Skip to content
WWatchpost

First run

Create the first administrator

Set up the account that will enroll posts and manage this Watchpost.

WWatchpost
OverviewResource surveyPostsAdd a postRun a checkHistoryRulesEvidenceInvestigateActionsIncidentsSNMP devicesFleetUsersAuditAccount

Operational state

Overview

Health, evidence, alerts, and incidents across every post.

Enroll post

Recent posts

View all

Active evidence

Fleet at a glance

Resource survey

Recent CPU, memory, and disk use across every post on one screen.

Inventory

Posts

Every system, service, or device monitored by this Watchpost.

Enroll post

Post settings

Edit post

Change inventory details without breaking the post identity or its history.

Back to posts

Permanently delete post

Deletion removes collector credentials, samples, rules, alerts, logs, and post-scoped investigation history. Archive instead if any of that may be useful.

Posts

Add a machine or device

Record where it is, choose what it is, then connect the appropriate small collector.

  1. Identity
  2. Kind
  3. Review

Name and locate the post

Choose what this post is

A host collector runs on the post and sends telemetry outbound to Watchpost. Watchpost does not open or administer an inbound agent port.

Review enrollment

Host posts continue to a one-use pairing command and wait for the first delivered sample.

Host monitoring

Watchpost Agent, installed before pairing

  1. Install the Watchpost Agent on the machine (its local interface binds to loopback; the CLI is equivalent).
  2. From the agent, enter this Watchpost URL and request pairing. Both sides show the same three-word phrase.
  3. Match the phrase and approve it here. The agent collects its one-time credential and begins delivering CPU, memory, disk, load and uptime outbound.

An unpaired agent is a valid quiet state. Archive, delete, revoke, reset and uninstall remain distinct operations.

Connectivity

Run a check

Test a target immediately without creating a scheduled rule.

Immediate check

Signals

History

Compare up to four numeric signals from the last hour.

No chart selected

Choose a post and one or more signals to draw its recent history.

Export CSV

Deterministic alerting

Create a rule

Evaluate each matching observation against an explicit threshold.

Operational record

Evidence

Add and search bounded log evidence. Citations from investigations return here.

Add log evidence

Search evidence

Read-only agent

Investigate

Ask a bounded question and attach evidence. Answers may only cite supplied, verified records.

Controlled operations

Actions

Request a typed operation, inspect its impact, then execute and verify it.

Response

Incidents

Durable operational episodes that connect alerts, evidence, investigation, and resolution.

Open an incident

Current incidents

Read-only SNMPv3

Connect an SNMP device

Use an authPriv account, choose a bounded profile, and test before saving credentials elsewhere.

  1. Connection
  2. Profile
  3. Test

Connection

Bounded profile

Test connection

Credentials are sent only to this Watchpost for the immediate poll and are not returned in the result.

Watchpost cluster

Cluster

Pair Watchpost servers without merging human accounts, Agent identities, or databases.

Join another Watchpost

Invite a Watchpost

Create a short-lived, single-use invitation. The token is shown once.

Accountable operations

Audit log

Attributable record of every state-changing operation. Administrator access only.

Global roles

Users

Administrator management of viewer, operator and administrator accounts.

Your account

Account

Rotate your own password. Other sessions are revoked; this session stays.