Overview
The Overview page answers "is anything wrong?" at a glance. It is eight tiles, each covering one question, and it updates live.
Fleet health
Counts across four states:
| State | Meaning |
|---|---|
| Online | Connected right now |
| Offline | Enrolled, has reported before, not connected now |
| No metrics | Enrolled and connected, but has never sent telemetry |
| Not enrolled | A record exists, but the machine never finished enrolling |
The last two look similar and are not. No metrics is a machine that is talking but not reporting. Not enrolled never completed setup.
Went dark
Machines that were reporting and stopped, most recent first. This is where you look after fleet health tells you the offline count went up.
A machine appears here on disconnection, not on silence. A machine nobody is looking at is silent by design and does not go dark. See Machine shows offline.
Session posture
Who is logged in across the fleet, how many of those sessions are remote, and which have been idle long enough to be worth noticing.
Session counts are collected on their own timer, roughly every thirty seconds, and are not gated on whether you are looking at the machine. The count stays accurate for machines you never scroll to.
Sessions are collected on Linux and Windows. macOS machines report none.
Composition
What the fleet is made of, as stacked bars: operating system family, CPU architecture, and virtual versus physical.
Useful for scoping work — how many machines a change actually touches.
Security events
Refused connections, duplicate machines, and mismatched account claims, newest first. See Security events for what each kind means.
Empty is the expected state.
Events appear here and nowhere else. Watchtower does not email or notify you when one is recorded, so this tile is only useful if somebody looks at it.
Uptime
How long the online machines have been up, shortest first, so recent restarts surface. A machine that restarted when you did not expect it to is the thing this tile is for.
Derived from boot time reported by the agent.
Availability
A seven-day by twenty-four-hour grid of fleet reachability — one cell per hour, shaded by how much of the fleet was reachable. Patterns are the point: a column that is dark every day at the same hour is a scheduled job or a nightly reboot, not a coincidence.
Built from hourly rollups, so it fills in over time. A new account shows an empty grid until it has a day of history.
Storage pressure
Volumes running out of space, fullest first. Sorted by how full, not how large, so a nearly full small volume outranks a half-empty big one.
Disk data comes from the real host. A machine that has never reported telemetry does not appear.
Live updates
The page updates as telemetry arrives — no refresh needed. Counts derived from presence, such as fleet health and session posture, update immediately on connect and disconnect.
There is no "see all" link from a tile. Use Machines and filter.