NETWORK SYSLOG SERVER FOR MACOS, WINDOWS & LINUX

Every router log, live on your desktop.

SyslogWatch is a syslog server for your network on macOS, Windows and Linux. Point any router, NAS, firewall, or Linux box at your computer and events show up instantly — link flaps, failed logins, firmware warnings, VPN drops, cron failures. Local-first. No cloud account.

The 30-day trial opens Enterprise — AI anomaly detection included, no card, no account. When it ends SyslogWatch drops to the free tier and keeps running; it does not lock you out. Pro is US$99/year, Enterprise with AI is US$999/year. See what each tier adds →

Windows, Linux and macOS builds are all below. The Mac App Store edition is Pro-only — Apple’s in-app purchase rules mean it cannot include AI.

RFC 3164 RFC 5424 UDP + TCP Port 1514, no admin Local storage AI anomaly detection

DEMO

See it in action

ACTUAL PRODUCT SCREENS

Enterprise, with AI anomaly detection

Direct screenshots from the signed, notarised build — not mockups.

SyslogWatch live log table with Enterprise Active and AI Detection on, showing coloured severity rows from firewall, web, database and NAS hosts
Live log table with Enterprise active. Severity colours, host and program columns, and the AI Detection toggle with a live Findings count in the toolbar.
SyslogWatch Anomaly Detection panel showing a learned baseline from over 22,000 processed messages and 8 recognised patterns
Anomaly Detection panel. Shows the learned baseline and recognised message patterns — runs entirely on this computer, no cloud service, no API key.

WITH THE DETECTOR ON, AND WITHOUT IT

A rule finds what you knew to look for.

An alert rule is a question you asked in advance. It matches the text you told it to match, and it is very good at that. What it cannot do is notice that something is happening more often than usual, or that a message has arrived which no device on your network has ever sent before. To a rule, three of something and three thousand of it look identical, and anything you did not think of does not exist.

What the detector learns

Switch on AI Detection and SyslogWatch starts reading your own logs to work out what an ordinary day looks like. It does this in two steps, and neither of them involves a server.

First it groups messages into patterns. These three lines are one event type wearing different clothes, and the app treats them as one:

Failed password for admin from 10.0.0.5 port 22 ssh2
Failed password for root  from 203.0.113.9 port 51422 ssh2
Failed password for test  from 198.51.100.3 port 33087 ssh2

  →  Failed password for <*> from <IP> port <NUM> ssh2

The vocabulary comes from your equipment, not from a dictionary shipped with the app, so it works the same for a Ubiquiti router, a Synology NAS, a pfSense firewall or a Linux host — in whatever language they log in.

Then it learns how often each pattern normally occurs, counted in five-minute intervals. That is the part a keyword rule has no way to express. After this, "unusual" means something specific and measurable rather than a hunch.

Three things get reported that no rule could raise on its own.

Spike

A pattern you already have, arriving at least twice its normal rate and outside its usual variation. Both conditions must hold. A busy pattern varies little, so a purely statistical test treats a twenty per cent bump as an emergency — the absolute ratio is what keeps the quiet days quiet.

Burst

A pattern with no history at all, arriving fifty or more times inside one five-minute interval. A message never seen before is worth knowing about. Four hundred of them in five minutes is worth knowing about immediately, and the count is the part that tells you which one you are looking at.

New

A message shaped unlike anything since the app finished learning. Often harmless — a backup job running for the first time — and occasionally the first trace of something nobody had written a rule for, because nobody knew to.

A worked example

Against a synthetic twenty-four hour stream — 23,908 messages, seven ordinary patterns from an sshd, nginx, kernel and cron mix, with a twenty-minute SSH brute-force attempt dropped into the middle — and with no alert rules configured at all, the detector reported four things across the whole day.

Two of them were the attack. Once the moment a login failure unlike anything before it arrived, and again when four hundred of them landed inside a single interval. The other two were a backup job and a login session appearing for the first time: correct, and quiet enough that nobody has to start ignoring the panel.

