Sri Ranga Sentinel Logo

Sri Ranga Sentinel

Network Monitoring Platform
Connecting…
30

Topology Intelligence Command Center

All Sites · — · Last discovery never · 0 nodes · 0 edges
— Health
— Confidence
— Complete
Site Topology
Online Offline
Collector ZTNA VPN Hybrid Fabric Node
Link Legend
Map

No Topology Data

Enter an IP range and click Scan Network to discover your network.

Idle — ready to scan
0 nodes 0 edges
0
Critical
0
Warning
0
Info
0
Recovered
0
Total events
No topology events yet — discovery, link, and node changes will appear here in real time.

Dashboard Intelligence Command Center

Devices · Health · Alerts · Site Availability
Updated — ·
0
Total Devices
0
Online
0
Offline
0
Active Alerts
—
Network Health Score
—
Site Availability %
—
WAN Health Score
Tunnel-based
N/A
Alert SLA Compliance %no alerts yet
Gathering network status…
Bandwidth Timeline (Kbps)
Device Status
Protocol Distribution
Avg Health Score
Real-Time Network Operations
Live Alert Stream
No alerts
Active Incidents
DeviceSeverityDurationImpact
No active incidents
Network Events Feed derived
No recent events
Network Health Engine —
Healthy Devices
—
Score 80–100
Warning Devices
—
Score 50–79
Critical Devices
—
Score 0–49
Network Score
—
Overall / 100
Top 5 Unhealthy Devices
DeviceIPTypeScoreStatus
Run a scan to analyse health
Infrastructure Health Command Center
Health Breakdown
Health Trend
Device Risk Analysis
Capacity Forecast loading…
Traffic Intelligence Center
Top Bandwidth Consumers
DeviceSiteInboundOutbound
No traffic data
Network Utilization
Traffic Flow Insights
WAN Performance live
Device Health Overview
StatusDeviceIPTypeCPUMemoryLatencyHealth
No devices yet — run a scan
Site Operations Center
Site Health Ranking
#SiteAvailabilityHealthAlerts
No sites configured
Top 10 Critical Devices
DeviceHealthAlerts
No critical devices
Devices Requiring Attention
DeviceIssueValue
Nothing flagged
Top Alert Sources
DeviceCountSeverity
No alert sources

Alert Intelligence Command Center

Incidents · Correlation · Escalation · SLA
Updated — All clear
Total Active
0
— 0%
Critical
0
— 0%
Warning
0
— 0%
Informational
0
— 0%
Unacknowledged
0
— 0%
Escalated
0
— 0%
Resolved Today
0
— 0%
MTTR
—
— based on today
0 alerts
0/400

No alerts — all systems normal

Traffic Intelligence Command Center

Bandwidth · Flow Intelligence · WAN Performance · Anomalies
WebSocket connecting… Last refresh: — Data age: —
Loading traffic KPIs…
Bandwidth In / Out (Kbps)
Protocol Distribution
Top Talkers
RankHostIPBytes InBytes OutTotalUsage
No traffic data yet
Traffic Distribution — LAN / WAN / VPN / Internet
No traffic data yet
Top Interface Consumers
InterfaceDeviceUtilization
Loading…
Top Sites by Traffic
SiteTotal BandwidthActive Devices
Loading…
Device-to-Device Flows
SourceDestinationBandwidthSite
Loading…
Site-to-Site Flows
Source SiteDestination SiteTraffic Volume
Loading…
Flow Heat Map — Site × Site Traffic Intensity
Loading heat map…
WAN Link Utilization & Quality
LinkSiteUtilizationLatencyJitterPacket LossThroughputQuality ScoreStatus
Loading…
Traffic by Device Type
Traffic by Vendor
Traffic Growth Trend
Application Visibility
Business
—
Infrastructure
—
Unknown
—
ServiceBytesShare
Loading…
Classified from each flow's port against a well-known-service table — not packet-payload DPI, which this NetFlow-based pipeline never has access to.
Bandwidth Spikes
TimeBytesBaseline
No spikes detected
Sudden Drops
TimeBytesPrevious
No drops detected
Link Saturation
DeviceUtilization
No saturated links
High Utilization Devices
DeviceBytes
No devices exceeding thresholds
Traffic Outliers (same detector as the NetFlow anomaly panel above)
Source IPBytesZ-ScoreSeverity
No outliers detected
Traffic Operations
0 devices
DeviceSiteType VendorInboundOutbound TotalUtilization LatencyHealthStatus

