πŸ›‘οΈ Tech Sentinel v5.0

Network Monitoring & Management Suite

Professional Edition - User Manual

1. Introduction

Tech Sentinel is a comprehensive network monitoring and management tool designed for IT professionals, network administrators, and system engineers. It provides real-time network visibility, automated discovery, and powerful management capabilities all in one intuitive interface.

🎯 Core Capabilities:

  • Real-Time Monitoring - Continuous ping monitoring with latency graphs and packet loss tracking
  • Network Discovery - Scan entire subnets and detect all active devices
  • Port Scanning - Identify open ports and services on any target
  • SNMP Monitoring - Query SNMP-enabled devices for system information
  • ARP/mDNS Discovery - Detect devices using ARP tables and mDNS queries
  • Drive Mapping - Manage network drive mappings with secure credential storage
  • Remote Agents - Deploy and query lightweight monitoring agents
  • Scheduled Automation - Run network scans automatically on a schedule
  • Advanced Reporting - Export data in CSV and PDF formats
  • Email Alerts - Receive automated reports via email

Who Should Use Tech Sentinel?

  • Network Administrators - Monitor network health and troubleshoot connectivity issues
  • System Engineers - Automate network audits and maintain device inventories
  • IT Support Teams - Quickly diagnose network problems and verify connectivity
  • MSPs - Monitor multiple client networks from a single dashboard
  • Security Teams - Detect unauthorized devices and monitor network changes

2. System Requirements

Minimum Requirements:

  • Operating System: Windows 10/11 (64-bit) or Linux
  • Python: Python 3.8 or higher
  • Memory: 4 GB RAM
  • Disk Space: 100 MB for application and logs
  • Network: Active network connection

Required Python Packages:

pip install customtkinter matplotlib psutil

Optional Python Packages (Enhanced Features):

# For SNMP monitoring pip install pysnmp # For advanced ARP/mDNS discovery pip install scapy # For PDF report generation pip install reportlab # For Windows-specific features (Windows only) pip install pywin32

Recommended:

  • Operating System: Windows 11 or Ubuntu 22.04+
  • Memory: 8 GB RAM or higher
  • Administrator Rights: Required for some features (raw sockets, scapy)
  • Firewall Configuration: Allow ICMP (ping) and required ports
⚠️ Important: Some features require Administrator/root privileges:
  • ARP scanning with Scapy
  • Raw socket operations
  • Windows drive mapping
  • System startup configuration

3. Installation

Step 1: Install Python

  1. Download Python 3.8+ from python.org
  2. During installation, check "Add Python to PATH"
  3. Complete the installation

Step 2: Install Required Packages

Windows:

# Open Command Prompt as Administrator pip install customtkinter matplotlib psutil # Optional but recommended pip install pysnmp scapy reportlab pywin32

Linux:

# Ubuntu/Debian sudo apt update sudo apt install python3-pip python3-tk pip3 install customtkinter matplotlib psutil # Optional sudo pip3 install pysnmp scapy reportlab

Step 3: Download Tech Sentinel

  1. Download TechSentinel_v5.py
  2. Place in a dedicated folder (e.g., C:\TechSentinel)
  3. Configuration files will be created automatically on first run

Step 4: First Launch

Windows:

# Right-click TechSentinel_v5.py β†’ Run as Administrator # Or from Command Prompt (as Admin): python TechSentinel_v5.py

Linux:

sudo python3 TechSentinel_v5.py

Automatic Files Created:

  • network_vault.json - Configuration and saved profiles
  • target_history.json - Monitoring target history
  • techsentinel.log - Application log file
  • telemetry_logs/ - CSV telemetry data directory
  • reports/ - Exported reports directory
πŸ’‘ Tip: Create a desktop shortcut with "Run as Administrator" enabled for easy access:
  • Right-click shortcut β†’ Properties
  • Advanced β†’ Check "Run as administrator"

4. Getting Started

Interface Overview

Tech Sentinel's interface is organized into logical sections for efficient network management.