What it does not do

It does not know what is dangerous, only what is different. A first-ever backup run and a first-ever intrusion both read as new. The detector narrows the pile you have to look at; it does not decide for you.

The first hour is silent. Twelve five-minute intervals go by while the baseline forms. Before that everything is new, and saying so would be noise rather than information.

It does not replace your rules. They run side by side. For the things you already know to watch for — a specific interface, a specific error string — a rule is more direct, and it can send email.

Off means off. Turn the switch down and nothing is learned and nothing is recorded about your patterns; the app goes back to plain keyword rules. Turn it back on and what it had already learned is still there.

All of it happens on your computer

There is no cloud service behind this, no API key to paste, no account, and no model to download. The whole detector is a few hundred lines of plain JavaScript inside the app, with no dependencies, and it makes no network calls of any kind. Your logs are never uploaded anywhere — not to us, not to anyone — which is also why it keeps working on an isolated network with no internet connection at all.

You can see exactly what it has learned. The Findings panel lists every pattern it recognises along with how often each one normally occurs, so the baseline it is judging against is open to inspection rather than hidden behind a score.

WORKS OUT OF THE BOX WITH

Ubiquiti / UniFi pfSense OPNsense MikroTik Cisco Synology QNAP Proxmox TrueNAS OpenWrt Linux journald

Real-time clarity

Severity colours and instant filter-as-you-type help you focus on the events that matter. Stop tailing SSH sessions.

Private by design

Logs stay on your computer. No developer analytics. No advertising network. No cloud account required.

Alerts you control

Rules match on severity, host, program and message content, then raise a sound or email you through your own SMTP server — with rate limits so a flapping link cannot bury your inbox.

AI anomaly detection ENTERPRISE

Included in Enterprise. SyslogWatch learns what normal looks like on your own machines — grouping messages into patterns and building a frequency baseline for each one — then flags sudden spikes and messages it has never seen before, including things no keyword rule was ever written for. It runs as plain JavaScript with zero dependencies: no cloud service, no API key, no model to download, and no log data ever leaves this machine.

No administrator password required

SyslogWatch listens on port 1514 by default, so it starts without any privileged access to your computer. Configure the same destination port on your router, NAS, or firewall.

DOWNLOADS

Get SyslogWatch

Recommended · Notarized by Apple · Apple silicon

macOS — direct download ENTERPRISE + AI

Skip the App Store and this build unlocks Enterprise and AI anomaly detection on Mac too — the App Store edition tops out at Pro because Apple's in-app purchase rules don't allow third-party subscriptions there. Signed with a Developer ID certificate and notarised by Apple, so Gatekeeper opens it with no warning.

Download DMG (Apple Silicon) · 120 MB

Signed · Version 1.3.9

Windows — 64-bit

Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Run the installer and SyslogWatch is added to your Start menu. Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

Download Installer · 96 MB

Version 1.3.9 · x86-64

Linux — 64-bit

Debian package for Ubuntu, Debian and Mint. Install with sudo apt install ./SyslogWatch-1.3.9-linux-amd64.deb. Other distributions can use the AppImage or archive below.

Download DEB · 97 MB

Reviewed by Apple · Pro only, no AI

macOS — Mac App Store NO AI

Basic log monitoring. Apple’s in-app purchase rules cap this edition at Pro, so AI anomaly detection is not included — use the direct download for that. macOS 12 Monterey or newer, Apple silicon or Intel. Installs and updates through the Mac App Store, with Pro billed to your Apple Account.

Mac App Store

Notarized by Apple · Intel

macOS — Intel

For Intel Macs. Same notarised, Enterprise-capable build as the Apple Silicon version above.

Download DMG (Intel) · 124 MB

Windows — portable EXE

No installer, no admin rights needed. Download and run — nothing is written outside its own folder.

Download EXE · 96 MB

Windows — ZIP

Unzip anywhere and run SyslogWatch.exe. Same build as the installer, just unpacked.

Download ZIP · 134 MB

Linux — AppImage

Works across most distributions without installing anything. Make it executable and run it: chmod +x SyslogWatch-1.3.9-linux-x86_64.AppImage && ./SyslogWatch-1.3.9-linux-x86_64.AppImage.