Devices Intelligence Command Center

Inventory · Health · Discovery · Performance · Risk
— Online — Critical Updated —
Swipe for more metrics
Managed/Unmanaged is a proxy based on classification confidence (≥60% = Managed) until a dedicated backend flag exists. Trend sparklines build up from this browser session's live updates.
Device Inventory Center 0
Saved views:
No devices — run a scan first
Classic Inventory Table (legacy) — original table, unchanged
Device Health Snapshot
0
Healthy
0
Warning
0
Critical
0
Offline
Health trend window: Live session data only — historical rollups need a backend timeseries endpoint (framework only).
Device Discovery Snapshot
Newly Discovered
No new devices
Recently Changed
Change tracking (IP / MAC / vendor / site history) requires a backend change-log endpoint — not available yet. Framework only.
Unclassified Devices
None
Device Performance Center
Top CPU
Top Memory
Highest Latency
Most Traffic
Packet Loss
No packet-loss field in current device payload — framework only.
Most Alerts
Per-device alert counts need a backend join to Alerts — framework only.
Device Lifecycle Center
0
Active
0
Inactive
0
Recently Seen (24h)
0
Not Seen Recently
—
End-of-Life (framework)
—
Unsupported (framework)
EOL/Unsupported tracking needs a vendor EOL database join — framework only until that data source is connected.
Device Intelligence Center
Vendor Distribution
Device Type Distribution
OS Distribution
Site Distribution
Risk & Compliance Center
High Risk Devices
Requiring Attention
Flapping Devices
Needs status-change history from the backend — framework only.
Silent Devices

Reports Intelligence Command Center

Enterprise Reporting · Analytics · Compliance · Capacity Planning
Reporting Command Center
Executive Summary Center
Report Template Center
Report Builder
Scheduled Reporting Center
Reports generate and log to History automatically when due. Email/PDF delivery transport isn't wired to an SMTP provider yet — see schedule status.
ReportFrequencyFormatRecipientsLast RunDelivery
No scheduled reports
Report History Center
ReportFormatSitesRequested ByGenerated OnSizeStatus
No reports generated yet
Multi-Site Analytics
SiteAvailabilitySLADevicesRisk Score
No site data
Advanced Analytics Center
Alert Reporting Center
Top Alert Sources
SourceCount
No data
Most Frequent Alerts
MessageCount
No data
Alert Categories
Alert Activity (daily, last 90 days)
Compliance Reporting
Capacity Planning
Traffic Growth (bandwidth)
Loading…
Capacity Growth (storage)
Loading…
Enterprise Historical Reports Backed by PostgreSQL long-term storage
Download PDF:
Historical Metrics
SLA Status —
DeviceIPStatus Avg LatencySLA Met
Load report to see SLA data
0
Devices Found
—
Avg Health
—
Avg Latency
0
Total Alerts
Device Types
Vendors
OS Distribution
Subnet Calculator
Open Port Security Summary Flagged ports that may need attention
DeviceIPPortServiceRisk Level
Run a scan to analyse port security
Device Uptime Report
StatusDeviceIPTypeUptimeLast SeenLatency
No data — run a scan

