RELEASE NOTES

What changed, and when.

Every released version of every MeshWatch product, newest first. The version marked Currently available is what you get from the download page today.

How to read this. These notes are written from the actual release record — the commits that moved each download page to a new build. A few early versions have no note because they shipped before the change log started; those say so rather than guessing.

Licence keys are not tied to a version. A key activates every release of the product it was bought for, and activation happens offline against a public key built into the application, so upgrading never involves us.

SyslogWatch

Network syslog server for macOS, Windows and Linux.

Product page and downloads →

SyslogWatch 1.3.9 Currently available

Released 2026-10-02

  • The trial now unlocks email alerts and archived-log search, as it should. During the 30-day trial the app said “Enterprise trial”, but the email settings were greyed out and Search archived logs opened the upgrade window instead of searching. The screen was checking for a paid licence rather than for the features the trial includes, and the archived search itself was refused in the same way. Both now follow the trial: everything the paid plans include is available until the trial ends, and after it the Free plan applies as before.
  • No other changes. If you are already using SyslogWatch, the update keeps your settings, rules and logs.

SyslogWatch 1.3.8

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • The licence panel no longer contradicts itself. With a trial running and an old key saved, it showed the trial, the old key’s details as if they were valid, and “The Free plan is active” at the same time. It now says one thing: the trial and its days left, a red line that the saved key has expired (or is not valid) and is not in use, with a Remove button, and what happens when the trial ends.
  • Connecting to MeshWatch Central saves the token when the test succeeds. A successful Test connection now stores the address and token and turns the connection on, and the button at the bottom becomes Done, which closes the dialog. Before, the bottom Save saved the other settings but not the token.
  • Headless mode for Linux servers is included in the .deb and .tar.gz. syslogwatch-headless runs the same receiver without a window and serves the same screen to a browser on 127.0.0.1:8514; a systemd unit and README-headless.txt are installed next to it. The desktop app is unchanged.
  • The Windows installer is Authenticode-signed and timestamped.
  • The upgrade dialog shows the right price for each plan during the trial. Pro showed the Enterprise price, and the Enterprise option was hidden while the trial ran.
  • A saved key that is not accepted says why, and a key for another MeshWatch product says which product it belongs to.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

SyslogWatch 1.3.7

Released 2026-09-20

  • 2026-09-25: the Windows installer is now Authenticode-signed and timestamped. Same build and version as before, signed rather than rebuilt. Its checksum changed because the signature is part of the file; the published SHA256SUMS lists the new value. The certificate is new, so SmartScreen may still show a warning until it has built reputation.
  • A crafted syslog message can no longer inject HTML into the log view. The host and application columns were written into the table as raw HTML, so a message carrying markup in those fields could alter the page. Both are now rendered as text. Message bodies were already safe.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

SyslogWatch 1.3.6

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.

SyslogWatch 1.3.5

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.

SyslogWatch 1.3.4

Released 2026-09-12

  • The Debian package would not start on a minimal server. It did not declare libasound2 or libgbm1 among its dependencies, so apt install succeeded without them and SyslogWatch then exited with error while loading shared libraries: libasound.so.2 — a message that does not say what to install. Desktop installations were unaffected, because those libraries are usually already there; server installations, which is where most of you run it, were not. Both are now declared, and on Ubuntu 24.04 the dependency names the correct package rather than a compatibility stub that satisfies the same name. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12: the package installs and the window opens with nothing added by hand. macOS and Windows are unchanged from 1.3.3.

SyslogWatch 1.3.3

Released 2026-09-12

  • The window is created before start-up work rather than after it. SyslogWatch reads its settings, licence and stored logs when it launches; the window used to be created once that had finished, which left a short gap with nothing on screen. It is now created first, so anything slow at start-up happens behind a window that is already visible. This matches how the other MeshWatch applications start. There are no other changes in this release.

SyslogWatch 1.3.2

Released 2026-09-10

  • A first run now tells you what to do, and lets you prove it works. Until a device is pointed at it, SyslogWatch showed an empty table and nothing else — you had to already know that the next step was configuring a router. The empty screen now names the port it is listening on, says where to find the setting on most devices (Remote syslog or Log forwarding), and adds a Send a test message to myself button. That button sends a real syslog packet to this computer, so if it appears in the table, receiving is confirmed working and anything left to fix is on the device or the firewall.

SyslogWatch 1.3.1

Released 2026-09-09

  • Test connection now tests what you typed. It used to test the last saved settings, so changing the address and pressing Test without pressing Save first gave the same failure no matter what you entered. That was the actual cause of connections that "would not work" on a correctly configured server.
  • Test connection gives up after 8 seconds instead of waiting indefinitely. A firewall that drops packets rather than refusing them used to leave "Testing…" on screen with no result. Timing out and being refused are now reported differently, because they mean different things.
  • An address without http://, or a token that does not start with mwc_, is now named as the problem immediately rather than after an 8-second timeout that pointed at the firewall.
  • Pressing Save in Settings now says what happened. A rejected value used to write its error into a different part of the window, far from the button, so Save looked like it did nothing. The result now appears beside the button, the offending field is focused, and a successful save says so and closes the dialog.
  • The MeshWatch Central fields are labelled Central address and Token from Central → Agents, with a note that the address is http:// unless you put a reverse proxy in front of it.
  • Switching the interface language to Japanese and back to English now restores every heading. Some — Log Retention, Email (SMTP) Settings, the Findings button and the anomaly dialog among them — stayed in Japanese, because the original wording was only remembered for elements with a single child node and those carry a badge beside the text.

