π Table of Contents
- 1. Introduction
- 2. System Requirements
- 3. Installation
- 4. Getting Started
- 5. Network Monitoring
- 6. Network Discovery
- 7. Port Scanning
- 8. SNMP Monitoring
- 9. Network Drive Mapping
- 10. Remote Agent
- 11. Scheduled Scans
- 12. Reports & Export
- 13. Email Notifications
- 14. Telemetry Logging
- 15. Troubleshooting
- 16. Best Practices
1. Introduction
Tech Sentinel is a comprehensive network monitoring and management tool designed for IT professionals, network administrators, and system engineers. It provides real-time network visibility, automated discovery, and powerful management capabilities all in one intuitive interface.
π― Core Capabilities:
- Real-Time Monitoring - Continuous ping monitoring with latency graphs and packet loss tracking
- Network Discovery - Scan entire subnets and detect all active devices
- Port Scanning - Identify open ports and services on any target
- SNMP Monitoring - Query SNMP-enabled devices for system information
- ARP/mDNS Discovery - Detect devices using ARP tables and mDNS queries
- Drive Mapping - Manage network drive mappings with secure credential storage
- Remote Agents - Deploy and query lightweight monitoring agents
- Scheduled Automation - Run network scans automatically on a schedule
- Advanced Reporting - Export data in CSV and PDF formats
- Email Alerts - Receive automated reports via email
Who Should Use Tech Sentinel?
- Network Administrators - Monitor network health and troubleshoot connectivity issues
- System Engineers - Automate network audits and maintain device inventories
- IT Support Teams - Quickly diagnose network problems and verify connectivity
- MSPs - Monitor multiple client networks from a single dashboard
- Security Teams - Detect unauthorized devices and monitor network changes
2. System Requirements
Minimum Requirements:
- Operating System: Windows 10/11 (64-bit) or Linux
- Python: Python 3.8 or higher
- Memory: 4 GB RAM
- Disk Space: 100 MB for application and logs
- Network: Active network connection
Required Python Packages:
Optional Python Packages (Enhanced Features):
Recommended:
- Operating System: Windows 11 or Ubuntu 22.04+
- Memory: 8 GB RAM or higher
- Administrator Rights: Required for some features (raw sockets, scapy)
- Firewall Configuration: Allow ICMP (ping) and required ports
- ARP scanning with Scapy
- Raw socket operations
- Windows drive mapping
- System startup configuration
3. Installation
Step 1: Install Python
- Download Python 3.8+ from python.org
- During installation, check "Add Python to PATH"
- Complete the installation
Step 2: Install Required Packages
Windows:
Linux:
Step 3: Download Tech Sentinel
- Download
TechSentinel_v5.py - Place in a dedicated folder (e.g.,
C:\TechSentinel) - Configuration files will be created automatically on first run
Step 4: First Launch
Windows:
Linux:
Automatic Files Created:
network_vault.json- Configuration and saved profilestarget_history.json- Monitoring target historytechsentinel.log- Application log filetelemetry_logs/- CSV telemetry data directoryreports/- Exported reports directory
- Right-click shortcut β Properties
- Advanced β Check "Run as administrator"
4. Getting Started
Interface Overview
Tech Sentinel's interface is organized into logical sections for efficient network management.
Main Tabs:
- π Monitor - Real-time ping monitoring with graphs and statistics
- π Discovery - Network scanning and device discovery
- πΊοΈ Topology - Visual network topology mapping
- πΎ Drive Mapping - Network drive management with credentials
Monitor Tab Sections:
- Target Entry - Enter hostname or IP address to monitor
- Control Buttons:
- Start/Stop Monitoring
- Start/Stop CSV Logging
- Clear Output
- Real-Time Graphs:
- Latency over time
- Packet loss percentage
- Statistics Display:
- Current latency
- Average latency
- Packet loss
- Uptime
- Output Log - Detailed ping results and events
Network Tools Sidebar:
- Discovery - Launch network scans
- Port Scan - Check open ports
- SNMP - Query SNMP devices
- DNS - Perform DNS lookups
- Trace - Run traceroute
- Web Check - Test web connectivity
- Agent Query - Contact remote agents
- Batch Ping - Ping multiple targets
Quick Start Guide
Monitor a Host:
- Enter target (e.g.,
google.comor192.168.1.1) - Click START Monitor
- View real-time latency and packet loss
- Click STOP Monitor when done
Discover Network Devices:
- Switch to Discovery tab
- Enter network range (e.g.,
192.168.1.0/24) - Click START Discovery
- View discovered devices in the list
- Export results to CSV or PDF
Map a Network Drive:
- Switch to Drive Mapping tab
- Enter drive letter (e.g.,
Z:) - Enter network path (e.g.,
\\server\share) - Enter credentials (optional)
- Click Add & Map
5. Network Monitoring
Tech Sentinel provides comprehensive real-time network monitoring with visual graphs and detailed statistics.