Main Tabs:

  • πŸ“Š Monitor - Real-time ping monitoring with graphs and statistics
  • πŸ” Discovery - Network scanning and device discovery
  • πŸ—ΊοΈ Topology - Visual network topology mapping
  • πŸ’Ύ Drive Mapping - Network drive management with credentials

Monitor Tab Sections:

  • Target Entry - Enter hostname or IP address to monitor
  • Control Buttons:
    • Start/Stop Monitoring
    • Start/Stop CSV Logging
    • Clear Output
  • Real-Time Graphs:
    • Latency over time
    • Packet loss percentage
  • Statistics Display:
    • Current latency
    • Average latency
    • Packet loss
    • Uptime
  • Output Log - Detailed ping results and events

Network Tools Sidebar:

  • Discovery - Launch network scans
  • Port Scan - Check open ports
  • SNMP - Query SNMP devices
  • DNS - Perform DNS lookups
  • Trace - Run traceroute
  • Web Check - Test web connectivity
  • Agent Query - Contact remote agents
  • Batch Ping - Ping multiple targets

Quick Start Guide

Monitor a Host:

  1. Enter target (e.g., google.com or 192.168.1.1)
  2. Click START Monitor
  3. View real-time latency and packet loss
  4. Click STOP Monitor when done

Discover Network Devices:

  1. Switch to Discovery tab
  2. Enter network range (e.g., 192.168.1.0/24)
  3. Click START Discovery
  4. View discovered devices in the list
  5. Export results to CSV or PDF

Map a Network Drive:

  1. Switch to Drive Mapping tab
  2. Enter drive letter (e.g., Z:)
  3. Enter network path (e.g., \\server\share)
  4. Enter credentials (optional)
  5. Click Add & Map

5. Network Monitoring

Tech Sentinel provides comprehensive real-time network monitoring with visual graphs and detailed statistics.

Starting Monitoring:

  1. Enter target in the target field:
    • Domain name: google.com
    • IP address: 192.168.1.1
    • Hostname: server01
  2. Click START Monitor
  3. Monitoring begins immediately with 0.5-second intervals

Understanding the Graphs:

Latency Graph (Top):

  • X-Axis: Time (last 120 samples)
  • Y-Axis: Response time in milliseconds
  • Green Line: Normal latency
  • Yellow Spikes: Elevated latency
  • Red Spikes: High latency or timeouts

Packet Loss Graph (Bottom):

  • X-Axis: Time (last 120 samples)
  • Y-Axis: Packet loss percentage (0-100%)
  • Shows: Failed ping attempts over time

Statistics Display:

Metric Description Good Values
Current Latency Most recent ping response time < 50ms (LAN)
< 100ms (WAN)
Average Latency Mean response time over monitoring period Consistent, low values
Packet Loss Percentage of failed pings 0% (acceptable: < 1%)
Uptime Duration of continuous monitoring N/A (informational)

CSV Telemetry Logging:

Record all monitoring data to CSV for analysis:

  1. Start monitoring a target
  2. Click START CSV Log
  3. Data is saved to telemetry_logs/[target]_[timestamp].csv
  4. Click STOP CSV Log when done

CSV Format:

timestamp_iso,target,latency_ms,packet_loss,status 2026-02-07T14:30:00.123Z,google.com,25.4,0,OK 2026-02-07T14:30:00.623Z,google.com,26.1,0,OK 2026-02-07T14:30:01.123Z,google.com,TIMEOUT,1,FAIL

Advanced Options:

Sample Interval:

  • Default: 0.5 seconds
  • Adjustable via Settings
  • Lower values = more data points, higher CPU usage

Buffer Length:

  • Default: 120 samples displayed
  • Configurable via Settings
  • Determines graph time window
πŸ’‘ Pro Tips:
  • Monitor critical servers 24/7 with CSV logging enabled
  • Use long-term logs to establish baseline performance
  • Compare latency during different times of day
  • Look for patterns in packet loss (congestion, hardware issues)
⚠️ Note: Continuous monitoring generates network traffic. Be mindful of:
  • ICMP rate limiting on some firewalls
  • Network bandwidth on metered connections
  • Disk space usage with long CSV logs

6. Network Discovery

Discover all active devices on your network using various scanning methods.

Supported Input Formats:

CIDR Notation:

192.168.1.0/24 # Scans 192.168.1.1 - 192.168.1.254 10.0.0.0/16 # Scans entire 10.0.x.x network

IP Ranges:

192.168.1.1-254 # Short form 192.168.1.1-192.168.1.254 # Long form

Single IP:

192.168.1.100 # Single host

Running a Discovery Scan:

  1. Go to Discovery tab
  2. Enter target range in the input field
  3. Configure scan options:
    • Use ARP Scan: Check for ARP-based discovery (requires scapy)
    • Port Probe: Check for port scanning during discovery
    • SNMP Query: Enable SNMP polling (requires pysnmp)
  4. Click START Discovery
  5. Monitor progress in the output log
  6. View results in the discovered devices list

Discovery Methods:

1. Ping Sweep (Default):

  • Sends ICMP echo requests to each IP
  • Fast and reliable
  • Works on most networks
  • May be blocked by firewalls

