Highlights
This release widens what octoja can watch and makes big lists easier to live with. You can now monitor whole classes of equipment without installing an agent — network switches, routers and firewalls, VMware hosts, even FRITZ!Box gateways — and a broad wave of new checks covers databases, printers, backups, disks, network services and more. A new full-screen TV View puts your fleet's warnings, critical issues and offline servers on one board, while the device list gains bulk actions, optional columns and the same controls now shared by every list in the product. The rest is polish and reliability — steadier remote desktop, calmer inventory history, and a long tail of check-accuracy fixes.
New
- Monitor network devices without an agent — You can now add and monitor network devices — switches, routers, firewalls, printers and other agentless equipment — without installing an agent; a designated agent monitors them on your behalf. Each device offers SSH, SNMP and an experimental Web Console (open the device's web admin interface securely tunnelled through its monitoring agent) from its hover card and the command menu, shows its IP in device lists, and can be isolated with a new Network device-type filter on the dashboard.
- Manage VMware ESXi and vCenter — You can now add VMware ESXi hosts and vCenter servers as agentless devices and manage them from octoja: live host CPU, memory and performance metrics, virtual-machine inventory, datastores, and power control to start or stop VMs. A Test connection button lets you verify host access before saving.
- Monitor FRITZ!Box-class internet gateways without SNMP — octoja can now inventory FRITZ!Box-style internet gateways over TR-064 when SNMP isn't available, pulling device details directly from the gateway. The add/edit network-device form gains Test connection buttons for both SNMP and TR-064 so you can confirm access before saving.
- New TV View for live fleet status — The new TV View puts your fleet's active warnings, critical issues and offline servers on a full-screen board — colour-coded tiles above a sortable, filterable table whose rows link straight to the device. New issues flash briefly as they arrive and can play a configurable alert sound when a critical issue appears or a server goes offline, and the list scrolls while the header, tiles and pagination stay pinned. It auto-refreshes and is gated behind its own permission.
- New database monitoring checks — You can now monitor your database servers. Microsoft SQL Server gets a Health check (service and connectivity, database status, backup age, disk space, failed Agent jobs, Always On) and an Activity check (blocking sessions and severe error-log entries), while PostgreSQL and MySQL/MariaDB each get a health check (reachability, response time, active sessions, size/uptime) plus a check that runs your own read-only query and alerts on its row count or run time. Query checks run read-only, so they can never change your data.
- New printer monitoring checks — You can now monitor printers three ways: a network-printer check over SNMP (v2c and v3) reports status, remaining toner and consumable levels and the lifetime printed-page count; a local-printer check watches Windows-installed printers for error states (out of paper or toner, jams, offline, service required); and a print-queue check for print servers alerts on offline printers, errored or blocked jobs, or a backed-up queue.
- New disk and storage monitoring checks — Several new checks watch disks and storage. Disk Presence tracks the physical disks in a device and alerts when one is removed, reporting serial and model (external/USB drives ignored by default). Others verify BitLocker encryption on fixed drives, flag a volume scheduled for a chkdsk repair at next boot, measure disk fragmentation (SSDs excluded), watch free space on folder-mounted volumes that ordinary disk checks overlook, and report Windows Storage Spaces pool and virtual-disk health.
- New backup monitoring checks — New checks keep an eye on backups. A Xopero ONE check watches the Backup & Recovery Agent on Windows, Linux and macOS, flagging failed or overdue backups and naming the affected plan; two TERRA CLOUD checks cover backup job status (result, age, error/warning counts, ransomware-detection state) and satellite replication health; and a shadow-copy writer check flags problems with the Windows Volume Shadow Copy writers backups rely on — an early warning of backup failures.
- New network and internet service checks — A family of new checks watches network services by connecting to them and alerting when one is unreachable, times out or responds incorrectly: SMTP, IMAP and POP3 mail servers, FTP and SSH servers, and a TCP port check for any host and port. A DNS check resolves hostnames and alerts on failures, slow lookups or unexpected addresses, and a domain-expiry check warns before a domain registration lapses. Most are cross-platform and let you require a specific response banner.
- New Windows Server infrastructure checks — New checks cover Windows Server roles: DFS Replication backlog between two members, DHCP scope utilization (how full each address pool is), WSUS health (last sync result and age plus managed-computer compliance — how many have update errors, still need updates, or have stopped reporting), and network-adapter team health (degraded or down teams, with active member count).