Starting Monitoring:
- Enter target in the target field:
- Domain name:
google.com - IP address:
192.168.1.1 - Hostname:
server01
- Domain name:
- Click START Monitor
- Monitoring begins immediately with 0.5-second intervals
Understanding the Graphs:
Latency Graph (Top):
- X-Axis: Time (last 120 samples)
- Y-Axis: Response time in milliseconds
- Green Line: Normal latency
- Yellow Spikes: Elevated latency
- Red Spikes: High latency or timeouts
Packet Loss Graph (Bottom):
- X-Axis: Time (last 120 samples)
- Y-Axis: Packet loss percentage (0-100%)
- Shows: Failed ping attempts over time
Statistics Display:
| Metric | Description | Good Values |
|---|---|---|
| Current Latency | Most recent ping response time | < 50ms (LAN) < 100ms (WAN) |
| Average Latency | Mean response time over monitoring period | Consistent, low values |
| Packet Loss | Percentage of failed pings | 0% (acceptable: < 1%) |
| Uptime | Duration of continuous monitoring | N/A (informational) |
CSV Telemetry Logging:
Record all monitoring data to CSV for analysis:
- Start monitoring a target
- Click START CSV Log
- Data is saved to
telemetry_logs/[target]_[timestamp].csv - Click STOP CSV Log when done
CSV Format:
Advanced Options:
Sample Interval:
- Default: 0.5 seconds
- Adjustable via Settings
- Lower values = more data points, higher CPU usage
Buffer Length:
- Default: 120 samples displayed
- Configurable via Settings
- Determines graph time window
- Monitor critical servers 24/7 with CSV logging enabled
- Use long-term logs to establish baseline performance
- Compare latency during different times of day
- Look for patterns in packet loss (congestion, hardware issues)
- ICMP rate limiting on some firewalls
- Network bandwidth on metered connections
- Disk space usage with long CSV logs
6. Network Discovery
Discover all active devices on your network using various scanning methods.
Supported Input Formats:
CIDR Notation:
IP Ranges:
Single IP:
Running a Discovery Scan:
- Go to Discovery tab
- Enter target range in the input field
- Configure scan options:
- Use ARP Scan: Check for ARP-based discovery (requires scapy)
- Port Probe: Check for port scanning during discovery
- SNMP Query: Enable SNMP polling (requires pysnmp)
- Click START Discovery
- Monitor progress in the output log
- View results in the discovered devices list
Discovery Methods:
1. Ping Sweep (Default):
- Sends ICMP echo requests to each IP
- Fast and reliable
- Works on most networks
- May be blocked by firewalls
2. ARP Scan (Scapy Required):
- Uses ARP protocol to discover Layer 2 devices
- More reliable than ping on local networks
- Bypasses ICMP-blocking firewalls
- Limited to local subnet
- Retrieves MAC addresses
3. ARP Table Fallback:
- Reads system ARP cache
- No active scanning
- Only shows recently communicated devices
- Instant results
Discovered Device Information:
Each discovered device shows:
- IP Address - Network address
- Alive Status - Responded to ping
- Open Ports - Detected services (if port probing enabled)
- MAC Address - Hardware address (if ARP scan used)
- mDNS Name - Advertised hostname (if detected)
- SNMP Data - System name, description, uptime (if SNMP enabled)
Port Probing:
When enabled, scans these common ports:
- 22 - SSH
- 80 - HTTP
- 443 - HTTPS
- 3389 - RDP (Remote Desktop)
SNMP Discovery:
Configure SNMP settings:
- Go to Settings β SNMP
- Set Community String (default:
public) - Set SNMP Port (default:
161) - Set SNMP Version (default:
2c) - Enable SNMP Query in Discovery options
π Discovery Scope Examples:
- Home Network:
192.168.1.0/24(254 hosts) - Small Office:
10.0.0.0/24(254 hosts) - Subnet Range:
172.16.0.1-100(100 hosts) - Large Network:
10.0.0.0/16(65,534 hosts - may take hours)
- Start with small ranges (/28 or /27) to test
- Use ARP scan for local networks (faster and more reliable)
- Disable port probing for faster scans
- Schedule large scans during off-hours
- Export results regularly for comparison
7. Port Scanning
Identify open ports and services on network targets.