Health Intelligence Command Center

Root Cause Analysis · Risk Assessment · Network Assurance
Last refresh: — Avg: —/100
Overall Network Health —
—
Healthy Devices
—
Score 80–100
Warning Devices
—
Score 50–79
Critical Devices
—
Score 0–49
Offline Devices
—
Unreachable
Average Health Score
—
Across active devices
Health Trend
—
This session
Health Stability Index
—
100 = perfectly stable
Uptime SLA (24h)
—
Approximate · this session
Overall Health Trend
Health Score Distribution
Device Type vs Health
Health by Device Type
Run a scan to see type breakdown
Root Cause Analysis Center
No unhealthy devices detected
Health by Site
SiteDevicesHealth ScoreAvailabilityCriticalRiskTrend
Run a scan to see site health
Highest Risk Devices
DeviceSiteStatusRisk Score
No risk data yet
Requires Immediate Action
Nothing needs immediate action 🎉
Trending Toward Critical Score fell since the last poll and is already below 80
Health Degradation Detection
Sudden Health Drops
None detected
Flapping Devices
None detected
Near Failure
None detected
Frequently Offline
None detected
Device Health Command Center
Health Score Device Site IP Vendor Type CPU Memory Latency Pkt Loss Uptime Risk Root Cause Trend
Run a scan to see health data
Health Heatmap
Run a scan to build the heatmap
Health Timeline
No state changes recorded yet this session
Executive Insights
Gathering insights…
Intelligent Device Profiles
DeviceIPVendor / LogoTypeSub-TypeConfidenceMAC OUIOS
Run a scan to see device profiles
Device
—
Loading…

Discovery Intelligence Command Center

Real-time asset discovery, coverage & rogue-device intelligence across all sites
Engine Active Sources Last Scan
Total Assets
0
New Today
0
Devices first seen today
Coverage
0%
— online / tracked
Rogue Devices
0
Unauthorized / unknown
Discovery Jobs
0
Running now
Sources Active
1 / 8
ARP · SNMP · LLDP · CDP…
Query Success Rate
100%
This session's discovery calls
Avg. Query Duration
—
/discovery/history latency
Discovery Coverage
0% ONLINE
Online: 0 Offline: 0 Unknown: 0
Discovery Sources
Discovery Timeline
Rogue Device Center
RiskDeviceIPMACVendorFirst SeenActions
Loading…
Device Classification
Discovery History — All Tracked Devices
Loading discovery history…
Discovery Jobs Monitor
Job NameTypeSiteStatusDurationDevices FoundProgress
Loading…
Discovery Analytics
Assets Discovered
New Devices Trend
Rogue Device Trend
Top Vendors
Risk Distribution
Query Duration (ms)
Discovery Insights
Export Center
Discovery History
New Devices
Rogue Devices
Coverage Report
Classic Discovery Log (original view)

Secure Connectivity Command Center

Unified control for every IPsec, WireGuard & OpenVPN connection — Sri Ranga Sentinel Hub

Checking connectivity backend…
Global Connectivity Map
Healthy Degraded Down
—Total Tunnels
—Healthy
—Degraded
—Down
—Avg Health Score
Provider Status
Loading provider status…
Dual-Backbone VPN Architecture — Sri Ranga Enterprises NMP
🔐
IPsec/IKEv2 Backbone
Site gateways between branch firewalls, HQ, cloud VPCs and datacenter edges. Managed via strongSwan swanctl/VICI running directly on this Ubuntu VM.
TRANSPORT BACKBONE
🌐
WireGuard Overlay
Monitoring agents, probes, edge mini-PCs and cloud probes. Managed via wg / wg-quick on this VM. Simple handshake age, bytes, and peer count.
MONITORING OVERLAY
🏢
NMP Monitoring Core
Sri Ranga NMP runs on this Ubuntu VM. Three collectors feed into a Tunnel Service that merges all state into one unified graph.
MONITORING CORE
⚙️
Control Plane
Tunnel Service + Polling Scheduler. Jobs run locally via swanctl, wg show dump, and Linux net tools (ping, dig, ip).
CONTROL PLANE
Unified Tunnel Graph
Three Collectors — Health
IPsec Collector
Polls strongSwan SAs via VICI or swanctl --list-sas. Cisco/Fortinet/Palo Alto via SNMP MIBs when reachable.
—Tunnels
—UP
—TX Total
—Backend
WireGuard Collector
Reads wg show <iface> dump on this VM. Per-peer: handshake age, bytes TX/RX. Maps to UP<120s / STALE / DOWN.
—Peers
—UP
—STALE
—Latest HS
Experience Collector
Runs ping, dig, MTU probe, jitter, TCP check via Linux net tools on this VM. Tunnel state alone is not enough.
—Tests
—Passing
—Avg Latency
—Packet Loss
All Tunnels — Unified View (IPsec + WireGuard)
TypeNameLocalRemoteStateTXRXHS / DPDVendor
Loading tunnels…
What do you want to connect?