- New Windows system and activity checks — New checks report on day-to-day system state: system uptime (cross-platform, to catch missed reboots), whether a machine is waiting for a reboot and why, named Task Scheduler tasks that failed or were disabled, the health of the Windows Update agent itself, active and disconnected terminal/RDP sessions, and who is interactively logged on (with modes to warn when someone is or isn't present).
- New custom and advanced metric checks — For monitoring beyond the built-in checks, you can now run a read-only WMI query, sample any Windows performance counter, watch a specific process's CPU usage across all cores, count files in a folder (too many for a stuck spool, too few for missing output), check whether specific files or folders are present or absent, and monitor Microsoft Message Queue depth — each alerting on your own thresholds.
- New security monitoring checks — Two new Windows checks help you spot attacks and misconfiguration: a failed-logon check counts failed sign-in attempts over a window you choose and alerts when the volume looks like a brute-force attempt, and an AppLocker check counts blocked-application events (optionally including audit-mode) so you notice when software is being blocked or policies are wrong.
- New change-detection monitoring checks — New stateful checks alert you when something you're watching changes: the contents of files or folders, Windows registry values (useful for autorun and security-policy keys), or file/folder access permissions on Windows and Unix. Each offers an “accept current” option to acknowledge an expected change and reset the baseline, so you're only alerted on the next one.
- Lenovo hardware warranty monitoring — You can now monitor Lenovo hardware warranty expiry. A new check reads the device's serial number, looks up the warranty end date and warns you a configurable number of days before it expires. It uses the latest end date across base, extended and contract coverage, so purchased extensions are not reported as already expired, and warranty dates delivered in different formats now render correctly.
- Bulk actions on the device list — Turn on Multiselect from the device list's menu to pick several devices at once, then assign them all to a customer or assign tags in a single action from a floating selection bar. Devices you aren't allowed to edit can't be selected.
- See and undo per-device check overrides in config packages — The Checks tab of a config package now flags how many devices have drifted from the package with an overrides badge on each check. Open it to see which devices changed a check — disabled it, or overrode its inputs or alert thresholds — compare their settings against the package, and pull a single device or every drifted device back to the package config in one step.
- Change service startup type from the Services tab — On a device's live Services tab you can now change a service's startup type between Automatic, Manual and Disabled, alongside starting and stopping it. Available on Windows devices when you have permission to control services.
- Read-only access to the customers area — You can now give technicians read-only access to the customers area with a new view permission, separate from the permission to create or edit customers. Previously the whole area required manage access, so technicians without it saw nothing; on upgrade, existing users who could manage customers keep their access automatically.
- Let users postpone a patch restart — When installing patches needs a reboot, the person signed in to the device can now be prompted to delay the restart a limited number of times before it goes ahead. You set how many times they can defer and how long each delay lasts per patch-policy ring, and the countdown survives a routine agent restart. Off by default.
- Lock down the Windows Update interface from a patch policy — A new patch-policy option lets you disable the Windows Update interface on managed Windows devices. When turned on, the Windows Update settings page is hidden and manual scans and installs are blocked, so users can't patch outside your policy; it applies only while the policy owns the maintenance window and reverts automatically afterward.
- Ready-made templates for patch policies and automations — Creating a patch policy or an automation is faster with built-in starter templates. Pick from ten curated patch policies (staged rollouts, rapid deployment, compliance, servers) or thirty automation templates (device onboarding, scheduled maintenance, software hygiene) and clone one as your starting point instead of building from scratch.
- New "Ensure Lywand agent" automation action — You can add an “Ensure Lywand agent” step to an automation that checks whether the Lywand security agent is installed on a Windows device and silently installs it if it's missing, using the customer's matched Lywand license. If the install fails, the run records the underlying installer error so you can see why.
- New automation step: add or remove a tag — Automations can now add or remove a tag on a device as part of a run. A condition on the step decides whether to add or remove, so one automation can tag the devices that match a rule and untag the ones that don't. Only tags you manage are touched, not ones derived automatically from inventory.
Improved
- Consistent, more capable lists across octoja — Every list in octoja — devices, Cases, patches, customers, reports, admin and the device-detail tabs — now shares the same controls: resize, reorder and hide columns, search from the toolbar, and export the full list (not just the current page) to CSV. Many lists can also switch to a card view, and the device-detail Tracked Time, Updates and Cases tables are now searchable.