SyslogWatch 1.3.0

Released 2026-09-08

  • Connect SyslogWatch to a MeshWatch Central server. Settings has a MeshWatch Central section for the address and the token Central issues. Only severity, host name and a one-line summary are sent — never log contents. The product page described this connection before now, but the shipped build had nowhere to enter the token. That is fixed.
  • Japanese interface, switchable in settings. This includes the encoding picker — the reason many people run SyslogWatch at all — which now reads 日本語 (Shift_JIS / CP932) instead of the English label. Severity lists and the detected-encoding line are translated too; they are assembled from parts, so the dictionary alone could not reach them.
  • Received log lines, host names and anything a device sent are never translated.

SyslogWatch 1.2.6

Released 2026-09-03

  • Adds the 30-day Pro trial and the notice that tells you what you lose when it ends.
  • Startup failures now show what failed instead of leaving a window-less process running.
  • Finds the other MeshWatch apps on the same machine and can hand off to them.
  • On-device anomaly detection wired up end to end.
  • macOS builds are notarised and stapled. Windows installers are unsigned.

SyslogWatch 1.2.5

Released 2026-08-31

  • Daily update check, off by default and switchable in settings.

SyslogWatch 1.2.4

Released 2026-08-31

  • LICENSE.txt is now packaged with every platform build.

SyslogWatch 1.2.3

Released 2026-08-30

  • Download and contact links moved to meshwatch.app.

SyslogWatch 1.2.0

Released 2026-08-22

  • Enterprise edition with on-device AI anomaly detection.

SyslogWatch 1.1.5

Released 2026-08-21

  • Checkout fixed.

SyslogWatch 1.1.4

Released 2026-08-10

No release note was recorded for this version. It predates the change log.

SyslogWatch 1.1.3

Released 2026-08-10

  • Replaces two broken builds.

SyslogWatch 1.1.2

Released 2026-08-10

  • Covers the case where the window came up blank.

SyslogWatch 1.1.1

Released 2026-08-10

  • Code page handling for non-UTF-8 senders (Shift_JIS, CP949, GBK).

SyslogWatch 1.1.0

Released 2026-08-08

  • Enterprise tier added.

DeviceWatch

SNMP monitoring with on-device AI. Up to 250 devices.

Product page and downloads →

DeviceWatch 1.2.9 Currently available

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • The licence panel no longer contradicts itself. With a trial running and an old key saved, it showed the trial, the old key’s details as if they were valid, and “The Free plan is active” at the same time. It now says one thing: the trial and its days left, a red line that the saved key has expired (or is not valid) and is not in use, with a Remove button, and what happens when the trial ends.
  • Charts no longer draw data that is not there. When only part of the time window had samples — for example a few minutes after the app started — the traffic and health charts filled a large wedge from the left edge. Each run of real samples is now filled on its own, and a single sample shows as a dot.
  • Network map boxes no longer overlap. Column width now follows the longest name; names longer than the box end in an ellipsis and show in full on hover. Positions you dragged are kept.
  • The Windows installer is Authenticode-signed and timestamped.
  • After the trial ends, polling really stops. Poll now could still query devices after the trial had ended; it is now blocked like the scheduled polling.
  • The trial-ended screen can be closed, and collected history stays viewable. View collected data closes it; interface and health graphs, alarms and reports open read-only. The dashboard now says monitoring is paused because the trial ended, instead of telling you to check SNMP.
  • Keys are explained. A saved key that is not accepted shows why; a key for another MeshWatch product says which product it belongs to.
  • Changing the language applies at once, and the red alarm badge no longer shows when there are no alarms.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

DeviceWatch 1.2.8

Released 2026-09-25

  • Connecting to MeshWatch Central now actually saves the token. Pressing Test connection on the Central settings verified the token and reported success, but did not store it; leaving the settings afterwards discarded it, so DeviceWatch never reported to Central even though the test had passed. A successful test now saves the address and token, turns the connection on and shows the connected state, and the button at the bottom becomes Done. Editing the address or token again returns it to Save. A failed test keeps the error on screen as before.
  • The Windows installer is Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation.

DeviceWatch 1.2.7

Released 2026-09-20

  • The device list can be sorted. A control above the list orders devices by status (down first, then unknown, hardware alerts, up), by vendor, or by name. The choice is remembered.
  • Vendor is shown for polled devices, not only discovered ones. The vendor column was filled in only when a device came in through Discovery; devices added by hand had no vendor until the next discovery run, which also made vendor sorting fall back to name order for them. It is now derived from the device's system identifier at polling time.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

DeviceWatch 1.2.6

Released 2026-09-16

  • A link on the map stayed normal when the port at one end went down. The line between two devices was drawn from whether each device answered SNMP, so a failure between two healthy devices — a pulled cable, a carrier circuit, a shut port — left the map looking as though nothing was wrong, which is the case the map exists to show. The line now reads the state of the ports the devices themselves report over LLDP/CDP. A device that is not answering is drawn red, a port that is down while both devices answer is drawn amber, because one sends you to the power and the other to the cable. Hovering a line now says which of the two it is in a sentence. Where the ports are not known the line is left normal rather than raising a false alarm.