2. ARP Scan (Scapy Required):

  • Uses ARP protocol to discover Layer 2 devices
  • More reliable than ping on local networks
  • Bypasses ICMP-blocking firewalls
  • Limited to local subnet
  • Retrieves MAC addresses

3. ARP Table Fallback:

  • Reads system ARP cache
  • No active scanning
  • Only shows recently communicated devices
  • Instant results

Discovered Device Information:

Each discovered device shows:

  • IP Address - Network address
  • Alive Status - Responded to ping
  • Open Ports - Detected services (if port probing enabled)
  • MAC Address - Hardware address (if ARP scan used)
  • mDNS Name - Advertised hostname (if detected)
  • SNMP Data - System name, description, uptime (if SNMP enabled)

Port Probing:

When enabled, scans these common ports:

  • 22 - SSH
  • 80 - HTTP
  • 443 - HTTPS
  • 3389 - RDP (Remote Desktop)

SNMP Discovery:

Configure SNMP settings:

  1. Go to Settings β†’ SNMP
  2. Set Community String (default: public)
  3. Set SNMP Port (default: 161)
  4. Set SNMP Version (default: 2c)
  5. Enable SNMP Query in Discovery options

πŸ” Discovery Scope Examples:

  • Home Network: 192.168.1.0/24 (254 hosts)
  • Small Office: 10.0.0.0/24 (254 hosts)
  • Subnet Range: 172.16.0.1-100 (100 hosts)
  • Large Network: 10.0.0.0/16 (65,534 hosts - may take hours)
πŸ’‘ Performance Tips:
  • Start with small ranges (/28 or /27) to test
  • Use ARP scan for local networks (faster and more reliable)
  • Disable port probing for faster scans
  • Schedule large scans during off-hours
  • Export results regularly for comparison

7. Port Scanning

Identify open ports and services on network targets.

Running a Port Scan:

  1. Enter target IP or hostname
  2. Click Port Scan in the Network Tools section
  3. View results in the output log

Default Ports Scanned:

Port Service Description
22 SSH Secure Shell remote access
80 HTTP Web server
443 HTTPS Secure web server
3389 RDP Windows Remote Desktop
3306 MySQL MySQL database
5432 PostgreSQL PostgreSQL database
8080 HTTP-Alt Alternative web server

Understanding Results:

OPEN:

Port is accepting connections. Service is running and accessible.

CLOSED:

Port is not listening. No service is running on this port.

FILTERED:

Firewall is blocking probe packets. Port state is unknown.

Web Quick Check:

Specifically tests HTTP/HTTPS connectivity:

  1. Enter target website or IP
  2. Click Web Check
  3. Tests ports 80 and 443
  4. Shows OPEN/CLOSED status

Custom Port Scanning:

For advanced users, modify the ports list in code:

# Edit probe_ports function ports=(20,21,22,23,25,53,80,110,143,443,993,995,3306,3389,5432,8080)
⚠️ Legal Warning:
  • Only scan networks and systems you own or have permission to test
  • Unauthorized port scanning may be illegal in your jurisdiction
  • Some ISPs may flag or block port scanning activity
  • Always obtain written authorization before scanning
πŸ’‘ Use Cases:
  • Verify firewall rules are working correctly
  • Identify unauthorized services
  • Troubleshoot service accessibility
  • Audit network security posture
  • Document available services

8. SNMP Monitoring

Query SNMP-enabled devices for detailed system information.

⚠️ Requirement: SNMP features require the pysnmp package:
pip install pysnmp

What is SNMP?

Simple Network Management Protocol (SNMP) is used to monitor and manage network devices like routers, switches, servers, printers, and more.

Configuring SNMP:

  1. Go to Settings β†’ SNMP
  2. Set Community String:
    • Default: public (read-only)
    • Check your device documentation
  3. Set SNMP Port:
    • Default: 161
    • Rarely needs changing
  4. Set SNMP Version:
    • Options: 1, 2c, 3
    • Default: 2c (most common)

Querying an SNMP Device:

  1. Enter target IP address
  2. Click SNMP in Network Tools
  3. View retrieved information in output log

Information Retrieved:

  • sysName - Device hostname
  • sysDescr - Device description and model
  • sysUpTime - Time since last reboot
  • sysLocation - Physical location (if configured)
  • sysContact - Administrator contact (if configured)

Common SNMP-Enabled Devices:

  • Network Equipment: Routers, switches, firewalls
  • Servers: Windows Server, Linux servers
  • Printers: Network printers and copiers
  • NAS Devices: Network attached storage
  • UPS Systems: Uninterruptible power supplies
  • Environmental Monitors: Temperature, humidity sensors

