NOC & Control Monitor

See what is changing before it becomes an incident.

Many network problems develop gradually. Monitor makes states and changes visible over time and preserves the technical context for later analysis, from site and AP down to client, SSID, VLAN, RF, and infrastructure evidence.

Local context

A service can be healthy globally and still fail locally.

Checks can run in the context of a site, AP, SSID, or VLAN. This reveals whether DNS, DHCP, NTP, RADIUS, NAC, or cloud services work exactly where they are needed.

DNS / RADIUS

Local dependency

The RADIUS hostname cannot be resolved through the DNS resolver at one site.

GUEST WI-FI

Access expired

The SSID is active, but credentials, vouchers, or time-limited access are no longer valid.

CLOUD / ONBOARDING

Blocked by SSL inspection

New APs cannot reach the cloud because of certificate manipulation or firewall rules.

DHCP / LINK

Responding, but too slowly

Part of the site shows unusually long lease times or intermittent failures.

Monitor insight loop from collector and timeline to findings and the NOC view
Collector · samples · timeline · findings · NOC view · historical investigation

Historical context

What happened yesterday at 18:00?

The issue is gone today. Yesterday at 18:00 it was real. That is when the NOC needs more than a live snapshot and a guess.

  • How many clients were connected, and which AP was affected?
  • Were there CPU or memory spikes?
  • Were channel utilization, airtime, or other collected RF values unusually high?
  • Did RX/TX retries, error counters, or the noise floor increase?
  • Were there signs of poor coverage, distant clients, or CCI?
  • Were DHCP, DNS, RADIUS, NAC, or cloud services abnormal at the same time?
  • Did the switch port show a link, PoE, CRC, or duplex issue?
AP investigation with historical throughput and RF evidence
Historical AP and RF context instead of a live snapshot alone.

From site to radio

From the site overview down to the individual radio.

OK, warning, and critical states can be narrowed down to the site, building, AP, client, SSID, VLAN, radio, and switch port.

Throughput and RF trends with channel utilization and counters
RX, TX, total throughput, airtime, noise floor, retries, errors, and raw counters.
Clients on an access point with SSID, VLAN, RSSI, and SNR
Client, SSID, VLAN, band, RSSI, and SNR context for each access point.

AP and site context

From an access point to its neighbors.

AP health combines CPU, memory, uptime, PoE, link speed, duplex, and switch-port data. Building, peer, and neighbor context shows whether an anomaly originates at the AP, within the building, or in the local RF environment.

AP health with CPU, memory, uptime, PoE, and switch port
AP health: CPU, memory, uptime, PoE, link speed, duplex, and switch port.
Building, peer, access point, and neighbor context
Building, peer, and neighbor context for local and site-wide anomalies.

Structured handoff

Turn a finding into a traceable technical result.

Control structures status, scope, severity, and evidence for reporting and machine-readable handoff. A local ServiceNow outbox foundation is prepared, but automatic remote incident creation or updates are not currently available as a production feature.

Data provenance

Visibility without false precision.

Control shows the data source and collection time. Teams can distinguish between live values, stored samples, and signals that were not collected, allowing historical conclusions to be assessed with technical confidence.

Proactive operations

Detect change, understand the timeline, and act on evidence.