Do I need MeshWatch Central?
No. MeshServerWatch is a complete product on its own: agents, Manager, console, charts, alerts and email. Central is a separate, optional product for people who run several MeshWatch products and want one inbox. If you connect it, the Manager forwards alerts and one status row per server; if you do not, nothing changes.
What exactly does the agent send?
Every interval: a hashed machine id, host name, IP address and aliases, OS name, agent version, uptime, CPU average and peak with the core count, memory total and used, each real disk with its mount, file system, total, used and percentage, and on Linux the load averages. For error events: the severity, the log (System, Application, journal), the source, the event id, the time and a summary of at most 300 characters. Never the full message text, event XML, user SIDs, user names, process lists or command lines. Only numbers and one-line summaries — nothing else leaves the server.
Which log events are collected?
On Windows, the System and Application event logs at Critical and Error level. Warning and Information events, and the Security log, are not collected. On Linux, journald entries at priority err and above (err, crit, alert, emerg); without journald, /var/log/syslog or /var/log/messages. Each event becomes a one-line alert within about 30 seconds; the same event is sent at most once per 10 minutes, with repeats counted, and at most 20 alerts go out per 30-second batch. The agent’s own log lines are never turned into alerts.
Can one token serve all my servers?
Yes, and that is how it is meant to be used. Issue one token on the Manager’s Agents tab and put it in the deployment script; the Manager tells servers apart by machine id, not by token. Issue several tokens if you want to revoke one site or one team without touching the others. A revoked token stops every agent using it at their next report.
What happens when the seats run out?
Nothing happens to the servers already reporting. Seats are taken in the order servers first reported, so the first N are licensed. A new server beyond that number gets a 402 seat-limit answer, appears in the console as unlicensed with a yellow notice, and its agent retries every hour. Add seats, or open a server you no longer monitor and press Remove server to free its seat — its charts are deleted, its alerts stay.
What happens when the trial ends?
The Manager stops accepting reports (402 trial-ended) until a licence key is entered in Settings. Everything already collected — 30 days of charts, every alert — stays visible. Agents keep collecting and retry every hour, so entering a key resumes the picture without reinstalling anything.
Why a certificate fingerprint instead of just HTTPS?
Because the Manager’s own certificate is self-signed, and because an agent sending a token to whatever answers at an address is a classic way to lose the token. The Manager shows its SHA-256 fingerprint at install, in meshserverwatch status and next to every token. The agent is given that value with --fingerprint and aborts the TLS handshake — before the token is sent — if the certificate does not match. If you install your own certificate from a CA your servers trust, you can leave the fingerprint out; there is deliberately no option to disable the check.
Which ports do I open?
One: TCP 8455 inbound on the Manager, from the servers that report to it and from the browsers that use the console. Agents make outbound connections only. The Windows setup wizard adds the rule for you (Allow this port through Windows Firewall, ticked by default). By hand on Windows Server: New-NetFirewallRule -DisplayName "MeshServerWatch" -Direction Inbound -Protocol TCP -LocalPort 8455 -Action Allow. With ufw: sudo ufw allow 8455/tcp. The port is a setting (--port).
Where is the data kept?
On the Manager: C:\ProgramData\MeshServerWatch\Manager\data\ on Windows, /var/lib/meshserverwatch/manager/ on Linux. Settings, alerts, servers, users, token hashes and the licence are JSON files; reports are one JSONL file per server per day; the certificate is in tls/. Back up that folder and you have everything. The agent keeps only its configuration and a small state folder (C:\ProgramData\MeshServerWatch\Agent\, /var/lib/meshserverwatch/agent/).
Does uninstalling delete my data?
No. meshserverwatch uninstall, the Windows uninstallers (Settings > Apps) and apt remove stop and remove the service and leave the configuration and data in place, so a reinstall picks up where it left off. On Linux, apt purge of the agent package also removes the agent’s configuration, state and user.
Does the Manager contact anyone?
Not unless you tell it to. It makes no outbound connection except the SMTP server you configure, the Central you configure, and — only if you switch it on — one unauthenticated request a day to a static version file on meshwatch.app. That request carries nothing about your deployment. The licence key is verified locally against a public key built into the Manager.
What can I do without the console?
Issue, list and revoke agent tokens (meshserverwatch token issue), see the address and fingerprint (status), reset a forgotten password (reset-password <user>, on the Manager host only — deliberately not over the network), and on each server run meshserverwatch-agent test and status, which explain in plain words what the agent is doing and why.