SNMP During Discovery:

Enable SNMP queries during network discovery:

  1. Go to Discovery tab
  2. Check SNMP Query option
  3. Run discovery scan
  4. SNMP data appears for responsive devices
  5. Export results include SNMP columns

Troubleshooting SNMP:

No Response:

  • Verify SNMP is enabled on target device
  • Check community string is correct
  • Ensure firewall allows UDP port 161
  • Verify device IP address is correct

Access Denied:

  • Community string may be wrong
  • Device may require SNMPv3 with authentication
  • Access control list may block your IP
πŸ’‘ Security Best Practices:
  • Change default community strings
  • Use read-only community strings
  • Implement SNMPv3 with authentication when possible
  • Restrict SNMP access to management networks
  • Monitor for unauthorized SNMP queries

9. Network Drive Mapping

Manage network drive mappings with secure credential storage.

πŸ” Secure Credential Storage:

Tech Sentinel uses Windows Credential Manager or system keyring to securely store passwords. Credentials are never saved in plain text.

Mapping a Network Drive:

  1. Go to Drive Mapping tab
  2. Enter drive letter (e.g., Z:)
  3. Enter network path:
    • UNC format: \\server\share
    • IP format: \\192.168.1.100\share
  4. Enter username (if required):
    • Domain: DOMAIN\username
    • Local: username
  5. Enter password (if required)
  6. Click Add & Map

Managing Saved Profiles:

All drive mappings are saved as profiles for quick remapping:

Saved Profile Features:

  • Persistent Storage - Profiles survive application restarts
  • One-Click Remapping - Quickly reconnect drives
  • Credential Security - Passwords stored securely
  • Status Display - See current connection state

Profile Actions:

  • Map - Connect this drive mapping
  • Disconnect - Disconnect this specific drive
  • Delete - Remove profile from saved list

Bulk Operations:

Auto-Map All:

  • Click Auto-Map All
  • All saved profiles attempt to connect
  • Perfect for startup or after network interruption

Disconnect All:

  • Click Disconnect All
  • Disconnects all network drives
  • Useful before system maintenance

System Status Display:

The status panel shows:

  • Currently Mapped Drives - Active connections
  • Drive Letter β†’ Network Path
  • Connection State - Online/Offline indication

Startup Configuration:

Configure Tech Sentinel to run at Windows startup:

  1. Click Startup Config
  2. Choose Yes to enable
  3. Application will start with Windows
  4. Auto-maps all saved drives on startup

Common Network Paths:

Type Example Path
Windows Share \\SERVER\Users
NAS Device \\192.168.1.100\backup
DFS Path \\domain.com\namespace\share
Hidden Share \\SERVER\C$
⚠️ Windows Only:
  • Drive mapping features require Windows
  • Requires pywin32 package for full functionality
  • Some features need Administrator rights
  • Credentials stored in Windows Credential Manager
πŸ’‘ Best Practices:
  • Use consistent drive letters across all computers
  • Document drive mappings for team members
  • Test connectivity before saving profiles
  • Use meaningful descriptions in profile names
  • Periodically verify saved profiles still work

10. Remote Agent

Deploy lightweight monitoring agents to remote systems for advanced monitoring capabilities.

What is a Remote Agent?

A remote agent is Tech Sentinel running in "agent mode" on a remote system. It listens for queries and responds with system information.

Starting the Agent Server:

  1. Go to Settings β†’ Agent
  2. Set Listen Port (default: 50050)
  3. Click Start Agent Server
  4. Agent begins listening for queries
  5. Configure firewall to allow the port

Querying an Agent:

  1. Enter agent IP address in target field
  2. Click Agent Query in Network Tools
  3. View response in output log

Agent Commands:

PING:

  • Simple connectivity test
  • Returns timestamp
  • Verifies agent is responsive

SYSINFO:

  • Retrieves system information
  • Platform details
  • CPU usage percentage
  • Memory usage percentage

ARP:

  • Returns agent's ARP table
  • Shows devices the agent sees
  • Useful for network topology mapping

Example Query Response:

{ "status": "OK", "platform": "Windows-10-10.0.19045-SP0", "cpu": 15.2, "mem": 45.8, "time": "2026-02-07T14:30:00.000Z" }

Deployment Scenarios:

Branch Office Monitoring:

  • Deploy agent at remote location
  • Query from central location
  • Monitor without VPN overhead

DMZ Monitoring:

  • Agent in DMZ network
  • Query from management network
  • Limited firewall rules required