DeviceWatch 1.2.5

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.
  • The network map put every device in one row. Devices were spread across a single line however many there were, so a site with twenty of them at the same level drew them 67 pixels apart while each box is 100 to 200 pixels wide. They overlapped and none of the names could be read. Rows now wrap, and the map grows downwards instead of squeezing.
  • The map can be arranged by hand. Drag a device to move it; where you put it is saved and used again next time, so a map arranged to match the real cabling survives adding and removing devices. Reset layout returns to the automatic arrangement.
  • Hovering over a link shows what it is. The ports at each end, as the devices themselves report them over LLDP/CDP, with link state, speed and current throughput. Where the interface counters show errors or discards, those are shown too — SNMP does not report path packet loss, so what you see is what the interface counted.
  • Two devices can be linked by hand. Where LLDP or CDP is not enabled, or the path runs across a carrier circuit, the devices cannot see each other and the map cannot work the connection out. Link by hand fills that gap. Links that would form a loop are refused.
  • Closing the discovery window. After adding devices the only way out was Cancel, which reads as though the additions will be discarded. The button becomes Close once something has been added.
  • Central connection diagnostics. The Central settings now show when the last report was accepted, how many are queued, how many were dropped, and the last error.

DeviceWatch 1.2.4

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.
  • Interface names now match what the device calls them. DeviceWatch showed the short form that switches report in ifName — gi1 on a Cisco C1300 — while TrapWatch showed the long form from ifDescr, GigabitEthernet1. The same port therefore appeared under two different names depending on which application you were looking at. Both now prefer the long form, which is the name you type into the device’s own configuration. Where a vendor leaves that field empty — FortiGate does, on every interface — the short name is used instead, so a FortiGate still shows wan and lan1 rather than a blank column.

DeviceWatch 1.2.3

Released 2026-09-12

  • The Debian package would not start on a minimal server. It did not declare libasound2 or libgbm1 among its dependencies, so apt install succeeded without them and DeviceWatch then exited with error while loading shared libraries: libasound.so.2 — a message that does not say what to install. Desktop installations were unaffected, because those libraries are usually already there; server installations, which is where most of you run it, were not. Both are now declared, and on Ubuntu 24.04 the dependency names the correct package rather than a compatibility stub that satisfies the same name. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12: the package installs and the window opens with nothing added by hand. macOS and Windows are unchanged from 1.2.2.

DeviceWatch 1.2.2

Released 2026-09-10

  • The dashboard explains itself before any device is added. On a fresh install it showed a row of zeros, which reads as a broken screen rather than an empty one. It now says what Discover does — scans your network for anything answering SNMP — and that read-only SNMP is enough, with nothing installed on the device itself. In English, Japanese, Korean and Simplified Chinese.

DeviceWatch 1.2.1

Released 2026-09-09

  • Test connection now tests what you typed. It used to test the last saved settings, so changing the address and pressing Test without pressing Save first gave the same failure no matter what you entered. That was the actual cause of connections that "would not work" on a correctly configured server.
  • Test connection gives up after 8 seconds instead of waiting indefinitely. A firewall that drops packets rather than refusing them used to leave "Testing…" on screen with no result. Timing out and being refused are now reported differently, because they mean different things.
  • An address without http://, or a token that does not start with mwc_, is now named as the problem immediately rather than after an 8-second timeout that pointed at the firewall.
  • The Test connection button in Settings did nothing at all. It read the address and token by element id, but that panel is built in JavaScript and its fields have no ids — so the button raised an error internally and reported nothing on screen. It now reads the fields it actually draws.
  • The character set for ifAlias and system strings now applies. Every device carried a fixed utf-8 setting that always won over the one in Settings, and there was no per-device control to change it — so an interface description sent as Shift_JIS stayed unreadable no matter what you chose. The setting is now followed unless a device explicitly overrides it, and existing devices are migrated.
  • Switching the interface language back to English now restores every heading.

DeviceWatch 1.2.0

Released 2026-09-08

  • Connect DeviceWatch to a MeshWatch Central server, from Settings. Only alarm summaries are sent, never the SNMP data itself.
  • This integration was written but never shipped. 1.1.9 was published without it while the product page already said it was available. This release closes that gap. It is 1.2.0 rather than a rebuilt 1.1.9 so that one version number never means two different builds.

DeviceWatch 1.1.9

Released 2026-09-03

  • Adds the 30-day Pro trial and the expiry notice.
  • Startup failures now report the cause.
  • Links into the other MeshWatch apps installed on the same machine.
  • macOS builds notarised and stapled. Windows installers unsigned.

DeviceWatch 1.1.8

Released 2026-08-31

  • Fixes charts drawing twice when tabs were switched quickly.

DeviceWatch 1.1.7

Released 2026-08-31

  • Help menu now shows the version number.

DeviceWatch 1.1.6

Released 2026-08-31

  • Daily update check, off by default.

DeviceWatch 1.1.5

Released 2026-08-31

  • LICENSE.txt packaged. Notarised macOS builds for arm64 and x64.

DeviceWatch 1.1.4

Released 2026-08-30

  • In-app legal links.

DeviceWatch 1.1.3

Released 2026-08-30

  • Download and contact links moved to meshwatch.app.

DeviceWatch 1.1.1

Released 2026-08-27

  • Properly code-signed macOS DMGs. The 1.1.0 DMGs were unsigned and rejected by Gatekeeper.

DeviceWatch 1.1.0

Released 2026-08-27

  • Network map built from real LLDP/CDP neighbour data.
  • Device editing.
  • Far fewer false alarms.