Answer one question — Sentinel recommends the right protocol and pre-fills sensible defaults. Every advanced field is still available in Expert Mode below.

Internet Gateway Mode

Choose how much of a connected client's traffic crosses the tunnel. This is per-provider and can be changed any time without reconnecting existing tunnels.

—
Expert Mode — protocol-specific configuration
Tunnel Intelligence
Select a tunnel above to see its full intelligence profile.
Experience Collector — Synthetic Tests

Measures VPN tunnel quality by running tests FROM this Ubuntu VM TO the remote VPN gateway/peers: ping (latency + packet loss), DNS resolution, MTU discovery, jitter, and TCP reachability. Tests run through the VPN tunnel — results reflect actual tunnel performance, not just internet connectivity. Auto-detects targets from connected IPsec sites and WireGuard peers.

Test Output
— Run tests to see output —
Control Plane Services
Tunnel Service
Ingests IPsec SAs and WireGuard peers, normalises state (UP/STALE/DOWN/UNKNOWN), and builds a unified tunnel graph accessible via /vpn/tunnels.
Running — merged graph at /vpn/tunnels
Polling Scheduler
Distributes collection jobs. Local polls run on this VM directly. Remote site collectors are separate processes; schedule them via cron or systemd timers calling POST /vpn/ipsec/poll.
Active — jobs listed below
IPsec State Ingestor
Priority order: python-vici (direct VICI socket) → swanctl --list-sas → ipsec status. Normalises bytes, DPD, cipher, and phase 1/2 state from any of these sources.
Ready
WireGuard State Ingestor
Parses wg show <iface> dump tab-separated output. All WireGuard interfaces on the VM are polled automatically. Handshake age drives UP/STALE/DOWN state.
Ready
Polling Scheduler — Jobs
Loading jobs…
Sites
Loading sites…
Routing Policies
Loading policies…
High Availability Groups
No HA groups configured yet.
Zero Trust Network Access Implemented

Per-application resources, not subnets. Every access request is checked against an explicit rule and the requesting device's current posture score — default-deny, and authorization expires if a posture check goes stale (15 min).

Protected Resources
NameHostSensitivity
No resources yet
Access Rules
IdentityResourceMin. Posture
No rules yet
Test Access Decision
SD-WAN Dynamic Path Selection Implemented

Group multiple tunnels that reach the same site as alternate WAN paths. Each group is re-scored automatically every poll cycle against three profiles — default (highest Health Score), voice (lowest jitter/latency), and bulk_transfer (highest throughput) — using the same metrics the Tunnel Intelligence panel shows.

No SD-WAN path groups configured yet.
—Certs Valid
—Expiring Soon
—Expired
—PSK-Based Tunnels
Certificates & Encryption
TunnelProviderAuthenticationEncryptionCertificate StatusExpiry
Loading…
RBAC & Compliance

Role-based access control governs who can view, connect, disconnect, edit policy, administer HA, rotate credentials, and back up/restore Connectivity Manager configuration. Roles: super_admin, operator, readonly.

Audit Log
Loading audit log…
Interactive Hub-and-Spoke Topology
Healthy (≥80) Degraded (40–79) Critical (<40 / down)