Distributed Topology:

  • Multiple agents across network
  • Each reports local ARP table
  • Build comprehensive network map

Security Considerations:

⚠️ Security Warning:
  • Agent does not use authentication (MVP version)
  • Anyone who can reach the port can query
  • Use firewall rules to restrict access
  • Do not expose agent port to internet
  • Consider VPN or secure tunnel for remote access

Firewall Configuration:

Windows Firewall (Agent Server):

netsh advfirewall firewall add rule name="Tech Sentinel Agent" ^ dir=in action=allow protocol=TCP localport=50050

Linux UFW (Agent Server):

sudo ufw allow 50050/tcp
πŸ’‘ Best Practices:
  • Use non-standard ports for agents
  • Limit agent access to management networks
  • Document agent deployments and ports
  • Regularly verify agent connectivity
  • Consider implementing VPN for agent communication

11. Scheduled Scans

Automate network discovery scans to run at regular intervals.

Configuring the Scheduler:

  1. Go to Settings β†’ Scheduler
  2. Set Scan Interval (minutes):
    • Minimum: 5 minutes
    • Recommended: 60 minutes (hourly)
    • Typical: 1440 minutes (daily)
  3. Configure Scan Target:
    • Enter network range to scan
    • Example: 192.168.1.0/24
  4. Select Export Format:
    • CSV
    • PDF (requires reportlab)
    • Both
  5. Click Enable Scheduled Scans

How It Works:

  1. Scheduler runs in background thread
  2. Waits for specified interval
  3. Executes network discovery scan
  4. Exports results to reports/ directory
  5. Sends email notification (if configured)
  6. Repeats automatically

Report File Naming:

reports/discovery_20260207_143052.csv reports/discovery_20260207_143052.pdf

Email Notifications:

Receive automatic email when scans complete:

  1. Configure email settings (see Email Notifications section)
  2. In Scheduler settings, check Email on Complete
  3. Set Email From address
  4. Set Email To recipients (comma-separated)
  5. Reports will be emailed as attachments

Use Cases:

Daily Network Audit:

  • Schedule: Every 24 hours (1440 minutes)
  • Purpose: Track device additions/removals
  • Export: CSV for historical comparison

Hourly Availability Check:

  • Schedule: Every 60 minutes
  • Purpose: Monitor critical devices
  • Export: CSV with email alerts

Weekly Compliance Scan:

  • Schedule: Every 10,080 minutes (7 days)
  • Purpose: Generate compliance reports
  • Export: PDF for documentation

Managing Scheduled Scans:

View Status:

  • Check output log for "Scheduled scan triggered" messages
  • Verify reports are being created in reports/
  • Confirm email delivery (if enabled)

Stop Scheduled Scans:

  • Go to Settings β†’ Scheduler
  • Click Disable Scheduled Scans
  • Background thread stops gracefully

Modify Schedule:

  • Stop current schedule
  • Update settings
  • Re-enable scheduled scans
⚠️ Important:
  • Application must remain running for scheduled scans
  • Computer must be powered on and network connected
  • Large network scans can impact performance
  • Monitor disk space usage for reports
πŸ’‘ Best Practices:
  • Schedule scans during off-peak hours
  • Start with longer intervals and adjust as needed
  • Regularly clean old report files
  • Use email notifications for critical scans
  • Consider running on dedicated monitoring system

12. Reports & Export

Export network discovery data in multiple formats for analysis and documentation.

Supported Export Formats:

CSV (Comma-Separated Values):

  • Machine-readable format
  • Open in Excel, Google Sheets, etc.
  • Easy data analysis and filtering
  • Historical trend analysis
  • Always available

PDF (Portable Document Format):

  • Professional presentation
  • Print-friendly format
  • Share with non-technical stakeholders
  • Archive for compliance
  • Requires reportlab package

Exporting Discovery Results:

  1. Complete a network discovery scan
  2. View results in Discovery tab
  3. Click Export CSV or Export PDF
  4. Choose destination and filename
  5. Click Save

CSV Format Details:

Columns:

  • timestamp_iso - ISO 8601 timestamp (UTC)
  • ip - IP address
  • alive - Responded to ping (True/False)
  • ports - Comma-separated open ports
  • snmp_sysName - SNMP system name
  • snmp_sysDescr - SNMP system description
  • snmp_sysUpTime - SNMP uptime
  • mac - MAC address (if available)
  • mdns_name - mDNS advertised name