TrafficWatch

Per-device DNS visibility with on-device threat scoring.

Product page and downloads →

TrafficWatch 1.1.8 Currently available

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • Headless mode for Linux servers is included in the .deb. trafficwatch-headless runs the DNS logger without a window and serves the same screen to a browser on 127.0.0.1:8053, with a systemd unit and README-headless.txt. The desktop app is unchanged.
  • The Windows installer is Authenticode-signed and timestamped.
  • A saved key that is not accepted says why on the plans screen. On the Free plan, the alert settings now say that the MeshWatch Central connection is part of Pro.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

TrafficWatch 1.1.7

Released 2026-09-20

  • 2026-09-25: the Windows installer is now Authenticode-signed and timestamped. Same build and version as before, signed rather than rebuilt. Its checksum changed because the signature is part of the file; the published SHA256SUMS lists the new value. The certificate is new, so SmartScreen may still show a warning until it has built reputation.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

TrafficWatch 1.1.6

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.

TrafficWatch 1.1.5

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.

TrafficWatch 1.1.4

Released 2026-09-12

  • The Debian package would not start on a minimal server. It did not declare libasound2 or libgbm1 among its dependencies, so apt install succeeded without them and TrafficWatch then exited with error while loading shared libraries: libasound.so.2 — a message that does not say what to install. Desktop installations were unaffected, because those libraries are usually already there; server installations, which is where most of you run it, were not. Both are now declared, and on Ubuntu 24.04 the dependency names the correct package rather than a compatibility stub that satisfies the same name. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12: the package installs and the window opens with nothing added by hand. macOS and Windows are unchanged from 1.1.3.

TrafficWatch 1.1.3

Released 2026-09-11

  • An empty query list now tells you which of the two things is happening. Before any device is pointed at it, TrafficWatch showed an empty table — and with DNS there is no way to tell “I configured it wrong” apart from “nothing has asked yet”. The empty screen now shows this computer’s actual IP address and port to enter on your router, and adds a Send a test query to myself button. If the query appears in the table, capture is confirmed working and all that is left is pointing your devices at it. The test uses a reserved .invalid name, so it never leaves this computer.

TrafficWatch 1.1.2

Released 2026-09-09

  • Test connection now tests what you typed. It used to test the last saved settings, so changing the address and pressing Test without pressing Save first gave the same failure no matter what you entered. That was the actual cause of connections that "would not work" on a correctly configured server.
  • Test connection gives up after 8 seconds instead of waiting indefinitely. A firewall that drops packets rather than refusing them used to leave "Testing…" on screen with no result. Timing out and being refused are now reported differently, because they mean different things.
  • An address without http://, or a token that does not start with mwc_, is now named as the problem immediately rather than after an 8-second timeout that pointed at the firewall.
  • The MeshWatch Central section in Settings is open by default. It was collapsed, which is a good way to hide a feature from the people who bought the product for it.
  • Switching the interface language back to English now restores every heading.

TrafficWatch 1.1.1

Released 2026-09-08

  • The MeshWatch Central settings were collapsed inside the Alerts dialog, and people could not find where to paste the token. That section is now open by default, and the dialog is named Alerts & delivery — it holds email and Central delivery as well as the rules.

TrafficWatch 1.1.0

Released 2026-09-08

  • Fixed: Pro is now billed at $99 per year, as the pricing page has always stated. The previous checkout link was set to $99 per month. No one was charged on it — the link had no active subscriptions — and it now redirects to the correct one.
  • Japanese interface, switchable in settings. Device names, domains and query history are never translated; only the interface changes.

TrafficWatch 1.0.8

Released 2026-09-03

  • The trial no longer describes itself as the Free plan.

TrafficWatch 1.0.7

Released 2026-09-03

  • Adds the 30-day Pro trial and the expiry notice.
  • Startup failures now report the cause.
  • Links into the other MeshWatch apps.
  • On-device anomaly detection wired up end to end.

TrafficWatch 1.0.6

Released 2026-08-31

  • Help menu now shows the version number.

TrafficWatch 1.0.5

Released 2026-08-31

  • Fixes a sandbox crash.
  • Log search performance fix.
  • AI threat detection (Pro).

TrafficWatch 1.0.4

Released 2026-08-31

  • Daily update check, off by default.

TrafficWatch 1.0.3

Released 2026-08-31

  • LICENSE.txt packaged. Notarised macOS build for arm64.

TrafficWatch 1.0.2

Released 2026-08-30

  • In-app legal links.

TrafficWatch 1.0.1

Released 2026-08-30

  • Download and contact links moved to meshwatch.app.

CertWatch

TLS certificate inventory, sorted by risk.

Product page and downloads →

CertWatch 0.4.5 Currently available

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • The licence panel no longer contradicts itself. A saved key whose date had passed was still shown as “Active until” that date. It now says one thing: the trial and its days left, a red line that the saved key has expired (or is not valid) and is not in use, with a Remove button, and what happens when the trial ends.
  • The Windows installer is Authenticode-signed and timestamped.
  • A saved licence is verified every time it is read. Only the key’s signature, product and signed expiry decide the plan; other stored values are ignored. A key that expires while the app is running stops counting within a minute.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

CertWatch 0.4.4

Released 2026-09-20

  • 2026-09-25: the Windows installer is now Authenticode-signed and timestamped. Same build and version as before, signed rather than rebuilt. Its checksum changed because the signature is part of the file; the published SHA256SUMS lists the new value. The certificate is new, so SmartScreen may still show a warning until it has built reputation.
  • A webhook alert that fails to deliver is retried. The alert was marked as sent before the webhook call was confirmed, so a failed delivery was never attempted again and the alert was lost. The sent mark is now recorded only after delivery succeeds, and rolled back if it fails, so the next cycle sends it again.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

CertWatch 0.4.3

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.

