24/7 computer monitoring —
what we actually watch, and when we call you

Your computer sends a health snapshot every quarter hour, the server compares it against fixed thresholds and against its own history, and a person decides what to do about it. Here is the whole mechanism.

Updated 24 July 2026 · by Oshri Pinhas, XIT · 9 min read
24/7 computer monitoring: what we watch, when we call | XIT

The short answer

XIT's 24/7 monitoring is a small agent on your computer that sends a health snapshot every 15 minutes: disk space, memory, CPU, crashes, antivirus, firewall, pending updates, drive SMART status and network quality. The server checks each snapshot against fixed thresholds — under 20% free disk, over 80% memory, over 150 ms latency — and keeps 60 days of history so it can spot trends a single reading cannot show. A machine silent for 1 hour is a warning; 24 hours is critical. When a critical alert fires, a human technician reviews it and decides whether to call you.

What is in the snapshot your computer sends every 15 minutes?

A small agent runs on the machine as a scheduled task. Every 15 minutes it wakes up for a few seconds, reads the state of the system, posts it to XIT's server and exits. That is the entire footprint: no open window, no heavy background service, and the collection itself takes seconds.

A single snapshot carries, among other things:

What is not in there matters just as much. The agent collects system and configuration state, not content. It does not read files, documents, photos, email or browsing history. The full breakdown of what is and is not collected is on what the report includes.

Why does one hour of silence already raise an alert?

A monitoring system that only alerts on what it can see misses the one case that matters most: a computer that stopped talking. So silence is treated as data.

At a 15-minute interval, a healthy machine sends four snapshots an hour. One missed report is noise — a dropped connection, a machine that went to sleep. Four missed in a row is a signal. That is why 1 hour without a report marks the machine as a warning, and 24 hours marks it as critical.

There are three explanations: the computer is off, it is disconnected, or the agent itself stopped running. The third is the real reason the alert exists. An agent that dies quietly turns the whole system into theatre — the dashboard stays green because no new data arrived, not because everything is fine.

An offline warning on a laptop that is shut down at night is expected, and whoever reviews it closes it without picking up the phone. The same warning on a machine that should run around the clock is a different story. The difference is not in the number; it is in the context.

What is the difference between a threshold alert and a trend alert?

The engine produces two kinds of alerts, and they work in completely different ways.

Threshold alerts — decided from one reading

Every incoming snapshot is measured against fixed numbers. Under 20% free disk space is a warning and under 10% is critical. Over 80% memory use is a warning and over 90% is critical. The same applies to latency above 150 ms, packet loss at 5% or more (20% is critical), WiFi signal below 30%, antivirus signatures older than 72 hours, battery wear of 40% or more, and more than 60 days without a single update installed. All of these are settled by the latest report and need no history at all.

Trend alerts — impossible without history

Snapshot history is kept for 60 days, and that is what makes it possible to see things one measurement never could. The trend maths runs over the last three days, or the last 30 readings if the machine reported less often:

That distinction is the entire reason to keep history. One reading can tell you a disk is at 18% free. Only a series can tell you whether it has been sitting there peacefully for two years, or fell from 60% in the last three weeks.

The full alert catalogue: 26 types across six areas

The engine knows 26 alert types. They are grouped here into the same six areas your plain-language report is organised by.

AlertWhen it firesLevel
Security and protection
No active antivirusReal-time protection is off and no other security product covers for itCritical
Threat detectedThe antivirus reports an active threat on the machineCritical
Pending security updatesOne uninstalled update is a warning; 10 or more is criticalWarning / critical
Stale AV signaturesVirus definitions older than 72 hoursWarning
Firewall offAny firewall profile (domain, private or public) is disabledWarning
RDP without NLARemote Desktop is open without Network Level AuthenticationWarning
Certificate expiringA certificate expires within 30 days; within 7 days is criticalWarning / critical
Hardware
SMART failureThe drive itself reports an unhealthy state — a pre-failure warningCritical
Disk filling upUnder 20% free on any drive; under 10% is criticalWarning / critical
Battery wearThe battery has lost 40% or more of its original capacityWarning
Drivers in errorA hardware device is registered as faulty (printer, network card, audio)Warning
Stability and crashes
Machine offlineNo report for 1 hour; over 24 hours is criticalWarning / critical
Blue screenOne or more BSOD crashes in the last 30 daysWarning
Unexpected shutdownThe machine booted without a clean shutdown, even once in 30 daysWarning
System error flood50 or more errors in the event log within 24 hoursWarning
Reboot churnThree or more restarts within seven daysWarning
Performance
Memory pressureOver 80% RAM in use; over 90% is criticalWarning / critical
Sustained CPU loadAn average above 70% across at least five readingsWarning
Rising memory trendGrowth above 1.5% per day while already above 60%Warning
Disk fill forecastUnder 60 days to 3% free at the current rate; under a week is criticalWarning / critical
Maintenance and updates
Patches staleNo Windows update installed for more than 60 daysWarning
Windows not activatedThe OS reports a licence state other than activatedWarning
Never restartedMore than 30 days of uninterrupted uptimeInfo
Network and internet
Packet loss5% or more of packets dropped; 20% or more is criticalWarning / critical
High latencyRound-trip time above 150 msWarning
Weak WiFiSignal strength below 30%Warning