Example CSV:

timestamp_iso,ip,alive,ports,snmp_sysName,mac,mdns_name 2026-02-07T14:30:00Z,192.168.1.1,True,"80,443",Router-01,aa:bb:cc:dd:ee:ff,router.local 2026-02-07T14:30:01Z,192.168.1.10,True,"22,80",Server-01,11:22:33:44:55:66,server.local 2026-02-07T14:30:02Z,192.168.1.20,False,"",,,

PDF Report Features:

  • Header - Report title and generation timestamp
  • Device Listings - One entry per discovered device
  • Key Information - IP, ports, MAC, SNMP data
  • Multi-Page Support - Automatically paginated
  • Professional Format - Clean, organized layout

Report Locations:

  • Manual Exports: User-selected location
  • Scheduled Scans: reports/ directory
  • Telemetry CSVs: telemetry_logs/ directory

Analyzing Exported Data:

Excel/Google Sheets:

  1. Open CSV file
  2. Use filters to find specific devices
  3. Sort by IP, ports, or other columns
  4. Create pivot tables for analysis
  5. Generate charts and graphs

Command Line (Linux/Mac):

# Count alive devices grep "True" discovery.csv | wc -l # Find devices with specific port open grep ",80," discovery.csv # Extract just IP addresses cut -d',' -f2 discovery.csv

Python Analysis:

import pandas as pd df = pd.read_csv('discovery.csv') alive_count = df['alive'].sum() devices_with_web = df[df['ports'].str.contains('80|443', na=False)]
πŸ’‘ Report Best Practices:
  • Export regularly for historical comparison
  • Use consistent file naming (include date)
  • Archive reports in organized folders
  • Keep CSV for analysis, PDF for presentation
  • Document any unusual findings in reports

13. Email Notifications

Configure automatic email notifications for scheduled scans and alerts.

Configuring Email Settings:

  1. Go to Settings β†’ Email
  2. Enter SMTP Server:
    • Gmail: smtp.gmail.com
    • Outlook: smtp.office365.com
    • Others: Check provider documentation
  3. Enter SMTP Port:
    • 587 (STARTTLS) - Most common
    • 465 (SSL/TLS) - Alternative
    • 25 (Unencrypted) - Not recommended
  4. Enter Username (your email address)
  5. Enter Password or App Password
  6. Select Use SSL/TLS if using port 465
  7. Click Save Email Settings
  8. Click Test Email to verify

Gmail Configuration:

⚠️ Gmail App Passwords:

Gmail requires App Passwords for third-party applications:

  1. Enable 2-Step Verification on your Google Account
  2. Go to Security β†’ App Passwords
  3. Generate new password for "Other"
  4. Name it "Tech Sentinel"
  5. Copy the 16-character password
  6. Use this password in Tech Sentinel (not your regular password)

Gmail Settings:

  • Server: smtp.gmail.com
  • Port: 587
  • Username: youremail@gmail.com
  • Password: App Password (not regular password)
  • SSL/TLS: Unchecked (using STARTTLS on 587)

Outlook/Office 365 Configuration:

Settings:

  • Server: smtp.office365.com
  • Port: 587
  • Username: youremail@outlook.com
  • Password: Your account password
  • SSL/TLS: Unchecked (using STARTTLS)

Credential Storage:

Email passwords are stored securely using:

  • Windows: Windows Credential Manager (if pywin32 installed)
  • Linux/Mac: System keyring (if keyring package installed)
  • Passwords are never stored in plain text

Email Notifications Usage:

Scheduled Scan Notifications:

  1. Configure email settings (above)
  2. Go to Settings β†’ Scheduler
  3. Check Email on Complete
  4. Enter Email From (your email)
  5. Enter Email To (recipients, comma-separated)
  6. Reports will be emailed automatically

Email Contents:

  • Subject: "Tech Sentinel - Discovery Report"
  • Body: Scan summary and timestamp
  • Attachment: CSV or PDF report file

Troubleshooting Email:

Authentication Failed:

  • Verify username and password are correct
  • Gmail users: Use App Password, not regular password
  • Check if 2FA is enabled (required for Gmail)

Connection Timeout:

  • Verify SMTP server and port
  • Check internet connectivity
  • Firewall may be blocking SMTP ports
  • Try different port (587 vs 465)

SSL/TLS Errors:

  • For port 587: Uncheck "Use SSL/TLS"
  • For port 465: Check "Use SSL/TLS"
  • Update Python if SSL errors persist
πŸ’‘ Email Best Practices:
  • Use dedicated monitoring email account
  • Set up email filters for automatic organization
  • Send critical alerts to multiple recipients
  • Keep email report size reasonable (< 10MB)
  • Test email configuration before enabling scheduler

14. Telemetry Logging

Record detailed monitoring data to CSV files for long-term analysis.

