HTTPDwatch

Self-hosted edition

Installing HTTPDwatch on your server

The self-hosted edition runs entirely on your own infrastructure: the HTTPDwatch server (dashboard, alerting, license) on one machine, and a small agent on each Apache httpd server. Both come as RPM packages that carry everything they need — no Node.js, Java or other runtime to install.

Check System requirements first. In short: RHEL, Oracle Linux, Rocky or AlmaLinux 8 or 9 on x86_64, 1 GB free memory, and outbound HTTPS to the license server.

1. Install the server package

sudo dnf install ./httpd-monitor-*.x86_64.rpm

The package creates a httpd-monitor system account, starts the httpd-monitor service, enables it at boot, and prints the address to open and a setup code:

  HTTPDwatch is installed and running.
  Finish setup in your browser:   http://your-server:3100/httpdmon/setup
  Setup code:                     7Q4K-M2XD

Keep the setup code — the browser asks for it once, so only the person who installed the server can finish the setup. If it scrolled away:

sudo journalctl -u httpd-monitor | grep "Setup code"

2. Open the port

The server listens on TCP 3100. Open it for your users' browsers and for the agents:

sudo firewall-cmd --add-port=3100/tcp --permanent && sudo firewall-cmd --reload

Without HTTPS, passwords, session cookies and everything on the dashboard travel across your network unencrypted, and HTTPDwatch shows a warning while it is used that way. Put the server behind your existing reverse proxy (nginx, Apache httpd or a load balancer) with a certificate, for example with nginx:

server {
    listen 443 ssl;
    server_name monitor.example.com;
    ssl_certificate     /etc/pki/tls/certs/monitor.crt;
    ssl_certificate_key /etc/pki/tls/private/monitor.key;

    location /httpdmon/ {
        proxy_pass         http://127.0.0.1:3100;
        proxy_http_version 1.1;
        proxy_set_header   Host              $host;
        proxy_set_header   X-Real-IP         $remote_addr;
        proxy_set_header   X-Forwarded-For   $proxy_add_x_forwarded_for;
        proxy_set_header   X-Forwarded-Proto $scheme;
        # live updates and agents use WebSockets
        proxy_set_header   Upgrade           $http_upgrade;
        proxy_set_header   Connection        "upgrade";
        proxy_read_timeout 3600s;
    }
}

Then make the server listen only to the proxy — set the listen address to 127.0.0.1 in Settings (Server) and restart — and close port 3100 again in the firewall. Agents connect through the proxy too (https:// / wss://).

With SELinux enforcing (the default — leave it on), allow the proxy to connect to HTTPDwatch once; the installer reminds you if it is needed:

sudo setsebool -P httpd_can_network_connect 1

Nothing else about HTTPDwatch needs SELinux changes — see System requirements.

Changing the port

Admins change the port and listen address in Settings (Server card). Save, then Restart now to apply: the dashboard comes back on the new port by itself. Ports from 1024 to 65535 are allowed (put a reverse proxy in front for 443), and the port must be free.

  • Agents follow automatically. Connected agents that reach the server directly on the old port are told the new address just before the restart, reconnect there, and go back to the old one if it doesn't answer within 5 minutes. Agents that come through a reverse proxy keep their address — point the proxy at the new port instead. Agents that are offline at the time, or older versions, need SERVER_URL changed by hand.
  • Open the new port in the firewall first, and close the old one after.

Settings changed in the dashboard are saved under /var/lib/httpd-monitor and take precedence over /etc/httpd-monitor/httpd-monitor.env; you can still edit that file and run sudo systemctl restart httpd-monitor instead.

3. Finish setup in the browser

Open http://your-server:3100/httpdmon/setup and continue with First-time setup and your license.

Where things are

Program /usr/bin/httpd-monitor (one self-contained file)
Settings /etc/httpd-monitor/httpd-monitor.env (port, base path, log level)
Data /var/lib/httpd-monitor — users, license, instances, history
Logs journalctl -u httpd-monitor
Service `systemctl status