Skip to content

Configuration Guardian — It Watches TrackMe Itself

A modular framework that proactively detects misconfigurations and must-know conditions across your TrackMe deployment — and turns them into actionable, self-healing alerts you can snooze, tune, act on, and be emailed about.

Key Capabilities

Proactive, Self-Healing Detection

Checks run continuously in the background — service account permissions, remote account connectivity and token expiration, backup freshness, AI provider reachability, degraded tenants, stale maintenance windows, and more. Every alert carries remediation guidance and clears itself the moment the condition heals.

A Full Check Catalog

See every check the Guardian can fire — including the currently quiet ones — so you can discover what's monitored before anything goes wrong. Enable or disable per check, tune its thresholds, run it on demand, and read its last-run status.

Snooze with Judgement

Silence a known condition for 1, 7 or 30 days with an optional reason — detection never stops underneath, and a condition that escalates to critical breaks through the snooze. When it expires, the alert simply returns if it still holds.

A Reviewed Severity Model

Warning → critical escalation ladders with a tunable persistence window: transient conditions start as warnings and escalate automatically only once they've genuinely persisted. Every transition is auditable.

Email Notifications

Be notified on genuine lifecycle transitions only — a new alert, an escalation to critical, or a resolution — as branded HTML emails with remediation guidance. Snoozed alerts never notify, and delivery is fail-open so email problems can never affect detection.

Ask AI, and a Full Audit Trail

Open the AI Assistant pre-contextualized on the Guardian and its alerts, directly from the page. Every state transition is written to the audit index, and all state lives in inspectable KV Store collections — you can always answer what changed, and when.

Configuration Guardian — It Watches TrackMe Itself — 1
Configuration Guardian — It Watches TrackMe Itself — 2
Configuration Guardian — It Watches TrackMe Itself — 3

Deep Dive

Explore the key aspects of Configuration Guardian in detail.

Active Alerts

Findings reach you — even when nobody is looking at the UI

TrackMe watches your data. The Configuration Guardian watches TrackMe — proactively detecting misconfigurations and must-know conditions across your deployment, and turning them into actionable, self-healing alerts. A service account missing a capability, a remote account whose token is about to expire, a backup that has gone stale, an AI provider that stopped answering, a tenant whose operations have degraded, a maintenance window left open past its end — the Guardian surfaces each one with a plain-language message, remediation steps, and a structured list of recommended actions.

And because every check is self-healing, the moment the underlying condition is resolved the next detection cycle clears the alert automatically. No manual housekeeping, no stale warnings — findings reach you when they matter and clear themselves when the condition heals.

A full management experience

TrackMe 2.4.7 turns the Guardian from a background safeguard into a first-class, manageable surface — a dedicated page organized in three tabs, with a KPI strip summarizing critical, warning and info counts, active and snoozed alerts, and the number of monitored checks.

📥
Active Alerts
The inbox — every active alert, grouped by check and filterable by severity, tenant and scope, each with its message, remediation and one-click actions.
🗂️
Check Catalog
Every check the Guardian can fire, quiet ones included — enable or disable, tune thresholds, run on demand, and see when each last ran.
📈
Activity Timeline
Created, escalated and cleared transitions over time — answer "which check is noisiest?" and "when did this first appear?" from the audit trail.

Snooze, clear, or disable — you decide the noise

Not every finding needs to shout at you forever. The Guardian gives you three distinct controls, so you can acknowledge what you know without going blind to what you don’t:

  • Clear now re-evaluates immediately — a temporary acknowledgement that comes straight back on the next cycle if the condition still holds.
  • Snooze hides a known condition for 1, 7 or 30 days while detection keeps running underneath — and a warning that escalates to critical breaks through the snooze, because you silenced a warning, not an active degradation.
  • Disable a check entirely from the catalog when it doesn’t apply to your deployment — its active alerts clear, and re-enabling resumes scanning automatically.

Snoozing is a read-time overlay, never a blindfold: the check keeps detecting, the record keeps updating, and the alert returns automatically when the snooze expires if the condition is still true.

It emails you — on transitions that matter

Configure a delivery account and recipients once, and the Guardian notifies you by branded HTML email on genuine lifecycle transitions: a new alert, an escalation to critical, or a resolution when the condition self-heals. Set a minimum severity so informational notices never reach your inbox, and pick exactly which of the three events you care about.

🔔Transitions only — routine re-detections never notify
🤫Snoozed alerts never email — you muted them
Resolved means self-healed — admin clears stay silent
🛡️Fail-open delivery — email can never affect detection

For teams routing through their own pipelines, an opt-in saved search additionally fires on any alert that becomes critical — attach any Splunk alert action you already use (email, ITSM, Slack, PagerDuty), with per-alert throttling so a persistent condition notifies once, not every cycle.

Ask AI — remediation, in context

When the AI Assistant is configured, Ask AI opens a chat pre-loaded with the Guardian’s live state: it sees the active alerts and their recommended actions, and walks you through remediation and verification. The same Guardian context reaches the Virtual Tenants and Tenant Home assistants too, so a question like “why aren’t my entities updating?” is answered by cross-checking the relevant checks first.

Observable and accountable by design

Every Guardian state transition — created, escalated, cleared, snoozed, unsnoozed, and every catalog change — is written to the TrackMe audit index under a dedicated sourcetype, so you always have a timeline of what changed and when. All state lives in inspectable KV Store collections, and on-demand runs are dispatched as a Splunk search job so even a fleet-wide scan can never be interrupted by a web-proxy timeout. The complete REST surface is self-documented in TrackMe’s built-in API reference.

Available to every deployment — no AI required

The Configuration Guardian management experience is available to every TrackMe deployment — the detection, the catalog, snooze, tuning, email notifications and the audit trail all work with no AI provider configured. The optional Ask AI button is the only part that needs the AI Assistant; the Guardian itself simply watches your deployment, and tells you — clearly, and only when it matters.

Ready to get started?

Request a free 90-day trial with all features enabled. No restrictions.