- Choose which columns to show in the device list, and page size — The device list now offers roughly 30 additional optional columns — manufacturer, model, serial, device type, CPU, RAM, storage, domain, OS build, uptime, IP addresses, agent version, tags, dates and more — that you can show or hide from the column menu. A new page-size selector lets you view 25, 50, 100, 250 or 500 devices per page.
- New device-targeting fields in the rule builder — You can now target devices in rules by chassis type, whether they have a battery (laptops vs desktops), directory membership (Workgroup, Domain, Azure AD, Hybrid), serial number, agent version and OS architecture. These fields work everywhere rules apply, including config packages, tag rules, patch policies, automations and device group access.
- Device aliases shown everywhere — Device aliases now appear everywhere a device is named — check alert emails, push and Teams notifications, reports, Cases, time entries, dashboards and device pickers — not just the main device and inventory lists. Lists sort by the displayed name where possible, and automations can reference the alias with a new deviceAlias token while the device-name token still resolves to the real hostname.
- Audit log now covers admin changes across the platform — The admin audit log records much more than before. Changes to branding, config and custom packages, custom checks, automations, users, customers and patch policies are now logged, each entry showing which item was changed.
- More control and detail in webhooks — In a webhook's settings you can again pick which events it delivers from a simple checklist, and you can leave inventory updates unselected to create a webhook that carries only monitoring-check alerts. Check-alert messages (failed, warning and recovered) now also include the device name and the customer's name, ID and external reference, so you no longer have to cross-reference a separate inventory message to see which customer an alert belongs to.
- Securepoint and ESET antivirus checks now run on the device — The Securepoint Antivirus Pro and ESET checks now run directly on each Windows device through the product's local interface instead of pulling status from a vendor cloud portal. Monitoring is more reliable and no longer needs the Securepoint or ESET PROTECT integration connected in admin settings — both integration cards have been removed and your existing checks keep working automatically.
- RAID check names the failed disk — The RAID check now lists the individual disks in an array and names the exact disk that has failed or degraded, across ZFS pools, Linux software RAID and Windows Storage Spaces. Degraded arrays are detected reliably on more Linux distributions, and a disk logging errors while the pool still reads healthy is now flagged as a warning.
- Firewall check adds Securepoint and Check Point — The firewall monitoring check now covers Securepoint UTM and Check Point appliances alongside the existing vendors. It reports firmware and update state, license expiry, VPN tunnels, cluster and failover status, and CPU and memory usage, plus disk usage on Check Point.
- Exclude specific event IDs in the Event Log check — The Event Log check can now exclude individual event IDs, optionally only for a specific source, so you can silence known-noisy events without switching off the whole check. It also reports when it cannot read the event log instead of failing silently.
- Full check output always visible — Large check outputs are no longer hidden behind a “truncated” banner. The full latest result is now always shown at full size, while only the stored history is trimmed. Updating the agent is required for this to take effect.
- Clearer Last Seen vs Last Inventory columns — The device list's “Last Reported” column is now labelled “Last Inventory”, and both it and “Last Seen” have tooltips explaining the difference: Last Seen is the most recent contact of any kind and drives online/offline status, while Last Inventory is the last full hardware and software inventory upload, which can lag behind.
- Cleaner device inventory history for changed services — When a Windows service changes its configuration (for example its startup type), a device's inventory history now shows a single “changed” entry instead of a confusing pair of “removed” and “added” lines.
- Resolving a vulnerability no longer freezes the app — When you resolve a vulnerability finding on a device, the app no longer locks up while the fix runs. The dialog now closes immediately and a notification reports success or failure when the device finishes, instead of dimming the whole screen for up to several minutes.
- Edit report-schedule recipients inline — Adding and editing recipients on a scheduled report now happens directly in cards on the schedule page instead of a separate popup. Each card lets you pick a customer, site and email addresses, and a single Save persists the whole schedule. A note clarifies that recipients are set per customer.
- Warning before leaving a page with unsaved changes — octoja now prompts you before you navigate away or close the tab with unsaved edits open. It covers the customer, user, group, patch policy, report template, report schedule, custom check, config package, tag rule and automation editing pages, so you no longer lose work by clicking away by accident.
- Open any list row in a new tab — You can now middle-click or Ctrl/Cmd-click a row in any list to open it in a new browser tab, exactly like a normal link. Left-click still opens it in place.
- See the full customer or site name in the dashboard tree — Long customer and site names in the dashboard tree were cut off with no way to read them. Hovering or focusing a row now shows the full name in a tooltip.