Running a Port Scan:
- Enter target IP or hostname
- Click Port Scan in the Network Tools section
- View results in the output log
Default Ports Scanned:
| Port | Service | Description |
|---|---|---|
| 22 | SSH | Secure Shell remote access |
| 80 | HTTP | Web server |
| 443 | HTTPS | Secure web server |
| 3389 | RDP | Windows Remote Desktop |
| 3306 | MySQL | MySQL database |
| 5432 | PostgreSQL | PostgreSQL database |
| 8080 | HTTP-Alt | Alternative web server |
Understanding Results:
OPEN:
Port is accepting connections. Service is running and accessible.
CLOSED:
Port is not listening. No service is running on this port.
FILTERED:
Firewall is blocking probe packets. Port state is unknown.
Web Quick Check:
Specifically tests HTTP/HTTPS connectivity:
- Enter target website or IP
- Click Web Check
- Tests ports 80 and 443
- Shows OPEN/CLOSED status
Custom Port Scanning:
For advanced users, modify the ports list in code:
- Only scan networks and systems you own or have permission to test
- Unauthorized port scanning may be illegal in your jurisdiction
- Some ISPs may flag or block port scanning activity
- Always obtain written authorization before scanning
- Verify firewall rules are working correctly
- Identify unauthorized services
- Troubleshoot service accessibility
- Audit network security posture
- Document available services
8. SNMP Monitoring
Query SNMP-enabled devices for detailed system information.
pysnmp package:
What is SNMP?
Simple Network Management Protocol (SNMP) is used to monitor and manage network devices like routers, switches, servers, printers, and more.
Configuring SNMP:
- Go to Settings β SNMP
- Set Community String:
- Default:
public(read-only) - Check your device documentation
- Default:
- Set SNMP Port:
- Default:
161 - Rarely needs changing
- Default:
- Set SNMP Version:
- Options:
1,2c,3 - Default:
2c(most common)
- Options:
Querying an SNMP Device:
- Enter target IP address
- Click SNMP in Network Tools
- View retrieved information in output log
Information Retrieved:
- sysName - Device hostname
- sysDescr - Device description and model
- sysUpTime - Time since last reboot
- sysLocation - Physical location (if configured)
- sysContact - Administrator contact (if configured)
Common SNMP-Enabled Devices:
- Network Equipment: Routers, switches, firewalls
- Servers: Windows Server, Linux servers
- Printers: Network printers and copiers
- NAS Devices: Network attached storage
- UPS Systems: Uninterruptible power supplies
- Environmental Monitors: Temperature, humidity sensors
SNMP During Discovery:
Enable SNMP queries during network discovery:
- Go to Discovery tab
- Check SNMP Query option
- Run discovery scan
- SNMP data appears for responsive devices
- Export results include SNMP columns
Troubleshooting SNMP:
No Response:
- Verify SNMP is enabled on target device
- Check community string is correct
- Ensure firewall allows UDP port 161
- Verify device IP address is correct
Access Denied:
- Community string may be wrong
- Device may require SNMPv3 with authentication
- Access control list may block your IP
- Change default community strings
- Use read-only community strings
- Implement SNMPv3 with authentication when possible
- Restrict SNMP access to management networks
- Monitor for unauthorized SNMP queries
9. Network Drive Mapping
Manage network drive mappings with secure credential storage.
π Secure Credential Storage:
Tech Sentinel uses Windows Credential Manager or system keyring to securely store passwords. Credentials are never saved in plain text.