CertWatch 0.4.2

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.

CertWatch 0.4.1

Released 2026-09-09

  • Test connection now tests what you typed. It used to test the last saved settings, so changing the address and pressing Test without pressing Save first gave the same failure no matter what you entered. That was the actual cause of connections that "would not work" on a correctly configured server.
  • Test connection gives up after 8 seconds instead of waiting indefinitely. A firewall that drops packets rather than refusing them used to leave "Testing…" on screen with no result. Timing out and being refused are now reported differently, because they mean different things.
  • An address without http://, or a token that does not start with mwc_, is now named as the problem immediately rather than after an 8-second timeout that pointed at the firewall.
  • The MeshWatch Central fields are labelled Central address and Token from Central → Agents, with a note about http:// and about using http://127.0.0.1:8443 when Central runs on the same machine.
  • Switching the interface language back to English now restores every heading.

CertWatch 0.4.0

Released 2026-09-08

  • Japanese interface, switchable in settings. Certificate subjects, issuers and host names are shown exactly as the server returned them and are never translated.

CertWatch 0.3.0

Released 2026-09-07

  • Fixed: on the free tier, only the first three targets were actually scanned. Every target you register is now scanned. The free tier limits how many results are shown, not how many are checked.
  • Scheduled background rechecks are now Pro-only, which is what the pricing page has always described. Manual rechecks stay available on every tier.

CertWatch 0.2.0

Released 2026-09-04

  • Version display in the window.
  • Daily update check, on by default and switchable in settings.

CertWatch 0.1.0

Released 2026-09-03

  • First release.

ConfigWatch

Read-only SSH configuration backup with line-level diffs.

Product page and downloads →

ConfigWatch 0.4.5 Currently available

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • The licence panel no longer contradicts itself. A saved key whose date had passed was still shown as “Active until” that date. It now says one thing: the trial and its days left, a red line that the saved key has expired (or is not valid) and is not in use, with a Remove button, and what happens when the trial ends.
  • The Windows installer is Authenticode-signed and timestamped.
  • A saved licence is verified every time it is read. Only the key’s signature, product and signed expiry decide the plan; other stored values are ignored. A key that expires while the app is running stops counting within a minute.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

ConfigWatch 0.4.4

Released 2026-09-20

  • 2026-09-25: the Windows installer is now Authenticode-signed and timestamped. Same build and version as before, signed rather than rebuilt. Its checksum changed because the signature is part of the file; the published SHA256SUMS lists the new value. The certificate is new, so SmartScreen may still show a warning until it has built reputation.
  • A partially collected configuration is no longer stored as complete. When paged output stopped before the device prompt returned, the truncated text was saved as that day's configuration and could show up as a spurious change. Collection now checks that the prompt came back and discards the capture otherwise.
  • SSH host keys are pinned. The host key presented on the first connection to a device is recorded, and a later connection that presents a different key is refused rather than accepted silently. The recorded keys are kept in known-hosts.json in the data folder.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

ConfigWatch 0.4.3

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.

ConfigWatch 0.4.2

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.

ConfigWatch 0.4.1

Released 2026-09-09

  • Test connection now tests what you typed. It used to test the last saved settings, so changing the address and pressing Test without pressing Save first gave the same failure no matter what you entered. That was the actual cause of connections that "would not work" on a correctly configured server.
  • Test connection gives up after 8 seconds instead of waiting indefinitely. A firewall that drops packets rather than refusing them used to leave "Testing…" on screen with no result. Timing out and being refused are now reported differently, because they mean different things.
  • An address without http://, or a token that does not start with mwc_, is now named as the problem immediately rather than after an 8-second timeout that pointed at the firewall.
  • The MeshWatch Central fields are labelled Central address and Token from Central → Agents, with a note about http:// and about using http://127.0.0.1:8443 when Central runs on the same machine.
  • A failed backup now says why. It reported only how many devices failed, so a wrong password looked exactly like an unreachable device — the reason was already there internally and simply never reached the screen. The summary now names the device and the reason.
  • Switching the interface language back to English now restores every heading.

ConfigWatch 0.4.0

Released 2026-09-08

  • Fixed a rollback bug that affected every vendor. When a top-level line changed, that line became its own section, and the generated rollback re-applied the change before removing it. Nothing was ever pushed to a device — rollback commands are yours to review and run — but the commands were wrong. Regenerate any rollback you saved from an earlier version.
  • Yamaha RTX / NVR / FWX support, built from Yamaha’s own documentation. Paging is stepped through with spaces rather than by sending console lines infinity, which appears in show config even unsaved and would have put our own line into your backup. A read-only account is enough. Not verified on real hardware yet, and the vendor list says so.
  • Japanese interface, switchable in settings. Device configuration text is never translated.