- Confirm before uninstalling software from a device — Uninstalling a package from a device's software list now asks you to confirm first, guarding against an accidental removal.
- Software Kiosk toggle when creating deployments — You can now set “Show in Software Kiosk” while creating a software deployment, not only when editing one, and deployment rows now show a badge indicating which packages are visible in the kiosk.
- Automations can update all outdated software at once — Software-installation automations gained an “update all outdated” mode that upgrades every outdated package a device reports, instead of naming a specific package. In this mode the form hides the version and package-name fields.
- Clearer DocBee connection-test errors — When a DocBee integration connection test fails during setup, octoja now shows the failure in a clear alert with a hint to double-check the base URL — it usually needs to end with /restApi and the casing must match exactly.
- Faster file downloads in deployments and scripts — Software deployments, custom checks and installer scripts that download files complete noticeably faster on Windows.
Fixed
- Devices no longer disappear after their customer is deleted — A device that reconnected after its assigned customer had been deleted could vanish from every view and stay hidden permanently. These devices now stay visible and can be reassigned, and any already-affected devices are restored automatically.
- Remote desktop recovers cleanly when a user logs off — If the signed-in user logs off, the device restarts, or the remote session disconnects during an active remote-desktop session, the viewer no longer freezes on the last frame. It now shows a clear “the remote session ended” message and returns you to the session chooser so you can reconnect to the login screen or another session.
- On-device prompts and indicators follow screen changes — After a screen-resolution change, the octoja agent's notifications, consent prompts and the remote-desktop session indicator now appear in the correct place on screen instead of floating mid-screen. Open overlays also reposition immediately when the resolution changes during a session.
- macOS agent interface no longer stuck in a restart loop after an update — On macOS, the octoja agent's on-device interface could get caught in a restart loop after an update. The agent now repairs itself before launching the interface, so it opens normally.
- Pending updates no longer flicker away on a scan hiccup — The Updates tab on a device no longer briefly empties or shows every pending update as removed when an update scan hits a temporary error. The previously known list is kept until a scan genuinely completes.
- Dashboard check-type and severity filters now match per check — When you filter the dashboard by a specific check type together with a severity, the severity now applies to that check's own result. Previously, combining an “online” check filter with “Critical” also returned devices whose online check was fine but that had some unrelated check in a critical state.
- Device Checks badge ignores disabled checks — The warning and error count badges on a device's Checks tab now ignore disabled checks, so they reflect only the checks that are actually running.
- SMART check recovers immediately after a disk is removed — Fixed the SMART disk-health check staying red for up to three days after you removed or decommissioned a disk, which had hidden the health of the remaining disks. Disk-removal detection now lives in its own check, so SMART recovers as soon as the surviving disks are healthy.
- Veeam backup check no longer fails on healthy machines — The Veeam Backup Agent check no longer reports a failure on machines whose backups are actually fine. Previously it could stop early and show an error instead of the real backup status; it now finishes and reports the correct result even when a single event-log entry can't be read.
- HP iLO check stops false-alarming on servers with empty bays — The HP iLO hardware check no longer raises a permanent warning on HP ProLiant servers that have empty fan or power-supply bays. Empty bays are now hidden and ignored, while genuine fan, power, memory, drive and temperature faults still alert.
- MailStore SPE user-count check now works — The MailStore Service Provider Edition (SPE) check used to fail every time instead of returning results. It now runs correctly and reports how many users are in each MailStore instance.
- Accurate example payloads in webhook help — The webhook help dialog now shows correct example payloads for every event that carries data — inventory updates and all check alerts — including the new device and customer fields. Previously the check-alert examples were the wrong shape and only the inventory example ever appeared.
- Links to ticketing systems and notifications respect your custom domain — Device, object and remote-support links that octoja passes to connected ticketing systems and notifications now use your configured custom domain instead of falling back to an octoja.cloud address. Previously customers on a custom domain received links pointing at the wrong domain.
- Clearer empty alert channel targets — When editing an alert's notification channels, a target you haven't picked yet now shows a readable “select a channel” prompt instead of a meaningless string of zeros.
- Automation and schedule configuration polish — Cleaned up the automation and schedule configuration screens. The schedule-override popup no longer runs off the edge in narrow panels, human-readable schedule descriptions now appear in your language on every page, the options for linking an existing automation are fully translated in German, French and Dutch, and a step you haven't renamed no longer shows its type label twice.