Mapping a Network Drive:
- Go to Drive Mapping tab
- Enter drive letter (e.g.,
Z:) - Enter network path:
- UNC format:
\\server\share - IP format:
\\192.168.1.100\share
- UNC format:
- Enter username (if required):
- Domain:
DOMAIN\username - Local:
username
- Domain:
- Enter password (if required)
- Click Add & Map
Managing Saved Profiles:
All drive mappings are saved as profiles for quick remapping:
Saved Profile Features:
- Persistent Storage - Profiles survive application restarts
- One-Click Remapping - Quickly reconnect drives
- Credential Security - Passwords stored securely
- Status Display - See current connection state
Profile Actions:
- Map - Connect this drive mapping
- Disconnect - Disconnect this specific drive
- Delete - Remove profile from saved list
Bulk Operations:
Auto-Map All:
- Click Auto-Map All
- All saved profiles attempt to connect
- Perfect for startup or after network interruption
Disconnect All:
- Click Disconnect All
- Disconnects all network drives
- Useful before system maintenance
System Status Display:
The status panel shows:
- Currently Mapped Drives - Active connections
- Drive Letter β Network Path
- Connection State - Online/Offline indication
Startup Configuration:
Configure Tech Sentinel to run at Windows startup:
- Click Startup Config
- Choose Yes to enable
- Application will start with Windows
- Auto-maps all saved drives on startup
Common Network Paths:
| Type | Example Path |
|---|---|
| Windows Share | \\SERVER\Users |
| NAS Device | \\192.168.1.100\backup |
| DFS Path | \\domain.com\namespace\share |
| Hidden Share | \\SERVER\C$ |
- Drive mapping features require Windows
- Requires pywin32 package for full functionality
- Some features need Administrator rights
- Credentials stored in Windows Credential Manager
- Use consistent drive letters across all computers
- Document drive mappings for team members
- Test connectivity before saving profiles
- Use meaningful descriptions in profile names
- Periodically verify saved profiles still work
10. Remote Agent
Deploy lightweight monitoring agents to remote systems for advanced monitoring capabilities.
What is a Remote Agent?
A remote agent is Tech Sentinel running in "agent mode" on a remote system. It listens for queries and responds with system information.
Starting the Agent Server:
- Go to Settings β Agent
- Set Listen Port (default:
50050) - Click Start Agent Server
- Agent begins listening for queries
- Configure firewall to allow the port
Querying an Agent:
- Enter agent IP address in target field
- Click Agent Query in Network Tools
- View response in output log
Agent Commands:
PING:
- Simple connectivity test
- Returns timestamp
- Verifies agent is responsive
SYSINFO:
- Retrieves system information
- Platform details
- CPU usage percentage
- Memory usage percentage
ARP:
- Returns agent's ARP table
- Shows devices the agent sees
- Useful for network topology mapping
Example Query Response:
Deployment Scenarios:
Branch Office Monitoring:
- Deploy agent at remote location
- Query from central location
- Monitor without VPN overhead
DMZ Monitoring:
- Agent in DMZ network
- Query from management network
- Limited firewall rules required
Distributed Topology:
- Multiple agents across network
- Each reports local ARP table
- Build comprehensive network map
Security Considerations:
- Agent does not use authentication (MVP version)
- Anyone who can reach the port can query
- Use firewall rules to restrict access
- Do not expose agent port to internet
- Consider VPN or secure tunnel for remote access
Firewall Configuration:
Windows Firewall (Agent Server):
Linux UFW (Agent Server):
- Use non-standard ports for agents
- Limit agent access to management networks
- Document agent deployments and ports
- Regularly verify agent connectivity
- Consider implementing VPN for agent communication
11. Scheduled Scans
Automate network discovery scans to run at regular intervals.
