এই সফটওয়্যারের লাইসেন্স রিনিউ করা হয়নি, তাই ড্যাশবোর্ডের কোনো তথ্য এখন দেখা যাচ্ছে না।
লাইসেন্স রিনিউ করার জন্য দয়া করে সফটওয়্যার প্রোভাইডারের সাথে যোগাযোগ করুন।
⚠️ লাইসেন্সের মেয়াদ শেষ হয়ে গেছে — দয়া করে রিনিউ করুন।
SS
Aurevyn247 IT COMMAND CENTER
Always-on intelligent visibility & vigilance
--:--:--
🔑 Change PasswordLogout
Monitoring
PC Health
Tickets
Data Protection
Reports
Add Device
Network Scan
Network Health
Risk Alerts
Activity Monitor
Wi-Fi Activity
Live Screens Wall
Bulk Recording
Recordings
Network Designer
Trigger Words
Admin
Office-Time Policy
USB Device Control
Data Channel Control
VPN Control
App & Transfer Control
Unit Management
User Management
Server Backup
Server Settings
Sensitive · Targeted
Clipboard Monitoring
Screen Recording + OCR
Units
Device Category
Notification Channels
Devices Online
--
out of total devices
Down / Offline
--
Needs attention now
Warning
--
Unstable connection / reboot loop
Uptime Rate
--
Percentage of devices currently online
Top Applications Used for
Top Alerts for
Device List — Live Status
All
On
Off
Warning
CSV Export
Device
Unique ID
Unit
IP Address
Status
Uptime / Last Change
Live Alert Feed
🔔
WhatsApp Connected
Email Connected
✕
PC Health & Support Assistant
Every PC gets a 0–100 health score. Click a PC to see what is wrong, which program causes it, and what to do.
Needs attention
Rules
Select a PC from the list.
✕
Data Protection
Are PCs backed up? Is anything encrypting files? What did the automatic fixes do?
Backups
Ransomware warning
Auto-fix
✕
Server Backup
Database, .env, MeshCentral data and license - daily, checked, kept on the places you choose.
Status
Where & how long
Last run log
✕
IT Report
Tickets, SLA, PC health, backups, ransomware warnings and automatic fixes in one page.
🖨 Print / Save PDF
Loading…
✕
IT Support Tickets
Track every problem from report to fix.
⏳ Approvals+ New ticket
Select a ticket.
✕
Remote Support Session
Establishing a secure connection to the device via the agent
Unique Device ID--
IP Address--
Unit--
⚠️ This is a privileged device — the session will be recorded
Notify the device user and get consent before connecting — the session cannot start without consent.
Per the company’s written IT Usage Policy (acknowledged by all staff) — no separate
consent prompt will be shown, but a brief notice will appear on the device’s screen
while recording is in progress.
Recording in progress00:00
Handshaking with agent…
Cancel
Start Screen Share →
End Session
✕
Message & Remote Command
Send a message to the user’s screen or issue a command directly to the device
Send Message (will stay on screen until acknowledged)
Send
Remote Command
🔁 Reboot
⏻ Shutdown
🚪 Log Off
🌅 Power On (WoL)
🔒 Lock Screen
📸 Take Screenshot
🌐 Open Website
▶️ Run Program
Send
Run
⚠️ Runs on the device immediately — double-check the path before sending.
Send
Activity Monitoring (Browsing History)
opt-in feature — off by default. Proceed per company monitoring policy before enabling.
Filter
USB Device Control (This Device Only)
Overrides the unit/group-wide USB policy for just this one device. Leave on "Use Unit/Group Policy" to follow the normal policy instead.
Save Override
Remove Override
This device has more than one monitor? No extra setup needed — once you press "Start Screen Share →" above,
MeshCentral's own remote-desktop toolbar automatically shows a monitor selector so you can switch between, or
view, each of that user's screens separately.
Want to watch every online device's screen at once, side by side (a CCTV-style wall of all users)? Use the
"🖥️ Live Screens Wall" button in the top toolbar
— it opens MeshCentral's own built-in group view, which is far more reliable than building this from scratch.
⚠️ Remote unlock is not possible: No operating system allows the screen to be unlocked remotely without the password —
this is an intentional OS security limit that no software can bypass. A message can be sent
to a locked PC to notify the user, but it cannot be force-unlocked.
An honest note about snapshots: This is not exactly a ""moment of the click"" picture — the agent takes a screenshot ~3 seconds after seeing a new URL
(to allow time for the page to load), so this is a best-effort
proxy, not pixel-perfect click timing.
✕
🖥️ Live Screens Wall
Watch online devices' screens side by side — like a CCTV / classroom-monitoring wall
Option A — Grid inside this dashboard NEW
Every online device's screen appears live in a grid right here — no new tab. Tiles are view-only until you
press the 🖱 icon on a tile. Best for up to ~12–16 screens at a time (paged); servers/network gear
(critical devices) are never shown on the wall.