Security Intelligence Command Center

Threat Detection · Vulnerability Management · Compliance · Incident Response
Connecting to Wazuh… Indexer — — protected Threat level — Last sync —
Security Posture Last 24 hours
—
Monitored Assets
—
Protected (Active)
—
Unprotected / Offline
—
Critical Alerts
—
High Severity Alerts
—
Active Vulnerabilities (Crit+High)
0
Open Incidents (local)
—
Security Health Score —
Connecting to Wazuh and gathering security posture…
Posture Index 5-factor
Loading…
Alert Volume by Severity Wazuh indexer
Loading…
Asset Risk Intelligence explained score
AssetStatusAlertsVulnsRisk
Loading…
Detection Pipeline Health manager + indexer
Loading…
Latest Critical & High Events
Loading…
Exposure at a Glance orbital
Loading…
Rule Level Spectrum Wazuh indexer
Loading…
Top Triggered Rules
Loading…
Noisiest Assets
Loading…
MITRE ATT&CK Matrix Wazuh MITRE module click a technique or tactic to filter the event feed
Loading…
Authentication & Brute-Force
Top attacking source IPs click to filter
Loading…
Most targeted accounts
Integrity, Malware & Response
File-integrity events by type
Most-changed paths
Malware / rootkit detections
Threat Intelligence Center heuristic · derived from alert text
Loading threat categories…
Attack Stage Overview heuristic mapping
Loading attack stages…
Security Operations Feed
TimeAssetSeverity RuleDescriptionSourceAction
Loading…
—
Vulnerability Command Center Wazuh Vulnerability Detection
—
—
—
—
CVSS Spectrum
Loading…
Exposure Age time since detection
Loading…
Most Vulnerable Packages
Loading…
Most Widespread CVEs click to filter
Loading…
Exposure by Asset click to filter
Loading…
Vulnerability Inventory
CVESeverityCVSSPackage VersionAssetDetected
Loading…
—
Sorted by CVSS score. EPSS, exploit availability and patch state are not provided by Wazuh 4.9, so they are intentionally not shown.
Configuration Assessment Wazuh SCA · CIS benchmarks
Loading…
Policies (lowest score first)
Regulatory Compliance PCI DSS · GDPR · HIPAA · NIST 800-53 · TSC
Loading…
Hardening by Asset select a row to see its failed checks
AssetPolicyScorePassFailN/A
Loading…
Security Hygiene Checklist
Loading…
Network Exposure listening services
Reads each agent's listening ports from Wazuh and flags risky services (Telnet, RDP, SMB, VNC, Redis, exposed databases…). Press Scan to run it.
Asset Risk Map 1 cell = 1 asset
Loading…
lowmedium highcriticalno data
Fleet Composition
Operating systems
Agent versions
Groups
Security Asset Explorer
IDNameIPStatus OSAgentRiskLast SeenNMP DeviceManage
Loading…
Use Manage to restart an agent, remove it from the Wazuh manager, or get the uninstall commands for the endpoint.
Threat Vector Radar MITRE tactics
Loading…
Posture Radar 5 factors
Loading…
Compliance Polar alerts per framework
Loading…
Signal Matrix weekday × hour · last 7 days
Loading…
quietbusy
Attack Flow source IP → technique → asset
Loading…
Rule Signal Traces top 5 rules over time
Loading…
Source Intelligence
Top source IPs
Loading…
Origin countries needs Wazuh GeoIP
Asset × Severity
Loading…
Detection Sources decoders
Loading…
Incident Management local tracker
AssetDescriptionSeverityStatusOpened
No incidents yet — promote an alert from the Security Operations Feed

Network Performance Command Center

Real-time throughput, latency & quality telemetry across all links

Idle Server Online Collectors Ready
Updated — Last 24 Hours Auto-refresh
Overall Network Score — —
WAN Health Score —
Active Tests —
Failed Tests —
SLA Compliance —
Sites Monitored —

Top Congested Links

No data for this window yet.

Top Latency Links

No data for this window yet.

Best Performing Site

No site data yet.

Worst Performing Site

No site data yet.

Test Outcomes

No tests in this window.

Alert Summary

No alerts.

Site Health Matrix

No site data yet.

Network Health Score

— Awaiting data
Throughput Score
—
Latency Score
—
Jitter Score
—
Loss Score
—
Availability Score
—
No samples in this window yet — run or schedule a test.

Health Score Trend

—

Score Drivers

No samples in this window yet.

Grade Distribution

No samples in this window yet.

SLA Profile — Voice

—

Monthly Compliance

—%
This calendar month, evaluated tests.

SLA Scorecard

—
No evaluated samples in this window.

Error Budget

%
No evaluated samples in this window.

