SNMP TRAP RECEIVER FOR WINDOWS, LINUX & MACOS
Your switches are already telling you when something breaks. TrapWatch is what listens.
A trap is a device raising its hand: a link went down, a power supply failed, something restarted. Most networks send them into a log file nobody reads, or nowhere at all. TrapWatch receives them from anything on your network — no device list to maintain first — decodes what they mean in plain English, and learns each device's normal pattern well enough to tell you when one stops being normal.
Accepts traps from any source
SNMP v1 & v2c
Flapping detection
No cloud account
Runs on your server
30-day trial
No device registry to keep up to date
Most trap collectors want you to declare every device before they will listen to it. That sounds tidy until the one box nobody documented is the one that fails — and its trap is discarded because it was not on the list.
TrapWatch accepts a trap from any address that can reach the port. The new device appears in the table the moment it speaks. If you want to restrict who is accepted, set community strings; traps that do not match are counted as rejected rather than silently dropped, so “why am I not seeing anything?” has an answer on screen instead of a shrug.
It says what the trap means
A raw trap is an OID and a list of numbered variables. TrapWatch decodes the standard ones — linkDown, linkUp, coldStart, warmStart, authenticationFailure — into a sentence, pulls the interface name out of the varbinds, and assigns a severity so a link drop does not sit at the same weight as a routine restart.
Vendor-specific traps are shown by their OID, exactly as received. TrapWatch does not invent a description for a trap it does not know. A plausible-sounding guess would send you looking in the wrong place, which is worse than an OID you can paste into a vendor search.
What the detection actually does
Three things, all running inside the application, on the machine you installed it on. No trap, address or community string is sent anywhere.
Flapping. A link that goes down and up repeatedly. It counts direction changes, not trap count — five linkUp traps in a row is a chatty device, not a flapping link, and calling it flapping would train you to ignore the alert.
Trap storms. It keeps a running average of how often each device sends each kind of trap, and reports when the rate departs from it. The comparison is against that device's own history, not a number someone guessed.
First sightings. A device that has never sent a trap before, or a trap OID never seen from anywhere. Often the most useful signal on the screen — and the reason it waits: it stays silent until it has a baseline, about half an hour, because on the first run everything is new.
Rules for what you already know
Detection covers what you do not know to look for. Rules cover what you do: alert on linkDown from these three core switches, at this severity or above, and do not repeat within five minutes.
The repeat suppression is keyed to the rule and the device. One noisy switch cannot bury the same event happening on a different one — a mistake that makes a quiet dashboard look like a working one.
Port 162 needs root. TrapWatch does not.
162 is the standard trap port and it is below 1024, so binding it requires administrator rights. TrapWatch listens on 1162 by default and starts without them. Point your devices at 1162, or grant the privilege and use 162 where the devices cannot be changed — the port is a setting, and the app tells you plainly when it cannot bind one.
Everything stays where you put it
Traps are written to the machine that received them, one file per day, and are never deleted to enforce a plan. The retention setting is yours to set — zero means keep everything. Export to CSV whenever you need to hand something to someone else.
There is no telemetry and no licensing callback. The licence key is verified against a public key built into the application, so activation works on a network with no outbound access at all.
It fits with the rest
TrapWatch works on its own. Connected to your own MeshWatch Central server, its alerts join whatever SyslogWatch, DeviceWatch, TrafficWatch, CertWatch and ConfigWatch are reporting, so a link that flapped and a config that changed on the same switch arrive as one incident rather than two unrelated lines.
What goes to Central is the severity, the source address and a one-line summary. Never the varbinds — a device can put anything in those — and never the community string, which is effectively a password.
Four languages
The interface is English, Japanese, Korean and Simplified Chinese, switchable while it runs. What a device sent — its address, the trap OID, the interface name — is never translated. Rewriting what arrived on the wire is not something a monitoring tool should do.
DOWNLOAD
Get TrapWatch
Signed · Version 0.1.5
Windows — 64-bit
Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.
Download Installer · 95 MB
Linux — 64-bit
AppImage runs anywhere; the .deb is for Debian and Ubuntu. Note that binding port 162 needs elevated privileges — the default of 1162 does not.
Notarised · Version 0.1.5
macOS
macOS 12 Monterey or newer. Signed with an Apple Developer ID and notarised by Apple, so it opens without a Gatekeeper warning.
Verify your download
Run shasum -a 256 TrapWatch-0.1.5-x64.exe (or certutil -hashfile on Windows) and compare the result with the published checksum.
Checksums
Installation and administration guide → — first run, choosing the port, pointing your devices at it, firewall rules, and connecting it to MeshWatch Central.
Every install starts with a 30-day trial with every feature enabled. Nothing is asked for up front — no card, no account, no email address.