SNMP TRAP RECEIVER FOR WINDOWS, LINUX & MACOS

Your switches are already telling you when something breaks. TrapWatch is what listens.

A trap is a device raising its hand: a link went down, a power supply failed, something restarted. Most networks send them into a log file nobody reads, or nowhere at all. TrapWatch receives them from anything on your network — no device list to maintain first — decodes what they mean in plain English, and learns each device's normal pattern well enough to tell you when one stops being normal.

Accepts traps from any source SNMP v1 & v2c Flapping detection No cloud account Runs on your server 30-day trial

DEMO

See it in action

No device registry to keep up to date

Most trap collectors want you to declare every device before they will listen to it. That sounds tidy until the one box nobody documented is the one that fails — and its trap is discarded because it was not on the list.

TrapWatch accepts a trap from any address that can reach the port. The new device appears in the table the moment it speaks. If you want to restrict who is accepted, set community strings; traps that do not match are counted as rejected rather than silently dropped, so “why am I not seeing anything?” has an answer on screen instead of a shrug.

It says what the trap means

A raw trap is an OID and a list of numbered variables. TrapWatch decodes the standard ones — linkDown, linkUp, coldStart, warmStart, authenticationFailure — into a sentence, pulls the interface name out of the varbinds, and assigns a severity so a link drop does not sit at the same weight as a routine restart.

Vendor-specific traps are shown by their OID, exactly as received. TrapWatch does not invent a description for a trap it does not know. A plausible-sounding guess would send you looking in the wrong place, which is worse than an OID you can paste into a vendor search.

What the detection actually does

Three things, all running inside the application, on the machine you installed it on. No trap, address or community string is sent anywhere.

Flapping. A link that goes down and up repeatedly. It counts direction changes, not trap count — five linkUp traps in a row is a chatty device, not a flapping link, and calling it flapping would train you to ignore the alert.

Trap storms. It keeps a running average of how often each device sends each kind of trap, and reports when the rate departs from it. The comparison is against that device's own history, not a number someone guessed.

First sightings. A device that has never sent a trap before, or a trap OID never seen from anywhere. Often the most useful signal on the screen — and the reason it waits: it stays silent until it has a baseline, about half an hour, because on the first run everything is new.

Rules for what you already know

Detection covers what you do not know to look for. Rules cover what you do: alert on linkDown from these three core switches, at this severity or above, and do not repeat within five minutes.

The repeat suppression is keyed to the rule and the device. One noisy switch cannot bury the same event happening on a different one — a mistake that makes a quiet dashboard look like a working one.

Port 162 needs root. TrapWatch does not.

162 is the standard trap port and it is below 1024, so binding it requires administrator rights. TrapWatch listens on 1162 by default and starts without them. Point your devices at 1162, or grant the privilege and use 162 where the devices cannot be changed — the port is a setting, and the app tells you plainly when it cannot bind one.

Everything stays where you put it

Traps are written to the machine that received them, one file per day, and are never deleted to enforce a plan. The retention setting is yours to set — zero means keep everything. Export to CSV whenever you need to hand something to someone else.

There is no telemetry and no licensing callback. The licence key is verified against a public key built into the application, so activation works on a network with no outbound access at all.

It fits with the rest

TrapWatch works on its own. Connected to your own MeshWatch Central server, its alerts join whatever SyslogWatch, DeviceWatch, TrafficWatch, CertWatch and ConfigWatch are reporting, so a link that flapped and a config that changed on the same switch arrive as one incident rather than two unrelated lines.

What goes to Central is the severity, the source address and a one-line summary. Never the varbinds — a device can put anything in those — and never the community string, which is effectively a password.

Four languages

The interface is English, Japanese, Korean and Simplified Chinese, switchable while it runs. What a device sent — its address, the trap OID, the interface name — is never translated. Rewriting what arrived on the wire is not something a monitoring tool should do.

DOWNLOAD

Get TrapWatch

Signed · Version 0.1.5

Windows — 64-bit

Windows 10/11 and Windows Server 2016 or newer (Desktop Experience). Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

Download Installer · 95 MB

Linux — 64-bit

AppImage runs anywhere; the .deb is for Debian and Ubuntu. Note that binding port 162 needs elevated privileges — the default of 1162 does not.

Notarised · Version 0.1.5

macOS

macOS 12 Monterey or newer. Signed with an Apple Developer ID and notarised by Apple, so it opens without a Gatekeeper warning.

Verify your download

Run shasum -a 256 TrapWatch-0.1.5-x64.exe (or certutil -hashfile on Windows) and compare the result with the published checksum.

Checksums

Installation and administration guide → — first run, choosing the port, pointing your devices at it, firewall rules, and connecting it to MeshWatch Central.