Daily SLA Compliance

Recent SLA Violations

—
TimeTargetTypeMetricThreshold
No violations recorded.
Peak Throughput—
Average Throughput—
95th Percentile—
Growth Trend—
30-Day Forecast—
Headroom (vs Peak)—
Peak Utilization—
Samples—
Saturation Prediction—

Throughput Trend

—

Utilization vs Capacity

Enter a link capacity above to compute utilization and headroom.

Top Links by Load

TargetSamplesAvgP95PeakGrowth/day
No samples in this window.

Historical Trend

—

Time-of-Day Heatmap

avg by weekday × hour
Hover a cell for details.

Detected Anomalies

No anomalies detected.

Samples

—
TimeTargetSiteProtoMbpsLatencyJitterLossHealthMOSSLA
No samples in this window.
Quick targets

Path Visualization

—
Run a trace to draw the network path.

Hop-by-Hop Path Analysis

HopIPAvg LatencyBestWorstLoss %Δ vs PrevProfile
Run a traceroute to populate hop analysis.

Run History & Route Changes

—
WhenTargetExecuted onMethodHopsEnd-to-EndRoute
No previous runs recorded.

Alerts — Last 24 Hours

No alerts.

Top Alert Types

No alerts.

Enterprise Alert Feed

—
No alerts yet.

Site Ranking & Regional Comparison

RankSiteHealthAvg Mbps Avg LatencyLoss %Failure %Tests
No multi-site data for this window.
Chart metric

Live Test Telemetry

— Mbps
Throughput
— ms
Jitter
— %
Packet Loss
—
Retransmits
—
SLA Status
Derived
— / 100
Quality Score
Throughput Timeline LIVE
No tests run yet.

Test Path

Client
Switch
Router
Firewall
Target

Event Timeline

No events yet — run a test to populate the log

Configuration Management Command Center

Backup · Version Control · Compliance · Change Intelligence
Updated —
—
Protected Devices
—
Config Coverage
—
Successful Backups
—
Failed Backups
—
Unauthorized Changes
—
Missing Backup
—
Avg. Backup Age
—
Storage Consumed
Compliance Score
—
Backed up, no failures, no stale (>24h) configs
Device Status Distribution
No device data yet
Backups by Vendor
No device data yet
Scheduled Config Backup
Last run: —  ·  Next: —
Next run in —
—
Healthy Devices
—
Stale Backups (>24h)
—
Missing Backup
—
Unauthorized Changes
—
Compliance Score
Compliance Heatmap
Healthy Warning Critical
No devices to display
Device Configuration Inventory
0 devices
StatusHostnameIPVendor Last BackupConfig SizeChangesActions
No devices — run a scan first
Select Device
Version Stats — No device selected
—
Total Versions
—
With Changes
Version Timeline
Select a device to view its version history
—
Critical Changes
—
High Impact
—
Medium / Low
—
Changes (7 days)
Change Detection Timeline
No changes detected in the selected window
Compare Versions
Diff Summary
Select versions and compute diff
Unified Diff
Diff output will appear here
1
Select Device
2
Select Version
3
Preview & Compare
4
Rollback
Device & Target Version
Risk & Validation
Select a device and version to see the rollback plan
Rollback Plan Preview
No rollback plan generated yet
Applies the selected version over SSH, then immediately re-reads the device to confirm what actually took effect. A fresh "before" backup is taken automatically first, so this action itself is always reversible from Version Explorer.
Loading policies…
Global Safety-Net Schedule
Last Run
—
Next Run
—
Every device still gets backed up on this global interval regardless of policy assignment — policies above only add extra, more frequent backups on top of it.
Store Device Credentials
"Generic SSH" sends show running-config by default, which is a network-CLI command and won't work on a Linux host — set the exact command to run instead (e.g. a specific config file to track). The account needs read access without an interactive sudo prompt.
Credential Vault
0 stored
DeviceVendorPortSecurity
No credentials stored yet
Credentials encrypted with Fernet AES-256. Key stored only in .env. Never logged.
—
Total Backups Stored
—
Storage Consumed
—
Most Recent Backup
—
Oldest Visible Backup
Storage by Vendor
No backup data yet
About This View
Figures reflect the latest known backup per device from live status data. Historical storage-growth trending (day-over-day) requires a periodic snapshot job on the backend and is not yet collected — this view shows a real-time snapshot rather than a trend line.
Activity Timeline
Live activity (this session) and recent changes will appear here as they occur.

