Monitoring and alerting
The moment a problem appears, you'll know.
Alerts fire within seconds. Routine fixes can start before anyone opens the queue.
Monitor each device for the job it does.
Tags keep the right checks attached as the fleet changes.
Resources
Catch sustained CPU and memory pressure without turning every brief spike into an alert.
Disk
See low space, overloaded storage, slow response, growing queues, and failing SMART health.
Network
Track device reachability, path latency, link saturation, and unexpected outbound traffic.
Security
Flag missing encryption, unhealthy antivirus, repeated login failures, and local account drift.
System
Watch required apps, named processes and services, Windows events, and overdue reboots.
Custom
Run a PowerShell, Bash, or Python script and alert when its numeric or text output matches your rule.
“Level gives us the power for only a few technicians to manage hundreds of endpoints from anywhere in the world with real-time insight.”
Justin Hayes
CEO · Bascom Logistics
Catch drift before it becomes an incident.
The useful signals are often changes in state, not another percentage on a dashboard.
Catch account drift.
Know when an unauthorized local user appears or a required account disappears.
Keep required software in place.
Alert when an application is installed where it should not be or missing where it belongs.
Spot repeated access attempts.
Set the count and time window across Windows, macOS, and Linux, for all users or admins.
Verify encryption across every OS.
Check BitLocker, FileVault, or LUKS automatically, with no platform-specific setup.
Replace a drive before it dies.
Alert the moment a drive reports a failing SMART self-assessment.
Restart a service when it stops.
Open an alert when service state changes and optionally restart it automatically.
Monitoring that earns its place in the stack.
Two operators on flexible checks, script monitors, and policies that scale with the fleet.
pjoerk
r/msp, Reddit
“We switched to Level in February from another RMM and are super happy. The whole platform is modern, fast, offers a ton of advanced features, and is very actively developed. Monitoring is super flexible because it allows us to use our own scripts as monitors and do things based on the results. The API is quite advanced and is extended constantly.”
kimsvane
r/msp, Reddit
“We came from Nagios and wanted to improve the whole environment with automations and script checks. Level’s script checks solved so many different checks that the other systems we looked at would require much more work. Onboarding around 150 endpoints was straightforward and easy. The tag-based policy and automations are well built. We monitor many APIs and specific services, and Level hits the spot for us.”
Every alert should arrive with a next step.
Filter the noise, preserve the evidence, and act while the problem is still live.
Hold for the duration you set.
A threshold must stay breached before Level opens the alert, so one-off spikes stay quiet.
Target the role with tags.
Apply a tag and every matching policy starts monitoring that device immediately.
Capture the problem. Start the fix.
Keep the trigger-time payload and run a remediation automation on the affected device.
Import a monitor policy. Make it yours.
Assign target tags, then tune its thresholds and severity for your fleet.
Before you turn on the first policy.
How targeting, noise control, remediation, and cross-platform coverage work.
Can a monitor start an automation?
Yes. Choose a remediation automation on the monitor. When the alert opens, Level runs it on the affected device.
Do monitors work on Windows, macOS, and Linux?
Most do. Antivirus and Event log monitors are Windows only. Encryption status checks BitLocker, FileVault, or LUKS for the device operating system.
How do I stop one noisy device from weakening the whole policy?
Disable that monitor only on the affected device. Use Maintenance Mode instead when you need temporary suppression during planned work.
How do devices get monitors?
Monitor policies target tags. Apply a matching tag and the policy starts monitoring that device immediately. Remove the tag and the policy stops.
How does Level keep brief spikes from creating noise?
Set a breach duration on the monitor. The condition must remain beyond the threshold for that long before an alert opens. Auto-resolve can close it when conditions recover.
What does an alert preserve for troubleshooting?
The alert captures monitor-specific evidence from the trigger, such as top CPU or memory processes, script output, or matching Windows event details. Once resolved, the final state is frozen for review.
Can I write my own check?
Yes. A Run script monitor executes PowerShell, Bash, or Python on a schedule and evaluates the returned number or text against the condition you define.
See the problem while it is still happening.
Import a monitor policy, target it with tags, and let Level preserve the evidence when something breaks.


