Capabilities

Everything you need to watch, in one platform

OverWatch collects from your whole estate, reads your logs for meaning, and correlates it into incidents you can act on — self-hosted, multi-tenant, and secure by design.

OverWatch device inventory — unified monitoring across firewalls, hypervisors, storage, wireless, and access points

Live device inventory in OverWatch — one view across every vendor and device class.

Unified monitoring

Active polling for reachability, latency, and packet loss (ICMP), plus SNMP for CPU, memory, interfaces, and environment — with per-device OID profiles for accurate readings across vendors.

ICMP pingSNMP v1/v2cInterface countersAdaptive cadence

Vendor-aware integrations

First-party collectors go beyond SNMP to pull rich, structured data straight from platform APIs — cluster and guest metrics, wireless clients and flows, storage pools and SMART, firewall sessions and traffic.

HypervisorsWirelessStorage arraysFirewalls

Logs & event collection

A token-secured HTTP event collector, a built-in syslog server (RFC 3164/5424), and Windows Event Log ingest feed one normalized event store — with a zero-dependency agent for tailing files.

HTTP collectorSyslogWindows Event LogNormalized severity

Discovery, topology & IPAM

Discover devices and fingerprint vendors automatically, map neighbor links into a live topology graph, and manage address space with built-in IPAM — subnets, host inventory, and DHCP lease ingest.

Auto-discoveryCDP/LLDP mapSubnets & hostsDHCP leases

Capacity & forecasting

Retain metrics with downsampling, trend usage over time, and forecast days-to-full for storage pools and datastores — so capacity incidents are raised before anything actually fills.

Days-to-fullTrendsDownsamplingRetention control

Surveillance & NVR health

Monitor camera and NVR estates through a vendor-neutral provider model — detection stalls, offline cameras, detector latency, and low storage all surface as signals.

Vendor-neutralLive gridHealth signalsONVIF-ready

Distributed edge collection

Deploy lightweight collectors at remote sites. They enroll over the network with mutual-TLS, then forward normalized telemetry back to the core — so one platform covers many locations.

Remote collectorsMutual-TLS enrolmentWAN forwardingMulti-site

Resilience & store-and-forward

When the link to the core drops, telemetry spools to durable disk and replays in order on reconnect. A layered watchdog suite — including a dead-man supervisor and peer corroboration — tells node-local trouble apart from a real outage.

Store-and-forwardOrdered replayWatchdog suiteNo data loss

In-platform deploy & self-update

Build once, gate, and roll every node from inside the platform. It detects when a newer build of itself is available, can apply it on its own, and reconciles environment changes across the cluster without a rebuild.

One-click rolloutSelf-updateENV reconcileDrift check

Custom dashboards

Assemble the exact view your team needs from a catalog of live panels — the metrics that matter to you, arranged your way.

Panel catalogLive dataYour layout
Correlation, not just collection

Turn raw signal into an answer

Every metric gets a self-updating baseline (an exponentially weighted moving average); the platform then flags readings that stray far from it — scored in standard deviations — with sensible floors for CPU, memory, disk, latency, and event rate. Log signatures catch known failure patterns, and everything correlates into incidents by shared entity and time.

Threshold & anomaly alerting

Device-down, high latency, packet loss, interface-down, high CPU/memory — plus statistical anomalies.

Incidents with context

Root cause, entity, severity escalation, impacted-device count, and auto-resolve.

Real-time everywhere

Live feed over Socket.IO; the NOC view updates the moment something changes.

Catches silence, too

A continuously-active source that suddenly goes quiet becomes an incident within about a minute — and auto-resolves when it resumes.

How the engine works
Anomaly · esxi-04anomaly
memory.used94% (baseline 61%)
deviationwell above baseline
correlated logvmkernel: OOM
actiongrouped into P3
Security Ops

Threats caught, not just logged

OverWatch correlates brute-force attempts, port scans, and anomalous east-west traffic from logs and session data, then shows the evidence behind each call. The policy engine enforces segmentation, egress allowlists, and privileged-access rules — keyless and self-learning, with no drift tolerated.

Walker-traced incidents

Every containment decision links back to the signal that triggered it — no black box.

Policy, enforced

Guest VLANs isolated, only gateway-role devices may NAT, MFA on console.

Silence watched

An expected telemetry feed that goes quiet is flagged as a potential gap.

OverWatch Security Ops — active threats, policy engine, and a Walker-traced brute-force
Secure by design

Enterprise access control, self-hosted trust

Your monitoring platform sees everything — so it's built to protect what it holds.

Strong authentication

Password login with lockout, TOTP MFA with recovery codes, WebAuthn passkeys, and enterprise SSO.

Granular RBAC

Custom roles and permission keys, plus service accounts and full session-activity audit.

Encrypted credentials

Device and integration secrets encrypted at rest with AES-256-GCM, keyed outside the data directory.

Config backups

Capture running configs and version them only when they change — a clean history of every device.

Firewall policy sync

Read and surface your firewall rulebase so policy is visible alongside the traffic it governs.

Threat map

Geolocate device IPs and session endpoints on a live world map to see where traffic is really going.

Edge mutual-TLS

Remote collectors authenticate with per-node mutual-TLS from an internal certificate authority, with live certificate issuance at enrolment.

Hardened proxies

Built-in proxies block server-side request forgery — loopback and cloud-metadata egress are refused on every request.

Ecosystem & scale

An integrations marketplace, built to grow

A modular catalog spans network, security, virtualization, storage, wireless, surveillance, and notification vendors — so coverage expands without waiting on a new release. Run it multi-tenant for MSP scale and cluster it for high availability.

Modules marketplace

Vendor coverage as installable modules across every major category.

Multi-tenant (Organizations)

Isolate clients and scope every device, event, and incident by tenant.

Clustered & self-hosted

Leader-elected polling, dynamic worker nodes, and HA on your own infrastructure.

Modules7 categories
NetworkCisco · Juniper · Arista
VirtualizationVMware · Nutanix · Hyper-V
StorageNetApp · Dell EMC · Pure
WirelessCisco · Aruba · Mist
NotificationsWebhook · Slack · Teams

Want the full tour?

We'll walk your team through live collection, the AIOps engine, topology, and Walker — on sample data, at your pace.