Every alert is shown with a plain-language sentence explaining what it means in practice, not just what was measured. The detail behind each group lives on the security check, the hardware check, crash analysis, the network check and updates and maintenance.

What happens after an alert fires?

The alert is computed on the server the moment the snapshot lands. From there it stops being software.

  1. Only a new critical alert pushes a notification to the technician's phone. Warning-level findings stay on the dashboard and get read in rotation. That is deliberate. A notification stream nobody reads is worse than none, because the one that mattered drowns in it.
  2. A person opens the machine and reads the alert in context. What else fired at the same time, what the 60-day history says, what the event log recorded around that hour. Plenty of warnings die here, correctly — one blue screen after a power cut, a driver error on an unplugged printer.
  3. If it matters, we contact you. In language that says what happened, what it is likely to cost you and what can be done, rather than event IDs and bugcheck codes.
  4. If there is something you can do yourself, we can push a short message to your screen. Those pop-ups are configured per alert type, with a cooldown so a flapping alert cannot spam the person at the keyboard.
Restarts are recommended, never forced. Some fixes — applying pending updates, running a memory test — need a reboot. We tell you it is needed, explain why, and you choose when. We will not restart a machine out from under someone mid-task.

The value is not the dashboard. It is that someone looks at it

You can download a free monitoring tool this afternoon and get attractive graphs. What happens next is predictable: most people open the dashboard twice in the first week and then never again. An alert about 12% free disk space is worth precisely nothing if nobody reads it for three weeks.

The less obvious half is that knowing what to ignore is most of the job. The 20%-free threshold fires on a machine that has sat at 19% for two years and is perfectly happy, and fires identically on a machine that fell from 60% to 19% in three weeks and is about to stop working. Same number, two different situations. The history separates them and a person decides what to do.

What you pay for is not the data collection. It is the attention. The tooling is what lets one technician keep track of many machines without sitting in front of each one.

What monitoring does not do

What does it cost?

There are two packages, and the difference between them is exactly the argument on this page.

One small-business computer stuck for two days — a lost file, a customer left waiting, an evening with a technician — costs more than a year of monitoring. All the system really does is move the moment you find out from after to before. Details are on the pricing page.

FAQ

How often does the computer report?

Every 15 minutes. The agent runs as a scheduled task, reads system state and posts it to the server. A machine that has not reported for 1 hour is flagged as a warning, and a machine silent for 24 hours is flagged as critical.

Why keep 60 days of history?

Because a single reading cannot show a trend. Sixty days of snapshots are what make it possible to forecast when a disk will fill up, to spot memory use climbing more than 1.5% per day, and to tell a momentary CPU spike apart from a sustained average above 70%.

Can you see my files?

No. The agent collects system and configuration state only: disk space, memory, antivirus and firewall status, pending updates, system errors and network quality. It does not read or upload files, documents, photos, email or browsing history.

What happens when my computer is switched off overnight?

An offline warning fires after an hour, and that is fine. Whoever reviews the dashboard sees a machine that is normally off at night, and closes the warning without calling. Supplying that context is exactly what a person adds to a number.

Will you restart my computer remotely?

No. Some fixes do need a reboot, such as applying pending updates or running a memory test. In those cases we say so, explain why, and the customer picks the moment. Restarts are recommended and never forced.

How many alert types are there?

Twenty-six, grouped into six areas: security and protection, hardware, stability and crashes, performance, maintenance and updates, and network and internet. Some are threshold alerts decided from one reading, and some are trend alerts that require history.

Does monitoring replace antivirus or backup?

No. Monitoring reports on the antivirus already installed, including whether real-time protection is on, whether signatures are current and whether threats were found, but it does not scan or remove. It also does not back up files; it warns before a drive fails so there is time to back up.

Want someone actually watching your computer?

Installation takes minutes, the first report arrives within a quarter of an hour, and you get a full picture on day one. From $5 per month, per computer.

Get in touch

Read next

⚡ POWERED BY INSTASITE
This site was built with InstaSite.ai
Build a high-quality business website with AI in 60 seconds — totally free · built-in SEO · your own domain
Build a free site →
instasite.store · Automatic AI website builder for small businesses