ConfigWatch 0.3.0

Released 2026-09-07

  • Fixed: on the free tier, only the first three devices were actually backed up. Every device you register is now backed up. The free tier limits history browsing, not collection.
  • If you ran the free tier with more than three devices, history for the others begins at this version. Earlier configurations were never captured and cannot be recovered.
  • The in-app notice that said those devices "are not being backed up" was wrong as of this version and now says their history stays locked instead.

ConfigWatch 0.2.0

Released 2026-09-04

  • Version display in the window.
  • Daily update check, on by default and switchable in settings.

ConfigWatch 0.1.0

Released 2026-09-03

  • First release.

TrapWatch

SNMP trap receiver with on-device anomaly detection.

Product page and downloads →

TrapWatch 0.1.5 Currently available

Released 2026-09-25

  • Deleting the data folder no longer restarts the 30-day trial. The trial start was kept only inside the app’s data folder, so removing that folder began a new trial. It is now also recorded in one or two places outside it (macOS: ~/Library/Preferences; Windows: the current user’s registry and %LOCALAPPDATA%\MeshWatch; Linux: ~/.local/share/meshwatch and ~/.config/meshwatch), and the earliest record wins. The check still happens only on this computer — nothing is sent anywhere.
  • A saved key that does not match no longer stops receiving during the trial. If an expired, mistyped or other-product key was saved, TrapWatch stopped receiving traps even with trial days left. It now keeps running on the trial and reports why the key was not accepted.
  • settings.json is readable only by the account that runs TrapWatch. It holds community strings; it was written readable by other local users.
  • Headless mode for Linux servers is included in the .deb. trapwatch-headless receives traps without a window and serves the same screen to a browser on 127.0.0.1:8162, with a systemd unit and README-headless.txt. The desktop app is unchanged.
  • The Windows installer is Authenticode-signed and timestamped.
  • Receiving now actually stops when the trial ends, as the documentation already said — it had kept receiving. The main screen shows “Stopped — the trial has ended” with the buy and enter-key actions; activating a key starts receiving again straight away.
  • Key errors are sentences (expired, not issued by us, a key for another product, incomplete) instead of codes such as bad_signature.
  • A rejected Central token is explained. When Central refuses the token (HTTP 401), the settings now say it may have been revoked or issued by a different Central, and to issue a new one on Central’s Agents tab — instead of “Central tokens start with mwc_”. Other connection failures are also shown as sentences, with the raw code on hover.

TrapWatch 0.1.4

Released 2026-09-20

  • 2026-09-25: the Windows installer is now Authenticode-signed and timestamped. Same build and version as before, signed rather than rebuilt. Its checksum changed because the signature is part of the file; the published SHA256SUMS lists the new value. The certificate is new, so SmartScreen may still show a warning until it has built reputation.
  • Settings and licence data survive a change in credential storage. Values kept with the operating system's encrypted storage are now tagged as such on disk, so if that storage later becomes unavailable — a keychain reset, a Linux server without a keyring, a signed update that the keychain does not yet trust — the file is still read correctly instead of being treated as corrupt and reset.
  • Clearer purchase guidance. The licence screen now says where the key comes from (license@meshwatch.app, usually within a minute) and to check the Junk or Spam folder if it is not in the inbox. A real purchase on 2026-09-19 landed in a spam folder; the key was valid, the customer just had to find it.

TrapWatch 0.1.3

Released 2026-09-16

  • A token issued for another product no longer fails silently. MeshWatch Central records every report under the product its token was issued for, never under the application that sent it. That rule is deliberate — an application must not be able to claim to be a different product — but it meant that pasting the wrong token produced no error anywhere. The application connected, reported successfully, and its data appeared under the other product while its own view in Central stayed empty. Test connection now compares the token against the product it belongs to, refuses a mismatch, and names the product the token was issued for.
  • A mistyped Central address is now pointed out. Most mistyped addresses are still valid addresses: 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5. The connection went somewhere else and the only symptom was that Central could not be reached, which sends people to the firewall. When a connection fails and the address you typed is not the address that was used, both are now shown.
  • Pressing Save or Test connection could do nothing at all. If the settings change failed inside the application rather than on the network, nothing was written to the screen — the button simply re-enabled itself, so it was not clear the press had registered. Both now report what went wrong.

TrapWatch 0.1.2

Released 2026-09-15

  • The check for a new version could stop happening altogether. The application checks once a day for a newer version. That check required a full 24 hours to have passed since the last one, and the repeating timer that would otherwise have run it only exists while the application is open. Between those two, an installation that is started and closed at roughly the same time each day — a workstation opened in the morning and shut down in the evening — never reached 24 hours at start-up, so it never checked again after the first time. The interval now allows four hours of slack, so a daily pattern reaches it. A machine that leaves the application running was not affected.
  • This release cannot tell you about itself. The version you are running now contains the old logic, so if it has already stopped checking, it will not announce this update. The corrected check begins working once this version is installed. This is the one release you have to come and get.
  • A linkDown trap from a FortiGate showed no port name. TrapWatch read the port name from ifDescr only. On a FortiGate 40F every one of those is an empty string — the name lives in ifName instead — so a link going down reported #5 rather than lan1, and you had to look the index up on the device yourself. It now reads ifDescr, then ifName, then ifAlias, and treats an empty value as absent rather than as a name. Checked against recorded SNMP data from nine devices: Cisco, HP, Palo Alto, Meraki, Dell, SilverPeak and APC are unchanged, and FortiGate now shows the name.