Configuring the Scheduler:
- Go to Settings β Scheduler
- Set Scan Interval (minutes):
- Minimum: 5 minutes
- Recommended: 60 minutes (hourly)
- Typical: 1440 minutes (daily)
- Configure Scan Target:
- Enter network range to scan
- Example:
192.168.1.0/24
- Select Export Format:
- CSV
- PDF (requires reportlab)
- Both
- Click Enable Scheduled Scans
How It Works:
- Scheduler runs in background thread
- Waits for specified interval
- Executes network discovery scan
- Exports results to
reports/directory - Sends email notification (if configured)
- Repeats automatically
Report File Naming:
Email Notifications:
Receive automatic email when scans complete:
- Configure email settings (see Email Notifications section)
- In Scheduler settings, check Email on Complete
- Set Email From address
- Set Email To recipients (comma-separated)
- Reports will be emailed as attachments
Use Cases:
Daily Network Audit:
- Schedule: Every 24 hours (1440 minutes)
- Purpose: Track device additions/removals
- Export: CSV for historical comparison
Hourly Availability Check:
- Schedule: Every 60 minutes
- Purpose: Monitor critical devices
- Export: CSV with email alerts
Weekly Compliance Scan:
- Schedule: Every 10,080 minutes (7 days)
- Purpose: Generate compliance reports
- Export: PDF for documentation
Managing Scheduled Scans:
View Status:
- Check output log for "Scheduled scan triggered" messages
- Verify reports are being created in
reports/ - Confirm email delivery (if enabled)
Stop Scheduled Scans:
- Go to Settings β Scheduler
- Click Disable Scheduled Scans
- Background thread stops gracefully
Modify Schedule:
- Stop current schedule
- Update settings
- Re-enable scheduled scans
- Application must remain running for scheduled scans
- Computer must be powered on and network connected
- Large network scans can impact performance
- Monitor disk space usage for reports
- Schedule scans during off-peak hours
- Start with longer intervals and adjust as needed
- Regularly clean old report files
- Use email notifications for critical scans
- Consider running on dedicated monitoring system
12. Reports & Export
Export network discovery data in multiple formats for analysis and documentation.
Supported Export Formats:
CSV (Comma-Separated Values):
- Machine-readable format
- Open in Excel, Google Sheets, etc.
- Easy data analysis and filtering
- Historical trend analysis
- Always available
PDF (Portable Document Format):
- Professional presentation
- Print-friendly format
- Share with non-technical stakeholders
- Archive for compliance
- Requires
reportlabpackage
Exporting Discovery Results:
- Complete a network discovery scan
- View results in Discovery tab
- Click Export CSV or Export PDF
- Choose destination and filename
- Click Save
CSV Format Details:
Columns:
- timestamp_iso - ISO 8601 timestamp (UTC)
- ip - IP address
- alive - Responded to ping (True/False)
- ports - Comma-separated open ports
- snmp_sysName - SNMP system name
- snmp_sysDescr - SNMP system description
- snmp_sysUpTime - SNMP uptime
- mac - MAC address (if available)
- mdns_name - mDNS advertised name
Example CSV:
PDF Report Features:
- Header - Report title and generation timestamp
- Device Listings - One entry per discovered device
- Key Information - IP, ports, MAC, SNMP data
- Multi-Page Support - Automatically paginated
- Professional Format - Clean, organized layout
Report Locations:
- Manual Exports: User-selected location
- Scheduled Scans:
reports/directory - Telemetry CSVs:
telemetry_logs/directory
Analyzing Exported Data:
Excel/Google Sheets:
- Open CSV file
- Use filters to find specific devices
- Sort by IP, ports, or other columns
- Create pivot tables for analysis
- Generate charts and graphs
Command Line (Linux/Mac):
Python Analysis:
- Export regularly for historical comparison
- Use consistent file naming (include date)
- Archive reports in organized folders
- Keep CSV for analysis, PDF for presentation
- Document any unusual findings in reports
13. Email Notifications
Configure automatic email notifications for scheduled scans and alerts.
Configuring Email Settings:
- Go to Settings β Email
- Enter SMTP Server:
- Gmail:
smtp.gmail.com - Outlook:
smtp.office365.com - Others: Check provider documentation
- Gmail:
- Enter SMTP Port:
- 587 (STARTTLS) - Most common
- 465 (SSL/TLS) - Alternative
- 25 (Unencrypted) - Not recommended
- Enter Username (your email address)
- Enter Password or App Password
- Select Use SSL/TLS if using port 465
- Click Save Email Settings
- Click Test Email to verify
Gmail Configuration:
Gmail requires App Passwords for third-party applications:
- Enable 2-Step Verification on your Google Account