Download AppImage · 123 MB

Linux — portable archive

For Fedora, RHEL, Arch, openSUSE and anything else. Unpack and run ./syslogwatch. Install gnome-keyring or libsecret first so your licence key and SMTP password are stored encrypted.

Download TAR.GZ · 116 MB

Open the firewall

Most Linux distributions drop incoming traffic by default. Run sudo ufw allow 1514/udp && sudo ufw allow 1514/tcp, or on Fedora and RHEL sudo firewall-cmd --add-port=1514/udp --add-port=1514/tcp --permanent.

Setup notes

Verify your download

Windows: CertUtil -hashfile SyslogWatch-1.3.9-windows-x64-setup.exe SHA256 in Command Prompt. macOS/Linux: shasum -a 256 -c SyslogWatch-SHA256SUMS.txt. Compare against the published checksums.

Checksums

Need an older build?

Previous versions are kept for a while in case a new release causes trouble on your setup. Sign in with a work email or a licence key to download one.

Previous versions

Installation and administration guide → — first run, settings, firewall rules, and connecting it to MeshWatch Central.

Open port 1514 before you start: on Windows, allow SyslogWatch through Defender Firewall on your private network when it asks; on Linux, allow 1514/udp and 1514/tcp on ufw or firewalld. Otherwise no messages arrive.

PRICING

Free forever. Pro when you're ready.

Free

$0

Enough for a hobby setup or a single-router household.

  • UDP + TCP syslog receiving
  • RFC 3164 + RFC 5424 parsing
  • Live filter as you type
  • Severity colour coding
  • Every message saved to disk — no cap, no expiry
  • Alert rules — up to 3
Download

Pro

$99/year

Windows, Linux, and the direct macOS download — a licence key arrives by email, no App Store required. On the Mac App Store Pro is a monthly subscription at US$9.99/month instead, billed by Apple.

  • Everything in Free
  • Full-text search back through the whole archive
  • Alert rules — up to 50
  • Email notifications via SMTP
  • CSV / JSON export
  • Priority support
Upgrade in the app

Enterprise

$999/year

Windows, Linux, and the direct-download macOS build — not sold on the Mac App Store. Includes AI anomaly detection, for teams running syslog across a fleet where a noisy alert is worse than none.

  • AI anomaly detection — learns your baseline, flags what breaks it
  • Everything in Pro
  • Unlimited alert rules
  • Host, program and facility conditions
  • Regular expressions and exclusions
  • Alert rate limiting and digests
  • Automatic document archiving
  • Log retention policies
  • Ruleset export for fleet deployment
Subscribe in the app

Free is free everywhere. Through the Mac App Store, Pro is billed monthly by Apple — cancel anytime in App Store settings. On Windows, Linux, and the direct-download notarised macOS build, Pro and Enterprise are annual: you receive a licence key by email and paste it into the app; the key is checked on your own computer, so SyslogWatch never contacts a licensing server. Enterprise — including AI anomaly detection — is sold on Windows, Linux, and the direct macOS download; the Mac App Store edition tops out at Pro because Apple requires in-app purchases there. Free features remain if a subscription lapses.

SETUP GUIDES

Pointing your gear at it

Step-by-step for the devices people ask about most. Each one covers the commands, how to check delivery, and the mistakes that make it look like nothing is arriving.

All guides →

FAQ

Common questions

Is there a Windows version?

Yes. Version 1.3.9 for Windows 10/11 and Windows Server 2016 or newer (Desktop Experience), 64-bit, is available above as an installer, a portable EXE, or a ZIP. It has everything the Mac version has, plus the Enterprise edition. Allow it through Windows Defender Firewall on your private network the first time it starts.

Is there a Linux version?

Yes, 64-bit x86. Ubuntu, Debian and Mint can install the .deb; the AppImage or portable .tar.gz work on most modern 64-bit distributions — no install step needed for the AppImage. Same features as Windows, including Enterprise.