TrapWatch 0.1.1

Released 2026-09-12

  • The Debian package would not start on a minimal server. It did not declare libasound2 or libgbm1 among its dependencies, so apt install succeeded without them and TrapWatch then exited with error while loading shared libraries: libasound.so.2 — a message that does not say what to install. Desktop installations were unaffected, because those libraries are usually already there; server installations, which is where most of you run it, were not. Both are now declared, and on Ubuntu 24.04 the dependency names the correct package rather than a compatibility stub that satisfies the same name. Verified on Ubuntu 24.04, Ubuntu 22.04 and Debian 12: the package installs and the window opens with nothing added by hand. macOS and Windows are unchanged from 0.1.0.

TrapWatch 0.1.0

Released 2026-09-10

  • First release. Receives SNMP v1 and v2c traps from any device on your network without registering it first, decodes standard traps and shows vendor traps by OID rather than inventing a description. On-device anomaly detection learns each device’s normal pattern and reports a link that keeps flapping, a burst of traps from one device, and a device that has never sent one before — and stays silent until it has a baseline. Listens on port 1162 by default so it starts without administrator rights. Everything runs on the machine that received the traps. Connects to MeshWatch Central 1.3.4 or newer. English, Japanese, Korean and Simplified Chinese.

MeshServerWatch

Server monitoring for Windows and Linux: an agent on each server, a Manager you run yourself.

Product page and downloads →

MeshServerWatch 1.0.0 Currently available

Released 2026-10-02

  • First release. Two programs: MeshServerWatch Manager, a self-hosted service with a browser console, and MeshServerWatch Agent, for Windows Server 2016, 2019 and 2022, Ubuntu 20.04+, Debian 11+ and RHEL / Rocky / Alma 8+.
  • Windows setup wizards. The Manager’s wizard asks for the port (8455 by default), opens it in Windows Firewall, starts the service and ends by showing the Manager address and the certificate fingerprint. The Agent’s wizard asks for those two values and the agent token, with Test connection; when the Manager is on the same computer, Fill in from this computer fills in all three. For many servers, the Agent’s setup installs silently with one line (/S /ACCEPT_EULA=1 with the three values), which the Manager’s Agents tab prints ready to copy.
  • Licence agreement. Nothing installs or runs until the licence agreement (meshwatch.app/terms) is accepted: a checkbox in the wizards, /ACCEPT_EULA=1 for a silent setup, --accept-eula on Linux, and a required box when the first administrator is created.
  • What the agent sends. CPU (average and peak), memory, every real disk and, on Linux, load, every 10 minutes by default; error-level events within about 30 seconds, as one-line summaries — the Windows System and Application logs at Critical and Error (not Warning, Information or the Security log), and journald at priority err and above. Only numbers and one-line summaries leave the server. While the Manager is unreachable, up to 6 hours of metrics and 500 alerts wait on disk and are sent in order.
  • HTTPS by default. The Manager generates its own certificate on first start; agents pin it by its SHA-256 fingerprint and send nothing to a Manager whose certificate differs. Your own certificate works too.
  • Alerts decided by the Manager. Disk 90 % warning and 95 % critical, CPU and memory 90 % for two reports in a row, and no report for 2.5 × the interval. One alert when a state changes and one when it clears, never repeated after a restart. Email over SMTP, at most one message per minute per server.
  • 30 days of charts per server, with 24-hour, 7-day and 30-day views, an alert list with filters, acknowledgement and CSV export, and admin, operator and viewer roles.
  • Licence per server. 30-day trial with unlimited servers from the first agent report, then US$5 per server per month, or US$48 per server per year, for a minimum of 3 servers, with the Manager included. A server already reporting is never cut off when the seats run out.
  • Optional MeshWatch Central connection (requires Central 1.3.9 or later — ships 13 October 2026): alerts and one status row per server are forwarded; raw metric series are not.
  • The Windows installers are Authenticode-signed and timestamped.

MeshWatch Central

Self-hosted console that correlates all six products into one incident.

Product page and downloads →

MeshWatch Central 1.3.8 Currently available

Released 2026-09-24

  • Agents no longer sit at “waiting” after a successful test. The Agents tab has three states: waiting (the token has never contacted Central), connected (the product’s Test connection succeeded, nothing sent yet) and reporting (an alert or a device has arrived). A report Central rejected no longer counts as activity, and the table shows when each token last made contact. Products do not send a heartbeat, so Central does not invent a “down” state; the last-contact time is the honest answer.
  • The same device under different names correlates when the names can be matched. Names that differ only by case or by domain suffix are one device — core-sw-01.example.com from ConfigWatch and core-sw-01 from SyslogWatch now form an incident. Central does not guess beyond that: a label such as “Core Switch” stays separate from core-sw-01. Products may now add host, ip and aliases to their reports; current product releases do not send them yet.
  • The Overview is a proper front page. A status strip, four severity tiles, an hourly histogram of the last 24 hours in your local time, the five noisiest devices, the five most frequent alert kinds, the devices a product reported down, the latest ten alerts with an Acknowledge button, the by-product table (which now keeps products that sent nothing) and the latest incidents. Everything is counted from data Central already holds; nothing is estimated. When there is nothing, it says so instead of showing a blank.
  • Counters that were wrong are fixed. The Agents count no longer includes revoked tokens; “Unacknowledged” is shown for the last 24 hours and for all time; the Alerts tab title shows the real total instead of the page size; incidents in the last 24 hours are no longer capped at fifty.
  • Reports with a clock far in the future are refused. An alert timestamped more than five minutes ahead of Central’s clock is rejected with a 400 that says by how much. Previously one such alert sat at the top of the Alerts tab and inside the 24-hour figures for days.
  • Alerts and incidents are explained where you see them. An alert is one report a product sent; an incident is two or more products reporting on the same device within 30 minutes, computed live and never stored. The Alerts tab shows which token sent each row and the alert kind; the Devices tab marks devices known only from alerts apart from devices whose status a product reported. Times in the console are your browser’s local time; incident reports say they are written in UTC.