What is Telemetry Logging?

Telemetry logging captures every ping result during monitoring sessions, creating a detailed historical record of network performance.

Starting Telemetry Logging:

  1. Start monitoring a target
  2. Click START CSV Log
  3. Logging begins immediately
  4. File created in telemetry_logs/ directory

File Naming Convention:

telemetry_logs/google.com_20260207_143052.csv telemetry_logs/192.168.1.1_20260207_150000.csv

Format: [target]_[date]_[time].csv

CSV Format:

Columns:

  • timestamp_iso - ISO 8601 timestamp (UTC)
  • target - Monitored host
  • latency_ms - Response time in milliseconds (or "TIMEOUT")
  • packet_loss - 1 if timeout, 0 if successful
  • status - "OK" or "FAIL"

Example Data:

timestamp_iso,target,latency_ms,packet_loss,status 2026-02-07T14:30:00.123Z,google.com,25.4,0,OK 2026-02-07T14:30:00.623Z,google.com,26.1,0,OK 2026-02-07T14:30:01.123Z,google.com,TIMEOUT,1,FAIL 2026-02-07T14:30:01.623Z,google.com,27.3,0,OK

Analyzing Telemetry Data:

Calculate Statistics:

  • Average Latency: Mean of all successful pings
  • Minimum Latency: Best case performance
  • Maximum Latency: Worst case performance
  • Packet Loss Rate: Percentage of timeouts
  • Uptime Percentage: (100 - packet_loss)

Identify Patterns:

  • Time-of-day performance variations
  • Recurring outages
  • Gradual degradation trends
  • Correlation with other events

Create Visualizations:

  • Import into Excel/Google Sheets
  • Create line charts of latency over time
  • Highlight timeout periods
  • Compare multiple monitoring sessions

Storage Considerations:

File Size Estimates:

  • 1 hour: ~50 KB (0.5s intervals)
  • 24 hours: ~1.2 MB
  • 1 week: ~8.4 MB
  • 1 month: ~36 MB

Disk Space Management:

  • Regularly archive old telemetry files
  • Compress archives for long-term storage
  • Set up automated cleanup of old files
  • Monitor telemetry_logs/ directory size

Use Cases:

SLA Compliance:

  • Document uptime percentage
  • Prove service level achievement
  • Identify SLA violations

Troubleshooting:

  • Correlate issues with specific times
  • Identify intermittent problems
  • Establish baseline performance

Capacity Planning:

  • Identify growth trends
  • Predict performance degradation
  • Justify infrastructure upgrades
πŸ’‘ Telemetry Best Practices:
  • Enable logging for critical infrastructure
  • Keep logs for at least 30 days
  • Automate analysis with scripts
  • Archive important monitoring sessions
  • Use telemetry data for trend reports

15. Troubleshooting

Installation Issues:

Issue: "customtkinter module not found"

Solution:

pip install customtkinter # or pip3 install customtkinter

Issue: "matplotlib backend error"

Solution (Linux):

sudo apt install python3-tk

Issue: Permission denied on Linux

Solution:

sudo python3 TechSentinel_v5.py

Monitoring Issues:

Issue: "Request timed out" constantly

Solutions:

  • Verify target is online and reachable
  • Check firewall allows ICMP (ping)
  • Try pinging from command line to verify
  • Some devices/firewalls block ICMP completely

Issue: High latency values

Causes:

  • Network congestion
  • Routing issues
  • Distance/hop count
  • Target system overload

Issue: Graphs not updating

Solutions:

  • Stop and restart monitoring
  • Check if application is frozen (CPU usage)
  • Close and relaunch application

Discovery Issues:

Issue: No devices discovered

Solutions:

  • Verify network range is correct
  • Check if devices allow ping
  • Try ARP scan instead of ping scan
  • Increase timeout values
  • Ensure network connectivity

Issue: Scapy features not available

Solution:

# Windows (as Administrator) pip install scapy # Linux sudo pip3 install scapy

Issue: SNMP queries fail

Solutions:

  • Verify SNMP is enabled on target
  • Check community string is correct
  • Ensure firewall allows UDP 161
  • Install pysnmp: pip install pysnmp

Drive Mapping Issues:

Issue: "Network path not found"

Solutions:

  • Verify server/NAS is online
  • Check network connectivity
  • Ensure share exists and is accessible
  • Try accessing via File Explorer first

Issue: "Access denied"

Solutions:

  • Verify credentials are correct
  • Check user has permissions on share
  • Try domain format: DOMAIN\username
  • Ensure password is current

