Elisk

Overseer security monitoring

Security monitoring for the systems you actually operate.

Overseer gives small and growing businesses an account-scoped view of equipment, networks, telemetry, endpoint posture, software policy, and alerts. It is already used in production for Elisk clients, with a public subscription SaaS opening planned for early 2027.

Ask about Overseer
Client production Public SaaS target: early 2027
Overseer account monitoring overview with node health, active alerts, and resource status

Monitoring with intent

Collect the signal needed for the risk, not every byte available.

Overseer is designed around scoped collection. Some environments only need basic resource telemetry. Others need endpoint inventory, active sessions, exposed ports, software policy, or network-edge visibility. The collection profile should match the operational question being answered.

Telemetry

CPU, memory, disk, and network health.

Time-series metrics are kept outside PostgreSQL and queried with tenant-safe account and node labels.

Endpoint inventory

Processes, ports, packages, services, and sessions.

Linux inventory is normalized into latest-state views, with searchable full process, software, and service pages when deeper review is needed.

Policy

Allowed, mandatory, forbidden, and unknown software.

Software policies and allow lists turn inventory into reviewable findings and durable alerts.

Network edge

Gateway and OPNsense-based monitoring.

Network visibility can be built through Elisk Gateway hardware or prepared OPNsense routers, tying edge state back to monitored systems.

Collection model

Managed client first. Open tooling where it fits.

Overseer is built around the managed Elisk Overseer Client for production deployments, while keeping support for established open-source telemetry and inventory components. Telegraf handles numeric resource telemetry, osquery reports host state, and Vector ships bounded inventory batches when that depth is enabled.

Basic monitoringResource telemetry and freshness
Endpoint visibilityInventory, sessions, ports, posture
Network visibilityGateway hardware or OPNsense edge data
Data retentionCustomer-defined, 30 days by default
Overseer equipment posture view with collector status, firewall state, listening ports, and observations
Overseer live node monitoring view with endpoint inventory, resource gauges, throughput, and CPU history

Operator view

Readable state for live review and later investigation.

Overseer keeps the live view focused on what an operator can act on: telemetry freshness, resource pressure, open alerts, exposed ports, current sessions, relevant processes, installed software, and services. Equipment records can be enriched from trusted observations without overwriting human ownership data silently.

Alerts with lifecycle

Open, acknowledged, and resolved states preserve the review trail instead of treating alerts as disposable dashboard noise.

Tenant-safe evidence

Account and node ownership are derived from trusted records, not from client-submitted labels or hidden form state.

Access and retention

Production access now. Public subscription later.

Overseer is currently available to Elisk clients as part of managed security and infrastructure work. Public subscription access is planned for early 2027, after the operating model, onboarding, and retention controls are ready for self-service use.

Data is retained for the period the customer needs. The default operational window is 30 days, with retention adjusted for monitoring goals, risk posture, storage cost, and compliance expectations.

Start with visibility

Need to understand what your systems are doing?

Tell us what you operate, what you need to monitor, and how much endpoint or network detail is appropriate. We will scope the collection path around the risk instead of defaulting to maximum data capture.