MeshWatch Central 1.3.7

Released 2026-09-16

  • The Windows instructions named the wrong folder. The bundle shipped as mwc-1.3.6 while its own START-HERE file told you to cd into mwc-1.3.5, and the licence file named an older version again. The version is now stamped into those files when the bundle is built, and the build stops rather than shipping if it is missing.
  • Documentation for what a token decides. Central files every report under the product its token was issued for. Using another product’s token therefore succeeds and files the data in the wrong place, with no error at either end. That, how to spot it in the Agents tab, and why an agent can read “tested just now” and “waiting” at the same time are now written down in the bundle README, the Windows guide, and every product guide.

MeshWatch Central 1.3.6

Released 2026-09-15

  • Nobody could get back in after losing the administrator password. The first person to open Central creates the administrator; after that the sign-in screen no longer offers to create one, because anyone who could reach the address would otherwise be able to make themselves an administrator. But there was no way back either — no reset, no way to see which accounts existed, and no hint on the screen. Someone who had inherited a server, or set one up months earlier, had to delete the data directory and start again. Central now has node src/server.js --reset-password <username>, run on the machine Central runs on. Give it a name that does not exist and it lists the ones that do, which is the usual problem. It asks for the new password twice, does not echo it, and closes any sessions that were open. There is deliberately no way to do this over the network: a reset you can reach from a browser is a back door, and whoever can run this command can already read the data directory. The sign-in screen now says where to find it, and so do the README and the Windows instructions inside the download.
  • A sign-in screen that could not reach the server said the wrong thing. If the status request failed, the screen assumed an administrator already existed and showed “Sign in to continue” — on a brand-new server that meant the one screen that can create the first account never appeared. It now says the server could not be reached.

MeshWatch Central 1.3.5

Released 2026-09-13

  • The documentation inside the Node bundle was wrong in three ways. That bundle is what you download to run Central without Docker — on Windows Server, it is the only way. The README.md inside it was an internal design document written in Korean; it is now written in English. Neither it nor START-HERE-WINDOWS.txt mentioned TrapWatch, although Central has accepted it since 1.3.4 — both now list all six products with the minimum version each one needs. And MWC_PORT, which is how you move Central off port 8443 when something else already uses it, appeared only in the Korean file, so a Windows administrator had no way to find it. The Windows instructions now show it.
  • The server itself is unchanged from 1.3.4. If Central is already running and answering, there is nothing here that requires you to update.

MeshWatch Central 1.3.4

Released 2026-09-10

  • The Agents table tells a connection test apart from real traffic. Pressing Test connection in a product no longer counts as the agent reporting in, so Last seen stays honest — but the test is recorded, and the row now says when it was last tested. Before this, an administrator who had just finished setting up and watched the test succeed would look at the table, read never, and conclude the connection had failed.

MeshWatch Central 1.3.3

Released 2026-09-09

  • Listens on IPv6 and IPv4 together. It bound IPv4 only, while Windows resolves localhost to ::1 first — so a browser could open the console (browsers try both) while a product’s connection test was refused. Where IPv6 is unavailable it falls back to IPv4 and says so.
  • The Agents table has a Delete button for revoked agents, and its last column is labelled Action rather than being blank. Deleting is refused unless the agent is revoked first — removing a live token from the list without revoking it would look like it was gone while it kept working.
  • The published Docker image no longer contains the licence-issuing script. It was never usable without the signing key, but it did not belong in a customer image.

MeshWatch Central 1.3.2

Released 2026-09-08

  • Console output is in English. It had been printing in Korean, which arrives as unreadable boxes in a default Windows PowerShell window — the first thing a server administrator sees.
  • Node 18 works. The requirement had been written as Node 20 without cause; that is a version many servers are already pinned to.

MeshWatch Central 1.3.1

Released 2026-09-08

  • An internal licence-issuing script was being copied into the container image by mistake. It is no longer included. It held no keys and Central itself is unchanged, but it had no business being there.
  • Central is now also published as a Node bundle. On Windows Server the container image cannot run without WSL 2 or a virtual machine, because it is a Linux image; Node runs there natively.

MeshWatch Central 1.3.0

Released 2026-09-04

  • Optional daily update check. Off by default, unlike the desktop apps — Central runs on your server.

MeshWatch Central 1.2.0

Released 2026-09-04

  • Per-device unified alert history. Click a device row to see everything reported about it across every product, not only the alerts that fell inside one correlation window.

MeshWatch Central 1.1.0

Released 2026-09-04

No release note was recorded for this version. It predates the change log.

SecureServe

Self-hosted secure file transfer server.

Product page and downloads →

SecureServe 0.1.3 Currently available

Released 2026-08-31

  • Billing domain moved to meshwatch.app.
  • LICENSE fix now actually in the shipped build.

SecureServe 0.1.2

Released 2026-08-23

  • Billing configuration fix.