Syslog Intelligence Command Center

Log Ingestion · Correlation · Security Events · Site-Aware Analytics
Updated — EPS — Log Health —
Syslog listener starting…
Queue: — Port UDP: 5514
Executive KPI Center
—
Total Events (7d)
—
Events / sec (live window)
—
Critical Events (24h)
—
Error Events (24h)
—
Warning Events (24h)
—
Security Events (loaded window)
—
Active Sources (7d)
—
Correlated Alerts (this session)
—
Last 1 Hour
—
Last 24 Hours
N/A
Log Volume needs backend
N/A
Storage Usage needs backend
Gathering log intelligence…
Advanced Search Engine
Try: / search · p pause · r refresh · f fullscreen
Time Severity Site Source IP Host Facility Program Category Message Risk Correlation
Interesting Fields
Loading…
Pinned Events
No pinned events. Click the icon on any row to pin it here.
24h by Severity
Loading…
Top Sources (1h)
IP Host Count
Loading…
Correlation Rules
Link Down
Auth Failure (3/60s)
Config Changed
VPN Tunnel Down
Firewall Deny Spike (20/60s)
Port Scan (3/30s)
Disk Full
Kernel Panic
Device Setup
Linux (rsyslog):
*.* @<NMP-IP>:5514

Cisco IOS:
logging host <NMP-IP> transport udp port 5514

Fortinet FortiGate:
config log syslogd
 set server <NMP-IP>
 set port 5514
end
Retention & Log Quality
—Unmatched-Device Rate
—Daily Volume (24h)
N/ARetention Days needs backend
N/AParse Success Rate needs backend
Event Analytics Center
Events Over Time live window
Severity Distribution (24h)
Facility Distribution
Top Programs
Event Correlation & Security Center
Correlated Incidents this session
No correlated incidents yet this session.
Security Event Classification loaded window
CategoryCountHighest Severity
No data yet
Top Talkers Center
Top Devices
DeviceCount
Loading…
Top Programs
ProgramCount
Loading…
Top Facilities
FacilityCount
Loading…
Top Sites
SiteCount
Loading…
Risk Scoring Engine heuristic
Highest Risk Devices
DeviceRisk
No data yet
Highest Risk Sites
SiteRisk
No data yet
Highest Risk Sources
Source IPRisk
No data yet
Log Timeline
No significant events in range.