Two things to do after installing. Open the port on your firewall — sudo ufw allow 1514/udp && sudo ufw allow 1514/tcp, or sudo firewall-cmd --add-port=1514/udp --add-port=1514/tcp --permanent && sudo firewall-cmd --reload on Fedora and RHEL. And make sure a keyring is present: without gnome-keyring or libsecret, your licence key and SMTP password are stored as plain text, and SyslogWatch will warn you in Settings when that is the case. The .deb pulls in libsecret for you.

Does it run on a server?

Yes, and that is the expected deployment — Windows Server and Linux both. The desktop app has a window, so it needs a session to display in (a logged-in console, RDP, or a desktop environment on Linux). On a Linux server without one, use the headless mode below.

On a Linux server with no graphical session the desktop app prints Missing X server or $DISPLAY; nothing is wrong with the install. For that case the .deb and .tar.gz include a headless mode: the same receiver, rules, alerts and licence, with the same screen served to your browser. Run /opt/SyslogWatch/syslogwatch-headless; it prints the web UI address with a one-time token on 127.0.0.1 port 8514. Open it through an SSH tunnel — ssh -L 8514:127.0.0.1:8514 user@server — or an HTTPS reverse proxy, never as plain HTTP on an untrusted network. A systemd unit is installed next to it. Step by step: Run on a server without a desktop.

The window opens but stays blank

First, extract the download to a new, empty folder rather than over a previous version, and make sure no SyslogWatch process is still running while you do — a partial extraction produces exactly this symptom. Then verify the download with CertUtil -hashfile SyslogWatch-1.3.9-win.zip SHA256 against the published checksum.

If you are running 1.1.1 or 1.1.2, that is a known bug in those two releases — a stylesheet rule hid the whole interface on Windows and Linux. Update to the current version above.

On 1.1.3 or later, the app reports its own startup failures: the window shows the error, or you can open Help → Open Data Folder and send renderer.log, or press Ctrl+Shift+I and copy the Console tab. Send any of those to support@meshwatch.app.

SyslogWatch will not start on Ubuntu 24.04

Ubuntu 24.04 and later restrict unprivileged user namespaces, which Electron's sandbox relies on. If you see a message about the SUID sandbox helper, run ./syslogwatch --no-sandbox, or install the .deb instead — it sets the sandbox helper permissions during installation.

Which port does SyslogWatch listen on?

Port 1514 by default (UDP + TCP), so no administrator password is needed on either platform. You can change the port in Settings; ports below 1024 require elevated access.

Does it work with UniFi / pfSense / Synology / MikroTik?

Yes. Any device that sends RFC 3164 or RFC 5424 syslog messages works out of the box. Setup guides for the major platforms are in the Setup guides section above.

My logs are in Korean, Japanese or Chinese. Will the text display correctly?

Yes. RFC 5424 requires UTF-8, but RFC 3164 specifies no encoding at all, so most devices and Windows event-log forwarders send the operating system's code page instead — CP949 on Korean Windows, Shift_JIS on Japanese, GBK on Chinese. Tools that assume UTF-8 turn those messages into rows of ����, and the damage is permanent because the original bytes are discarded.

SyslogWatch reads each message as UTF-8 when the bytes really are UTF-8 and falls back to a code page otherwise, guessed from your system locale. A Korean or Japanese install shows the right characters on first run with nothing to configure. If your collector runs in a different language from the devices sending to it, choose the encoding under Settings → Receiving Server.

Where are my logs stored?

Only on your own computer — under Application Support on macOS, %APPDATA%\SyslogWatch\ on Windows, and ~/.config/SyslogWatch on Linux (/var/lib/syslogwatch/SyslogWatch for the headless service). Nothing is sent to MeshWatch, to advertising networks, or to any cloud account.

What does the Enterprise edition add?

AI anomaly detection. SyslogWatch groups incoming messages into patterns and learns how often each one normally occurs, then flags sudden spikes and messages that have never been seen before — including things no keyword rule was written to catch. It runs entirely on your own machine: no cloud service, no API key, no log data ever leaves the computer.