Every install starts with a 30-day trial with every feature enabled. Nothing is asked for up front — no card, no account, no email address.

PRICING

One edition. Thirty days to decide.

TrapWatch

$228/year

About $19 a month, billed yearly. One price, per installation — there is no cheaper tier that quietly drops traps.

  • Traps accepted from any device, no registry
  • SNMP v1 and v2c, standard and vendor traps
  • On-device anomaly detection
  • Alert rules with per-device repeat suppression
  • Desktop notifications
  • CSV export and local history
  • MeshWatch Central integration
  • English, Japanese, Korean, Simplified Chinese
Buy TrapWatch

Or start the 30-day trial first — no card, no account.

There is no free tier, and the trial is not a crippled version — every feature is on for thirty days. When it ends, the traps you already received stay readable; TrapWatch simply stops accepting new ones until a key is entered. Nothing you collected is taken away or held hostage. The licence key is emailed after checkout, carries its own expiry, and is verified on your own machine — TrapWatch never contacts a licensing server, so it keeps working on an isolated network.

FAQ

Common questions

How is this different from snmptrapd?

snmptrapd receives traps and writes them somewhere. That is a genuinely solid piece of software and if a log file is all you need, use it. What it does not do is tell you what a trap means, notice that a link has flapped six times in ten minutes, or say that a device just sent its first trap ever. TrapWatch is the layer above receiving: decoding, severity, and noticing the pattern change.

Which SNMP versions does it accept?

v1 and v2c, which is what network equipment actually sends. v3 traps are not supported — v3 requires per-device engine IDs and credentials, which would mean the device registry this deliberately avoids. If you need v3, say so and it will be weighed properly rather than promised here.

Why does it listen on 1162 instead of 162?

Because 162 is below 1024 and binding it requires administrator or root privileges, and an application that demands elevation to start is an application people run as root. TrapWatch defaults to 1162 so it starts as an ordinary user. If your devices cannot be pointed at a different port, change the setting to 162 and grant the privilege — on Linux, setcap 'cap_net_bind_service=+ep' is enough and does not need root at runtime. For the headless service, uncomment the AmbientCapabilities=CAP_NET_BIND_SERVICE line in its systemd unit instead.

Do I have to configure community strings?

No. Left blank, TrapWatch does not check them and accepts anything that reaches the port — the honest default for a tool whose whole point is not requiring setup before it works. Set them and non-matching traps are rejected, with a count on screen so you can tell “nothing is arriving” apart from “everything is being refused”. Note that a community string travels in clear text in v1 and v2c; it is a filter, not security.

What does the anomaly detection send anywhere?

Nothing. It runs in the application process on your machine. There is no model to download, no service to call, and no data to upload. It builds its picture from the traps you receive and keeps it in memory and on your disk.

Why does it stay quiet at first?

Because on the first run every device and every trap is new, and an alert that fires for everything teaches you to ignore alerts. It waits until it has a baseline — roughly half an hour of traffic — before it will call anything unusual. Rules work immediately; they do not need a baseline.

Where is the data kept?

In a folder in the user profile of whoever runs it, one file per day. Nothing is deleted to enforce a plan. The retention setting is yours: set a number of days, or leave it at zero to keep everything. You can export any of it to CSV.

Does it run on a server?

Yes, and that is the expected deployment — Windows Server and Linux both. The desktop app has a window, so it needs a session to display in (a logged-in console, RDP, or a desktop environment on Linux). On a Linux server without one, use the headless mode below.

On a Linux server with no graphical session the desktop app prints Missing X server or $DISPLAY; nothing is wrong with the install. For that case the .deb (not the AppImage) includes a headless mode: it receives, decodes, stores and alerts the same way and serves the same screen to your browser. Run /opt/TrapWatch/trapwatch-headless; it prints the web UI address with a one-time token on 127.0.0.1 port 8162. Open it through an SSH tunnel — ssh -L 8162:127.0.0.1:8162 user@server — or an HTTPS reverse proxy, never as plain HTTP on an untrusted network. A systemd unit is installed next to it; it listens on 1162, and to use 162 you uncomment one capability line in it. Step by step: Run on a server without a desktop.

What happens when the trial ends?

TrapWatch stops accepting new traps and keeps showing you everything it already received. Nothing is deleted and nothing is locked behind an upgrade screen. Enter a licence key and it resumes.

Does it work with MeshWatch Central?

Optionally. Point it at your own MeshWatch Central server and its alerts join the other MeshWatch products in one shared inbox, so events on the same device correlate into a single incident. What is sent is the severity, source address and a one-line summary — never the varbinds, never the community string. Central is a separate product you run on your own server; TrapWatch works exactly the same with or without it.

CONTACT

Questions or feedback? Email support@meshwatch.app or open a topic on the Support page.