Multisite Intelligence Command Center

Sites · Collectors · Device Availability · WAN & Alerts
Updated — 0 sites
—
Sites
—
Collectors Online
—
Collectors Offline
—
Total Collectors
Collector Heartbeats — Live Updated every 30s · Green = last heartbeat <70s
No collectors registered yet
—
Total Sites
—
Healthy Sites
—
Degraded Sites
—
Offline / Critical Sites
—
Collectors Online
—
Protected Devices
—
Active Alerts
—
Global Site Health Score
Gathering multi-site status…
Site Health Matrix 0
SiteHealthDevicesCollectors AlertsStatusSLA (24h)
Loading site health…
Site Cards
Loading sites…
Multi-Site Incident Feed live · derived
SiteSeverityMessageTime
No active incidents
Smart Insights heuristic
Gathering insights…
WAN Intelligence & Geographic Distribution live · hub-and-spoke
This shows this central server's link quality to each site (hub-and-spoke), not a full site-to-site mesh — collectors only ever talk to this server, never to each other directly. Server-probed rows come from this server pinging a reachable collector directly (e.g. over site-to-site VPN); collector-reported rows come from the collector agent's own measured round-trip once its agent is updated to send it. A row with no data yet just means neither source has produced a sample for that site.
SiteSourceLatencyJitterPacket LossStatus
Loading WAN link data…
Site Map
Every Site
Loading…
All Registered Collectors
Status Hostname IP Address Site Version Last Heartbeat Devices Capabilities Actions
Loading collectors…
Recent Collector Events (WebSocket)
— Waiting for collector events —
HQ Site
Pick which site is Headquarters. The HQ site gets admin privileges (it cannot be deleted). Devices from an unassigned scan land in a regular site named "Scanned" — they are HQ only if you make "Scanned" the HQ site below.
Current HQ: —
Create / Edit Site
"My Current Location" needs you at the site; "Auto-detect from Collector" works remotely but is approximate over IP
All Sites 0
Name ID Subnet Location Description Actions
Loading sites…
Register New Collector
What happens next?
Registering creates a collector record and generates a one-time API key. Copy and store it securely — it is shown once only.
1 Registration creates the record in PostgreSQL and returns the API key
2 Download the collector.env file from the API key dialog
3 Deploy collector/agent.py on the remote site VM
4 The agent sends heartbeats every 60s and appears green here when active
Collector Agent — Complete Installation Guide Ubuntu 22.04+ / Debian 12+
1
Register the collector on the central server
Go to the Register Collector tab, select the site, enter a hostname, then click Register. Copy the API key — it will not be shown again.
2
Install dependencies on the remote VM
sudo apt update
sudo apt install -y python3 python3-pip python3-venv nmap arp-scan git
sudo mkdir -p /opt/srn-collector
sudo useradd -r -s /bin/false srnagent
sudo chown srnagent:srnagent /opt/srn-collector
3
Deploy the collector agent files
# Copy from central server or clone your repo
scp -r srn_multisite/collector/ srnagent@REMOTE_VM:/opt/srn-collector/
scp -r srn_multisite/shared/    srnagent@REMOTE_VM:/opt/srn-collector/

# Create Python virtual environment
cd /opt/srn-collector
python3 -m venv venv
./venv/bin/pip install requests pysnmp nmap
4
Configure the collector.env file
cp /opt/srn-collector/collector.env.template /opt/srn-collector/collector.env
nano /opt/srn-collector/collector.env

# Fill in these required values:
SRN_CENTRAL_URL=https://your-srn-server.example.com
SRN_COLLECTOR_KEY=<key from registration step>
SRN_COLLECTOR_ID=<UUID from registration>
SRN_SITE_ID=<site UUID>
SRN_SCAN_RANGE=192.168.10.0/24
5
Grant sudo for nmap and arp-scan (no password)
sudo bash -c 'cat > /etc/sudoers.d/srn-collector << EOF
srnagent ALL=(ALL) NOPASSWD: /usr/bin/nmap, /usr/sbin/arp-scan, /usr/bin/arp
EOF'
sudo chmod 440 /etc/sudoers.d/srn-collector
6
Install as a systemd service
sudo cp /opt/srn-collector/srn-collector.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable srn-collector
sudo systemctl start srn-collector

# Verify it's running
sudo systemctl status srn-collector
journalctl -u srn-collector -f
7
Verify on central server
Within 60 seconds the collector will send its first heartbeat. Switch to the Collectors tab — the status dot turns green and the heartbeat indicator shows OK. Discovered devices appear on the Topology map tagged with the site name.
Firewall / Network Requirements
Collector VM → Central Server:
    TCP 443 (HTTPS) or TCP 5000 (HTTP)   — API uploads

Central Server → Collector VM (not required — push-only):
    No inbound ports needed on collector

Devices → Collector VM:
    UDP 5514  — Syslog
    UDP 1620  — SNMP Traps

Secure Access Fabric

ZTNA · VPN · SD-WAN · Agent Fabric — connection visibility & trust
Updated — 0 agents
—
Agents
—
Online
—
ZTNA Connectors
—
VPN Clients
—
Published Resources
—
Active Sessions
Loading agents…
ResourceTypeHost:PortPublishing AgentSite SensitivitySessionsStatus
Loading…
No VPN-mode agents yet.
Recent Failover Events
TimeGroupSiteFrom → ToReasonDetectSwitchPolicy
Loading…
Loading device posture…
AgentSerialStatusIssuedExpiresDays LeftRenewal
Loading…
TimeActorActionTargetSiteResult
Loading…