Plus a real rule engine and the controls a fleet needs. Rules combine severity ranges, hosts, programs and facilities (with * and ? wildcards), protocol, inclusion and exclusion terms, and regular expressions — and you can test a rule against your recent logs before saving it. Alerts get rate limiting: a cooldown, an hourly cap, or a digest window that collects a burst into one email, with suppressed counts reported so a quiet inbox never hides a storm. It also adds automatic document archiving to CSV, HTML or text, log retention policies, and ruleset export so you can deploy the same policy to every machine.

Enterprise is available on Windows, Linux, and the notarised direct-download macOS build — the Mac App Store edition tops out at Pro because Apple requires in-app purchases for anything sold through the Store.

How does the AI anomaly detection work?

It builds a baseline of what "normal" looks like for your logs, then watches for deviations from it — no training data, no model download, and nothing sent anywhere. Under the hood it groups messages into templates (the way a human would notice "these are all failed SSH logins, just with different usernames") and tracks how often each template fires, measured in short time intervals.

Two kinds of findings show up: a template firing far more often than its usual rate (a spike — useful for catching things like a brute-force attempt or a flapping interface generating thousands of messages), and a template that has never been seen before during the learning period (a first-time event — useful for catching a new failure mode nobody wrote a rule for). It needs a period of normal traffic to learn from before it can tell what is unusual; until a baseline is ready, findings stay off.

Is there a Mac version that skips the App Store?

Yes. The direct download above is a notarised DMG signed with a Developer ID certificate, so Gatekeeper opens it without warning — same as any other Mac app from outside the Store. Unlike the Mac App Store build, it can sell Enterprise and AI anomaly detection, because it isn't bound by Apple's in-app purchase requirement. Licensing works the same way as Windows and Linux: an annual Stripe subscription and a licence key checked locally.

Why does alert rate limiting matter?

One flapping interface can emit dozens of syslog messages a second. Without limits that becomes thousands of emails, your SMTP provider throttles the account, and the team learns to ignore the alerts entirely. Enterprise rules let you cap how often a rule may mail you, or collect a burst into a single digest — and the count of held-back events travels with the next message, so you still see the real scale.

What is the difference between free and Pro?

Free covers live receiving, filtering, and up to 3 alert rules. Pro adds full-text search across the stored archive, up to 50 alert rules, email notifications via your own SMTP, multi-host view, and CSV/JSON export. Unlimited alert rules are an Enterprise feature.

Do I need a paid subscription to try it?

No. The free tier is fully usable, and it does not cap how much it receives or stores — every message your devices send is written to disk regardless of edition. Pro is useful when you need to search that archive, more than 3 alert rules, email notifications, or CSV/JSON export.

How does Pro work on Windows?

Subscribing is US$99/year, billed through Stripe. You receive a licence key by email straight after payment (from license@meshwatch.app, usually within a minute — check your Junk or Spam folder if it is not in your inbox) — paste it into the app under Upgrade to Pro and Pro unlocks on that computer. The key carries its own expiry date and is verified locally against a key built into the app, so activation works offline and SyslogWatch never contacts a licensing server. Each year your subscription renews, a fresh key is issued and emailed automatically.

How do I cancel Pro?

Through the Mac App Store: App Store → your profile → Subscriptions → SyslogWatch Pro → Cancel. On Windows, Linux, or the direct macOS download, email support@meshwatch.app before your renewal date — the current key keeps working until its printed expiry date either way. Your free features continue to work after that.

Is there a lifetime licence?

Not currently. Subscription pricing lets us keep the app maintained across macOS releases. If a lifetime tier becomes available it will be announced here.

Does it work with MeshWatch Central?

Optionally. Connect SyslogWatch to your own MeshWatch Central server and its alerts join whatever ConfigWatch, CertWatch, DeviceWatch, TrafficWatch and TrapWatch are reporting into one shared inbox — a log burst on the same device an interface just went down on shows up as one incident, not two. SyslogWatch sends Central a one-line summary like “47 failed logins in 5 minutes on fw-01” — never the raw log lines themselves. Central is a separate product you run on your own server; SyslogWatch works exactly the same with or without it.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.