Open Grid Here →
Option C — TV Wall (one tile per monitor) NEW v2.6
A separate full-screen page made for a big TV: its own login (User ID + password), auto-fit grid, auto-rotating pages,
no MeshCentral login needed. A PC with 2–3 monitors shows 2–3 separate tiles; a single-monitor PC shows one.
Click a tile to lock just that monitor, or lock / log off / reboot the whole PC.
Owner / Director logins can be given all units and/or control by the Group Admin (Users → Add / Edit user). Each viewer picks how many screens to show at once (1–64 or a custom grid).
Open this address in the TV's browser:
Open TV Wall ↗
Mobile Screens — watch from your phone NEW v3.4
A phone-first page: PC list with live thumbnails (only the ones on screen load, to save mobile data), tap a PC for a full-screen view, swipe for the next one.
View only. Same login and the same server-side limits as the TV Wall. Open this address on the phone:
Open Mobile Screens ↗
TV Access & Limits — control what the TV may show NEW v2.8
A TV is an open screen, so you decide how much it shows: limit your own login on the TV (units, PCs, how many screens, main monitor only,
hide staff names, view / basic / full control), or create TV-only sub accounts and give each its own limit — up to full control.
Enforced on the server. Nobody can hand out more than they have. Available to Group Admin, Unit Admin and Owner / Director.
Open TV Access & Limits ↗
Option B — MeshCentral console (new tab)
Still the most reliable choice for a very large number of devices: it opens MeshCentral's own multi-desktop group view.
Press "Open MeshCentral Console →" (log in there once if asked).
Select the Device Group on the left, then open the view dropdown (top-right of the device list) and choose "Desktops".
Click any tile to expand just that one.
Open MeshCentral Console →
Per-device, multiple monitors on one PC? Opening that device's own "Desktop" tab (or this dashboard's "Start Screen Share")
shows a monitor selector automatically whenever that PC has more than one screen.
Close
🖥️ Live Screens Wall
‹
—
›
🖱 Controls
↻ Refresh list
⟳ Reload tiles
Open in MeshCentral ↗
✕ Close
Tiles asking for a login? Sign in to MeshCentral once (new tab), then press Reload tiles.
Tile shows “refused to connect”? MeshCentral must allow embedding — run tools/mesh_enable_iframe.sh on the server.
Tiles are view-only; 🖱 Controls (top bar) shows the Connect / RDP Connect / Actions buttons on every tile and makes tiles clickable (turn it OFF after connecting) · per-tile 🖱 = take control · ⛶ = full size · ↗ = open in MeshCentral · Esc = back/close.
✕
📶 Wi-Fi Browsing Activity — Phones
Domain-level activity (e.g. youtube.com) of registered phones while they use the office Wi-Fi. Page titles / full URLs are not visible. Phones on mobile data are not covered.
Activity
Devices & registration
Show
Registered phones
Register a phone seen on the Wi-Fi
Register phone
✕
🎬 Session Recordings
Recordings made by MeshCentral (Bulk Recording and “Record this session”). Download the .mcrec file, then play it in MeshCentral's recording player.
Search
▶ Open player ↗
‹ Prev
—
Next ›
Times are shown in your browser's time zone. Every download is written to the audit log. If the list is empty or says “not set up”, run tools/sync_mesh_recordings.sh on the server (see FIXES-v3.9.0.md).
✕
⏺ Bulk Session Recording
Pick a unit, tick the PCs you want (or “Select all”), then start recording their remote-desktop sessions together
Recorded under the company IT Usage Policy (basis company_policy, same as “Record this session”) and written to the audit log per PC.
Critical devices are never included. Recording runs while the recording screen stays open — keep that tab open until you press “Stop all”.
Cancel
Start Recording
Recording
00:00Size
−
+
420px
🖱 Controls
▶ Connect all
⏹ Stop all & close
Keep this tab open while recording. ⛶ = full size · ⟳ = reload tile · ⏹ = stop only this PC.
✕
Health Diagnostics
Automatic health check for CPU, RAM, disk, and graphics
Detected Issues & Suggestions
Limitation: CPU temperature cannot be read directly on many Windows PCs (an extra tool
is needed for the hardware sensor). Reading the hard disk’s SMART status on Linux/macOS requires smartmontools
to be installed — if it’s not, "Unknown" will be shown — that isn’t proof there’s no problem. The graphics card
check only shows driver status, not deep hardware diagnostics.
✕
✕
Device Details
Tag user, location, and asset info — the barcode label is also generated from here
Agent connection
Agent ID:
Lost the token, or it was leaked/shared? Issue a new one. The old token stops working immediately — the PC must be updated with the new token.
