NGINXwatch

Hosted edition

Agents and Enrollment

The NginxWatch agent is a small program you install on each server running Nginx. It connects outbound to NginxWatch over HTTPS — no inbound firewall rules needed.

How enrollment works

Each agent needs two things to talk to your account:

  1. The shared agent token — proves the caller is a legitimate NginxWatch agent build (comes with the agent install).
  2. A one-time enrollment token — proves which organization the agent belongs to. Generate one from Agents → Enroll New Agent in the dashboard. It's shown to you exactly once, is tied to your account, and is consumed the first time an agent successfully registers with it — after that, the agent stays linked to your account permanently (you don't need to re-enroll on every restart).

Installing the agent

  1. Download the agent binary for your platform.
  2. Set its config: the stub_status URL for the Nginx instance to monitor, the path to nginx.conf (needed for the config-test/reload commands), and the enrollment token from step above.
  3. Start the agent. On first successful contact it registers, and its server appears in your dashboard.

What the agent reports

  • A heartbeat, so NginxWatch knows it's alive
  • Periodic stub_status snapshots (active connections, reading/writing/waiting, request counters)
  • Results of any lifecycle command you trigger from the dashboard (reload, config test, restart, status)
  • Tailed access/error log lines used for response-time sampling

If an agent goes offline

The server's status flips to offline after the agent misses its expected heartbeat window. Nothing is lost — history up to that point is retained, and the server picks back up automatically once the agent reconnects.

Next: Lifecycle Commands