Documentation  /  Getting started

Site collectors

A collector is the platform's presence on a client network. It polls what has no agent and forwards what does.

link up link drops buffering to disk buffer at capacity oldest discarded, and it says so link returns backfill in order BUFFER DEPTH a gap in the data is recorded as a gap, never rendered as a quiet period

What a collector does

  • SNMP polling for switches, firewalls, UPS, printers and anything else that speaks it
  • Syslog reception
  • Network discovery sweeps
  • Relay for agents that cannot reach the platform directly
  • Local buffering when the link to the platform is down

Sizing

EstateCollectorNotes
Up to 250 assets2 vCPU, 4 GBA small VM or a spare workstation
250–1,0004 vCPU, 8 GB
1,000+4 vCPU, 8 GB eachTwo collectors, split by subnet, not one larger one

Buffering, and what happens when the link drops

A collector buffers locally and forwards when the link returns. Nothing is lost to a transient outage.

If the buffer fills, the collector reports buffer exhausted and names what it dropped. It never silently discards and it never reports a clean window it did not observe.

Health

Every collector reports last contact, buffer depth, poll success rate per target class, and what it failed to reach. A collector that stops reporting raises a finding with a named owner — not a grey icon.

← Deploying agents  ·  The autonomy ladder →

Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.

Thirty days · read-only · no card

Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.

Start an evaluation