- Go to Security β App Passwords
- Generate new password for "Other"
- Name it "Tech Sentinel"
- Copy the 16-character password
- Use this password in Tech Sentinel (not your regular password)
Gmail Settings:
- Server:
smtp.gmail.com - Port:
587 - Username:
youremail@gmail.com - Password: App Password (not regular password)
- SSL/TLS: Unchecked (using STARTTLS on 587)
Outlook/Office 365 Configuration:
Settings:
- Server:
smtp.office365.com - Port:
587 - Username:
youremail@outlook.com - Password: Your account password
- SSL/TLS: Unchecked (using STARTTLS)
Credential Storage:
Email passwords are stored securely using:
- Windows: Windows Credential Manager (if pywin32 installed)
- Linux/Mac: System keyring (if keyring package installed)
- Passwords are never stored in plain text
Email Notifications Usage:
Scheduled Scan Notifications:
- Configure email settings (above)
- Go to Settings β Scheduler
- Check Email on Complete
- Enter Email From (your email)
- Enter Email To (recipients, comma-separated)
- Reports will be emailed automatically
Email Contents:
- Subject: "Tech Sentinel - Discovery Report"
- Body: Scan summary and timestamp
- Attachment: CSV or PDF report file
Troubleshooting Email:
Authentication Failed:
- Verify username and password are correct
- Gmail users: Use App Password, not regular password
- Check if 2FA is enabled (required for Gmail)
Connection Timeout:
- Verify SMTP server and port
- Check internet connectivity
- Firewall may be blocking SMTP ports
- Try different port (587 vs 465)
SSL/TLS Errors:
- For port 587: Uncheck "Use SSL/TLS"
- For port 465: Check "Use SSL/TLS"
- Update Python if SSL errors persist
- Use dedicated monitoring email account
- Set up email filters for automatic organization
- Send critical alerts to multiple recipients
- Keep email report size reasonable (< 10MB)
- Test email configuration before enabling scheduler
14. Telemetry Logging
Record detailed monitoring data to CSV files for long-term analysis.
What is Telemetry Logging?
Telemetry logging captures every ping result during monitoring sessions, creating a detailed historical record of network performance.
Starting Telemetry Logging:
- Start monitoring a target
- Click START CSV Log
- Logging begins immediately
- File created in
telemetry_logs/directory
File Naming Convention:
Format: [target]_[date]_[time].csv
CSV Format:
Columns:
- timestamp_iso - ISO 8601 timestamp (UTC)
- target - Monitored host
- latency_ms - Response time in milliseconds (or "TIMEOUT")
- packet_loss - 1 if timeout, 0 if successful
- status - "OK" or "FAIL"
Example Data:
Analyzing Telemetry Data:
Calculate Statistics:
- Average Latency: Mean of all successful pings
- Minimum Latency: Best case performance
- Maximum Latency: Worst case performance
- Packet Loss Rate: Percentage of timeouts
- Uptime Percentage: (100 - packet_loss)
Identify Patterns:
- Time-of-day performance variations
- Recurring outages
- Gradual degradation trends
- Correlation with other events
Create Visualizations:
- Import into Excel/Google Sheets
- Create line charts of latency over time
- Highlight timeout periods
- Compare multiple monitoring sessions
Storage Considerations:
File Size Estimates:
- 1 hour: ~50 KB (0.5s intervals)
- 24 hours: ~1.2 MB
- 1 week: ~8.4 MB
- 1 month: ~36 MB
Disk Space Management:
- Regularly archive old telemetry files
- Compress archives for long-term storage
- Set up automated cleanup of old files
- Monitor
telemetry_logs/directory size
Use Cases:
SLA Compliance:
- Document uptime percentage
- Prove service level achievement
- Identify SLA violations
Troubleshooting:
- Correlate issues with specific times
- Identify intermittent problems
- Establish baseline performance
Capacity Planning:
- Identify growth trends
- Predict performance degradation
- Justify infrastructure upgrades
- Enable logging for critical infrastructure
- Keep logs for at least 30 days
- Automate analysis with scripts
- Archive important monitoring sessions
- Use telemetry data for trend reports
15. Troubleshooting
Installation Issues:
Issue: "customtkinter module not found"
Solution:
Issue: "matplotlib backend error"
Solution (Linux):
Issue: Permission denied on Linux
Solution:
Monitoring Issues:
Issue: "Request timed out" constantly
Solutions:
- Verify target is online and reachable
- Check firewall allows ICMP (ping)
- Try pinging from command line to verify
- Some devices/firewalls block ICMP completely
Issue: High latency values
Causes:
- Network congestion
- Routing issues
- Distance/hop count
- Target system overload
Issue: Graphs not updating
Solutions:
- Stop and restart monitoring
- Check if application is frozen (CPU usage)