Issue: Drive won't disconnect

Solutions:

  • Close programs accessing the drive
  • Use "Disconnect All" button
  • Manually disconnect via File Explorer
  • Restart computer if necessary

Email Issues:

Issue: Email test fails

Solutions:

  • Verify SMTP server and port
  • Check username/password
  • Gmail: Must use App Password
  • Check SSL/TLS setting matches port
  • Verify internet connectivity

Issue: "Authentication failed"

Solutions:

  • Gmail: Generate new App Password
  • Outlook: Check account password
  • Verify 2FA is properly configured
  • Some providers require "less secure apps" enabled

Performance Issues:

Issue: Application is slow/unresponsive

Solutions:

  • Reduce sample interval (increase from 0.5s)
  • Reduce buffer length (less data points)
  • Limit discovery scan range
  • Close unused tabs
  • Check system resources (CPU, RAM)

Issue: High CPU usage

Solutions:

  • Increase monitoring interval
  • Disable CSV logging when not needed
  • Limit concurrent operations
  • Close other applications

Log Files:

Check techsentinel.log for detailed error messages:

# View recent errors (Windows) type techsentinel.log | findstr ERROR # View recent errors (Linux/Mac) grep ERROR techsentinel.log | tail -20

Getting Support:

If issues persist:

  • Check techsentinel.log for errors
  • Note exact error message
  • Document steps to reproduce
  • Check Python and package versions
  • Contact: www.regteches.com

16. Best Practices

Network Monitoring:

Establish Baselines:

  • Monitor during normal conditions
  • Record average latency values
  • Document expected packet loss (if any)
  • Identify peak usage times

Continuous Monitoring:

  • Monitor critical infrastructure 24/7
  • Enable CSV logging for important targets
  • Set up automated alerting
  • Review logs weekly for trends

Alert Thresholds:

  • Critical: >5% packet loss
  • Warning: >2x normal latency
  • Info: >1.5x normal latency

Discovery & Documentation:

Regular Scans:

  • Daily: Critical networks
  • Weekly: Corporate networks
  • Monthly: Full infrastructure audit

Maintain Inventory:

  • Export discovery results regularly
  • Compare with previous scans
  • Investigate new/missing devices
  • Update network documentation

Security Scanning:

  • Look for unexpected open ports
  • Detect unauthorized devices
  • Monitor for topology changes
  • Document all findings

Data Management:

File Organization:

TechSentinel/ β”œβ”€β”€ telemetry_logs/ β”‚ β”œβ”€β”€ 2026-01/ β”‚ β”œβ”€β”€ 2026-02/ β”‚ └── archive/ β”œβ”€β”€ reports/ β”‚ β”œβ”€β”€ daily/ β”‚ β”œβ”€β”€ weekly/ β”‚ └── monthly/ └── config_backups/

Retention Schedule:

  • Telemetry CSVs: 30-90 days
  • Discovery Reports: 1 year
  • Compliance Reports: 7+ years
  • Log Files: 30 days

Backup Configuration:

  • Regularly backup network_vault.json
  • Document drive mapping profiles
  • Export SNMP settings
  • Save email configuration

Security:

Access Control:

  • Limit who can run network scans
  • Protect credential storage
  • Use strong passwords for SNMP
  • Restrict agent port access

Scan Authorization:

  • Only scan networks you own/manage
  • Obtain written permission for client networks
  • Document authorized scan ranges
  • Notify stakeholders before scanning

Credential Management:

  • Use dedicated service accounts
  • Rotate passwords regularly
  • Never share credentials
  • Document who has access

Performance Optimization:

Monitoring Intervals:

Use Case Interval
Real-time troubleshooting 0.5 seconds
Active monitoring 1-5 seconds
Background monitoring 10-30 seconds
Long-term baseline 60 seconds

Discovery Optimization:

  • Use ARP scan for local networks
  • Increase timeout for slow networks
  • Disable unnecessary features (port probe, SNMP)
  • Schedule large scans overnight

Reporting:

Report Frequency:

  • Daily: Operational metrics
  • Weekly: Trend analysis
  • Monthly: Executive summary
  • Quarterly: Strategic planning

Report Contents:

  • Current network inventory
  • Availability statistics
  • Performance trends
  • Incidents and resolutions
  • Recommended actions
πŸ’‘ Golden Rules:
  • Monitor proactively: Don't wait for problems
  • Document everything: Notes are invaluable later
  • Automate repetitive tasks: Use scheduling
  • Review regularly: Analyze trends weekly
  • Keep learning: Networks evolve, so should you