🔑 Re-issue agent token
MeshCentral link (needed for Remote Desktop / Live Screen)
Install the MeshCentral agent on this PC, open the PC in MeshCentral, then paste its node id or the address-bar link here (…?gotonode=…).
Save link
User & Location
Asset Information
Web Panel / Live View
Open the device’s own web-login page from here for IP cameras, printers, routers, attendance machines, etc.
(opens in a new tab; then log in with the device’s own user ID/password to view the live view/admin panel).
🔗 Open Directly (on LAN)
🌐 Open via Relay (works from outside too)
For "Open via Relay" to work, poller/relay_agent.js needs to be running on a machine in the office
(only needs to be set up once — see the "Built-in Relay/Tunnel" section of the README).
Live Video (for RTSP Cameras)
Enter the camera’s RTSP URL/credentials here to view live video directly from the dashboard
(shown by converting RTSP → HLS; MediaMTX must be running on the relay agent machine —
see the "RTSP Live Video" section of the README). The password is saved encrypted.
Save RTSP Config
▶ View Live Feed
Save Information
Barcode Label
First save the information above, then press "Generate Barcode"
Regular desktops/monitors/printers have no power sensor — attach a smart plug (Tasmota/Shelly) and configure it below for accurate readings.
Save Smart Plug
✕
Live View
RTSP feed is shown converted to HLS — a few seconds of delay is normal
✕
Network Health — Loop / Broadcast Storm / Congestion
Automatically detects which LAN segment and which device is causing the problem
LAN Segment Summary
All LAN Segments (Edit/Delete)
Event List
+ Add New LAN Segment
Create Segment
Switch Port-Location (SNMP)
Search
+ Add New Switch
Add Switch
How it works:poller/network_health_monitor.py and network_poller.js
run as a separate instance for each LAN segment (each with its own segment_name)
in the config) — broadcast/ARP storms and congestion are detected independently on each segment, so one segment’s
problem doesn’t affect another segment’s baseline. When a MAC address matches, the exact device responsible is shown by name.
⚠️ Setup Requirement: For broadcast/ARP storm detection, network_health_monitor.py
must be run with admin/root permission (Npcap must be installed on Windows). For each segment (LAN block/VLAN),
a separate copy of this script must be run on a PC connected to that segment — an
instance simply cannot see traffic outside its own broadcast domain; this is a
fundamental networking limitation that no software can work around.
🔌 How Port-Location Works: After adding a switch above, use that switch’s switch_id
with poller/switches.json to configure node poller/snmp_port_locator.js
and run it (SNMP v1/v2c must be enabled on the switch). From then on, storm/loop alerts will directly show "which switch,
which port" it’s on, and any MAC can also be looked up manually via the search box above. This only
works with managed/smart switches — unmanaged switches don’t have SNMP.
✕
Office-Time Policy
Set working hours and blocked sites — visiting these sites during office hours will trigger an automatic alert
⚠️ Allowlist mode is enforced by the agent's firewall on every device with the agent in this scope
(not only devices with activity monitoring enabled) and blocks essentially all other internet access —
including Windows Update and software updates. Pilot it on one unit/device first; avoid the Group-Wide
default unless you really mean every device (servers included). The backend server, DNS, the local
network and (if detected) the MeshCentral server stay reachable automatically; add your MeshCentral
domain to the list to be safe.
Save Policy
This policy only applies to devices with opt-in activity monitoring enabled (can be toggled in each device’s
"Message & Command" modal). On a violation, that device’s admins get an
automatic WhatsApp/Email alert, and it shows as a red flag in the browsing history — from where you can directly
press "Warn" (send message) or "Block Site".
✕
🚨 Trigger-Word / Sensitive-Phrase Alerts
Watched words/phrases are scanned against on-screen text on devices where Screen Recording + OCR
is already enabled (Screen OCR must be turned on separately per device — this panel does not add
any new capture, it only adds alerting on top of the existing OCR text).
Add
Phrase
Scope
Active
Added By
Detected Hits (user-wise)
⬇️ Download Report (CSV)
When
User
Device
Matched
Context
A CSV report can be printed directly from Excel/Sheets ("Print" after opening the file) — no separate
print pipeline is needed. Every hit is also written to the standard alerts feed for compliance records.
The same phrase on the same device is reported at most once per 10 minutes to avoid flooding.
✕
🔒 VPN Control
Detect and stop known VPN client apps on company devices — complements website allowlisting, since a VPN can otherwise bypass it.
Save Policy
Recent VPN-block Events
When
Device
User
Action
Process
Process-name based detection — a determined technical user could rename an executable to
evade it. This stops casual/policy-violation VPN use, not a guaranteed bypass-proof block.
Devices pick up policy changes at their next heartbeat (about a minute).
✕
USB Device Control
Control USB storage / MTP devices on managed endpoints — allow all, block all, or allow only specific serial numbers.