- Close and relaunch application
Discovery Issues:
Issue: No devices discovered
Solutions:
- Verify network range is correct
- Check if devices allow ping
- Try ARP scan instead of ping scan
- Increase timeout values
- Ensure network connectivity
Issue: Scapy features not available
Solution:
Issue: SNMP queries fail
Solutions:
- Verify SNMP is enabled on target
- Check community string is correct
- Ensure firewall allows UDP 161
- Install pysnmp:
pip install pysnmp
Drive Mapping Issues:
Issue: "Network path not found"
Solutions:
- Verify server/NAS is online
- Check network connectivity
- Ensure share exists and is accessible
- Try accessing via File Explorer first
Issue: "Access denied"
Solutions:
- Verify credentials are correct
- Check user has permissions on share
- Try domain format: DOMAIN\username
- Ensure password is current
Issue: Drive won't disconnect
Solutions:
- Close programs accessing the drive
- Use "Disconnect All" button
- Manually disconnect via File Explorer
- Restart computer if necessary
Email Issues:
Issue: Email test fails
Solutions:
- Verify SMTP server and port
- Check username/password
- Gmail: Must use App Password
- Check SSL/TLS setting matches port
- Verify internet connectivity
Issue: "Authentication failed"
Solutions:
- Gmail: Generate new App Password
- Outlook: Check account password
- Verify 2FA is properly configured
- Some providers require "less secure apps" enabled
Performance Issues:
Issue: Application is slow/unresponsive
Solutions:
- Reduce sample interval (increase from 0.5s)
- Reduce buffer length (less data points)
- Limit discovery scan range
- Close unused tabs
- Check system resources (CPU, RAM)
Issue: High CPU usage
Solutions:
- Increase monitoring interval
- Disable CSV logging when not needed
- Limit concurrent operations
- Close other applications
Log Files:
Check techsentinel.log for detailed error messages:
Getting Support:
If issues persist:
- Check
techsentinel.logfor errors - Note exact error message
- Document steps to reproduce
- Check Python and package versions
- Contact: www.regteches.com
16. Best Practices
Network Monitoring:
Establish Baselines:
- Monitor during normal conditions
- Record average latency values
- Document expected packet loss (if any)
- Identify peak usage times
Continuous Monitoring:
- Monitor critical infrastructure 24/7
- Enable CSV logging for important targets
- Set up automated alerting
- Review logs weekly for trends
Alert Thresholds:
- Critical: >5% packet loss
- Warning: >2x normal latency
- Info: >1.5x normal latency
Discovery & Documentation:
Regular Scans:
- Daily: Critical networks
- Weekly: Corporate networks
- Monthly: Full infrastructure audit
Maintain Inventory:
- Export discovery results regularly
- Compare with previous scans
- Investigate new/missing devices
- Update network documentation
Security Scanning:
- Look for unexpected open ports
- Detect unauthorized devices
- Monitor for topology changes
- Document all findings
Data Management:
File Organization:
Retention Schedule:
- Telemetry CSVs: 30-90 days
- Discovery Reports: 1 year
- Compliance Reports: 7+ years
- Log Files: 30 days
Backup Configuration:
- Regularly backup
network_vault.json - Document drive mapping profiles
- Export SNMP settings
- Save email configuration
Security:
Access Control:
- Limit who can run network scans
- Protect credential storage
- Use strong passwords for SNMP
- Restrict agent port access
Scan Authorization:
- Only scan networks you own/manage
- Obtain written permission for client networks
- Document authorized scan ranges
- Notify stakeholders before scanning
Credential Management:
- Use dedicated service accounts
- Rotate passwords regularly
- Never share credentials
- Document who has access
Performance Optimization:
Monitoring Intervals:
| Use Case | Interval |
|---|---|
| Real-time troubleshooting | 0.5 seconds |
| Active monitoring | 1-5 seconds |
| Background monitoring | 10-30 seconds |
| Long-term baseline | 60 seconds |
Discovery Optimization:
- Use ARP scan for local networks
- Increase timeout for slow networks
- Disable unnecessary features (port probe, SNMP)
- Schedule large scans overnight
Reporting:
Report Frequency:
- Daily: Operational metrics
- Weekly: Trend analysis
- Monthly: Executive summary
- Quarterly: Strategic planning
Report Contents:
- Current network inventory
- Availability statistics
- Performance trends
- Incidents and resolutions
- Recommended actions
- Monitor proactively: Don't wait for problems
- Document everything: Notes are invaluable later
- Automate repetitive tasks: Use scheduling
- Review regularly: Analyze trends weekly
- Keep learning: Networks evolve, so should you