NGINXwatch

Self-hosted edition

Troubleshooting

Start with the server's log — almost every problem names itself there:

sudo journalctl -u nginx-monitor -n 100

The browser can't reach the server. Check the service is running (systemctl status nginx-monitor) and the port is open (firewall-cmd --list-ports should include 3030/tcp).

Sign-in succeeds but the next page asks to sign in again. Behind a reverse proxy over HTTPS, the proxy must send X-Forwarded-Proto: https. Without it the server can't mark the session cookie secure and the browser drops it.

502 Bad Gateway through your reverse proxy. On SELinux systems the web server may not connect out until you run sudo setsebool -P httpd_can_network_connect 1. Denials show in sudo ausearch -m avc -ts recent.

"License server unreachable". The server needs outbound HTTPS to devapex.cinnamonsservices.com. From the server, curl -sI https://devapex.cinnamonsservices.com/license/health should answer 200. Going out through an HTTP proxy is not supported yet.

"This license key is already in use". The key is active on another installation. Stop or remove NGINXwatch there first, then try again.

An agent doesn't appear. On the nginx server, run sudo journalctl -u nginx-agent -n 50. "connection refused" or a timeout means the server URL or a firewall is wrong; an authentication error means the token or secret doesn't match the one on the dashboard's Agents page.

Diagnostics

NGINXwatch keeps a structured event log for 30 days under its logs folder (diag/events-YYYY-MM-DD.jsonl): errors, warnings, failed requests and errors your users' browsers hit, each tagged with a reference such as 7F3K2QXA that also appears in the error message on screen. Passwords, keys and tokens are removed before anything is written.

When you open a support ticket from the app, Attach diagnostics (ticked by default) sends the last 7 days of that log with the ticket. Admins can also use Download diagnostics on the Support page to see exactly what is sent, or to email it to us. We delete attached diagnostics 90 days after the ticket closes.

Still stuck? Paid plans can open a ticket from inside the app (Support in the menu); it reaches our team with your product and license details attached. Everyone else: write to us through cinnamonsservices.com.