Save Policy
Enforced by the on-device agent (Windows: USBSTOR registry + WMI watcher; Linux: usbguard). Takes effect on the device's next heartbeat cycle.
✕
Data Channel Control
Bluetooth file transfer, CD/DVD, network shares and e-mail — each is allowed or blocked on its own. USB is in "USB Device Control". Single-PC settings win over unit settings, unit settings win over the group default.
Other Bluetooth file-transfer programs are not recognised by "Block file transfer"; use "Block all" for those.
Uses the same Windows "Removable Storage Access" policy as Group Policy; applies immediately and survives reboot.
Domain-joined PCs: add the domain controllers and file server below BEFORE blocking, or logon scripts and Group Policy stop working.
Webmail and Microsoft 365 / Gmail run over normal HTTPS, so ports alone do not stop them — list the webmail sites below. File CONTENT and attachments are never read.
Save
Remove this PC's override
Recent enforcement events (names only, never file content)
Refresh
Windows PCs only (Linux / macOS agents ignore these settings). Enforced by the on-device SYSTEM service within about one heartbeat (~45 s). A local administrator can undo a setting; the agent re-applies it on the next cycle. This is a deterrent, not a tamper-proof lock.
✕
Behavioral Risk Alerts
Unusual patterns automatically detected from existing login time, IP, and remote-session data — no new content is captured
The score is calculated every 5 minutes, from the last 30 minutes of login/session data — new/unrecognized IPs,
logins outside office hours, a successful login after multiple failed attempts, logins from multiple IPs in a short time,
or an unusually high number of remote sessions — from the sum of these signals. A score of 40+ is "elevated",
and 70+ is "critical" an alert is generated and admins are notified via WhatsApp/Email.
✕
Activity Monitor — All Devices
Browsing activity from every device you can see, in one place — search, filter, and generate a user-wise report for a date range.
Today
Last 7 days
Last 30 days
Apply Filters
⬇ Detail (CSV)
⬇ User Summary (CSV)
🖨 Print / PDF
← Prev
Next →
The "User or device name" box matches the assigned user, the device name or the hostname (part of the name is enough). Only entries from devices with opt-in activity monitoring enabled are shown here, scoped to the units your account
can access. The date filter applies to when the page was visited (device local time as reported by the agent).
Reports (detail CSV, per-user summary CSV, printable PDF view) use the filters above, in your browser's local time; leave the date range empty to export everything in scope.
✕
Add Device
Register a PC/device manually. You get an Agent ID and Agent Token to install the agent on that PC.
Create device
✕
Network Scan Results
Devices found by the LAN scanner (poller/lan_scanner.js) — add new/unknown devices to tracking with one click
This backend receives the report, it does not run the scan itself: A LAN scan cannot be run directly from the browser,
so the poller/lan_scanner.js script must be run from any PC in your office
(node lan_scanner.js --watch runs it repeatedly every hour). Setup steps are in the backend README.
✕
User Management
Manage accounts and multi-business access for support engineers/unit officers
+ Add New User
🖥️ Live Screens Wall access (TV Wall)
The Owner / Director opens /tv.html with this login. The units ticked below only affect the main dashboard.
Create User
✕
Unit / Business Management
Add a new unit, edit name/address, or delete an empty unit
+ Add New Unit
Add Unit
✕
Change My Password
For security, your current password is required. The new password must be at least 8 characters.
Change Password
✕
Server Settings
Group Admin only — the server’s port number can be changed right from here, no terminal/SSH needed
Current Port: —
⚠️ As soon as the port changes, the server will restart for a few seconds — the dashboard will temporarily
lose connection during this time. Once the change is complete, it will automatically try to reconnect on the new port.
Change Port
Current Session/Login Duration: — hours
ℹ️ This is how long a user can use the dashboard after logging in without being auto-logged-out. Changing
this doesn’t require a server restart — it only takes effect from new logins onward ; anyone currently
logged in keeps their existing session valid for the previous duration.
Change Session Duration
✕
Clipboard Monitoring (Targeted)
Only the company owner/top admin can enable this — on a specific device, for a specific reason.
Password/credential-type content is automatically excluded (raw content is never stored).
As soon as it’s enabled, that device’s user is notified with an on-screen message.
Enable on this Device
Disable
Recent Logs (Redacted)
On/Off History
✕
Screen Recording + OCR (Targeted)
Only the company owner/top admin can enable this — on a specific device, for a specific reason. This is
not video recording — it’s periodic snapshots + OCR. Password fields are blurred when detected,
and the device’s user is notified as soon as it’s enabled.
Many PCs at once
Filter by unit / department, tick the PCs (or “Select all in view”), give one reason, then enable or disable them together. Each PC still gets its own on-screen notice and audit entry.