewer
  • MeshWatch Central integration
Buy monthly

Annual

$48/server /year

20% off — the same as US$4 a server a month. Minimum 3 servers (US$144 a year). Billed once a year.

  • Everything in Monthly
  • One invoice a year
  • Manager included, as in Monthly
Buy annual

On the Stripe page you choose the number of servers (minimum 3) and tick the licence agreement; the licence key arrives by email after payment.

Start with the 30-day free trial — unlimited servers, no card, no account. Charges are generally non-refundable, except where the law requires a refund or where we approve a refund request for a billing error submitted within 14 days of the charge (see the Terms of Use) — so please evaluate during the trial before you buy.

The trial begins when the first agent reports and covers as many servers as you connect. A licence key carries a number of seats; servers take seats in the order they first reported, and a server that is already reporting is never cut off when the seats run out — only a new server beyond the seats is refused, and the console tells you which. Removing a server on its page frees its seat. When the trial or the key expires, agents are refused and keep collecting locally; the charts and alerts you already have stay visible. The key is emailed after checkout and verified on your own Manager — there is no licensing server to reach.

FAQ

Common questions

Do I need MeshWatch Central?

No. MeshServerWatch is a complete product on its own: agents, Manager, console, charts, alerts and email. Central is a separate, optional product for people who run several MeshWatch products and want one inbox. If you connect it, the Manager forwards alerts and one status row per server; if you do not, nothing changes.

What exactly does the agent send?

Every interval: a hashed machine id, host name, IP address and aliases, OS name, agent version, uptime, CPU average and peak with the core count, memory total and used, each real disk with its mount, file system, total, used and percentage, and on Linux the load averages. For error events: the severity, the log (System, Application, journal), the source, the event id, the time and a summary of at most 300 characters. Never the full message text, event XML, user SIDs, user names, process lists or command lines. Only numbers and one-line summaries — nothing else leaves the server.

Which log events are collected?

On Windows, the System and Application event logs at Critical and Error level. Warning and Information events, and the Security log, are not collected. On Linux, journald entries at priority err and above (err, crit, alert, emerg); without journald, /var/log/syslog or /var/log/messages. Each event becomes a one-line alert within about 30 seconds; the same event is sent at most once per 10 minutes, with repeats counted, and at most 20 alerts go out per 30-second batch. The agent’s own log lines are never turned into alerts.

Can one token serve all my servers?

Yes, and that is how it is meant to be used. Issue one token on the Manager’s Agents tab and put it in the deployment script; the Manager tells servers apart by machine id, not by token. Issue several tokens if you want to revoke one site or one team without touching the others. A revoked token stops every agent using it at their next report.

What happens when the seats run out?

Nothing happens to the servers already reporting. Seats are taken in the order servers first reported, so the first N are licensed. A new server beyond that number gets a 402 seat-limit answer, appears in the console as unlicensed with a yellow notice, and its agent retries every hour. Add seats, or open a server you no longer monitor and press Remove server to free its seat — its charts are deleted, its alerts stay.

What happens when the trial ends?

The Manager stops accepting reports (402 trial-ended) until a licence key is entered in Settings. Everything already collected — 30 days of charts, every alert — stays visible. Agents keep collecting and retry every hour, so entering a key resumes the picture without reinstalling anything.

Why a certificate fingerprint instead of just HTTPS?

Because the Manager’s own certificate is self-signed, and because an agent sending a token to whatever answers at an address is a classic way to lose the token. The Manager shows its SHA-256 fingerprint at install, in meshserverwatch status and next to every token. The agent is given that value with --fingerprint and aborts the TLS handshake — before the token is sent — if the certificate does not match. If you install your own certificate from a CA your servers trust, you can leave the fingerprint out; there is deliberately no option to disable the check.

Which ports do I open?

One: TCP 8455 inbound on the Manager, from the servers that report to it and from the browsers that use the console. Agents make outbound connections only. The Windows setup wizard adds the rule for you (Allow this port through Windows Firewall, ticked by default). By hand on Windows Server: New-NetFirewallRule -DisplayName "MeshServerWatch" -Direction Inbound -Protocol TCP -LocalPort 8455 -Action Allow. With ufw: sudo ufw allow 8455/tcp. The port is a setting (--port).

Where is the data kept?

On the Manager: C:\ProgramData\MeshServerWatch\Manager\data\ on Windows, /var/lib/meshserverwatch/manager/ on Linux. Settings, alerts, servers, users, token hashes and the licence are JSON files; reports are one JSONL file per server per day; the certificate is in tls/. Back up that folder and you have everything. The agent keeps only its configuration and a small state folder (C:\ProgramData\MeshServerWatch\Agent\, /var/lib/meshserverwatch/agent/).

Does uninstalling delete my data?

No. meshserverwatch uninstall, the Windows uninstallers (Settings > Apps) and apt remove stop and remove the service and leave the configuration and data in place, so a reinstall picks up where it left off. On Linux, apt purge of the agent package also removes the agent’s configuration, state and user.

Does the Manager contact anyone?

Not unless you tell it to. It makes no outbound connection except the SMTP server you configure, the Central you configure, and — only if you switch it on — one unauthenticated request a day to a static version file on meshwatch.app. That request carries nothing about your deployment. The licence key is verified locally against a public key built into the Manager.

What can I do without the console?

Issue, list and revoke agent tokens (meshserverwatch token issue), see the address and fingerprint (status), reset a forgotten password (reset-password <user>, on the Manager host only — deliberately not over the network), and on each server run meshserverwatch-agent test and status, which explain in plain words what the agent is doing and why.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.