For network & systems engineers

A syslog, flow and SNMP trap collector that goes where you go.

MobiObs turns a mobile device, whether Android, iOS, a tablet or a laptop, into a portable observability stack. It receives Syslog (RFC 3164/5424, CEF, LEEF), Windows Events via NXLog, NetFlow v5/v9, IPFIX, sFlow v5 and SNMP traps v1/v2c/v3, stores them on the device and shows them live on the device and in any browser on the network.

Coming soon to Google Play and the App Store. Android first, then iOS, tablets and desktop.

  • Syslog 3164/5424
  • CEF · LEEF
  • Windows · NXLog
  • NetFlow v5/v9
  • IPFIX
  • sFlow v5
  • SNMP v1/v2c/v3
MobiObs Overview on a mobile device: live events and flows per second, ingest rate, sources, store size, collectors and an event timeline.
Product

The same dashboards in the app and in the browser

The device serves a full web UI over HTTP or HTTPS, so a laptop, a NOC screen or a colleague's tablet can follow the capture while the mobile device stays with the equipment. These screenshots are from a MobiObs engine receiving test traffic.

MobiObs Overview dashboard: events and flows per second, ingest rate, sources, store size, collectors, an event timeline by kind, a severity breakdown, top hosts, top apps, top talkers and protocols.
Overview. Rates, totals, a per-kind timeline, severity split, top hosts and apps, top talkers and protocol mix for the selected window.
Logs view: a live table of syslog messages with time, severity, host, app, facility and message, and filters for host, app, source IP, facility and severity.
Logs. Live tail with full-text search and filters by host, app, source IP, facility and severity.
Flows view: a traffic chart in bytes over time with top talkers, top destinations, top ports and a protocol split.
Flows. NetFlow, IPFIX and sFlow traffic over time, top talkers, destinations, ports and protocols.
Windows Events view: a table of events with level, event ID, channel, provider, computer and message, such as 4625 failed logon and 4740 account lockout.
Windows Events. Security, System and Application events from NXLog with event ID, channel, provider and computer.
SNMP Traps view: top traps such as authenticationFailure, linkDown and linkUp, top agents, and a table of traps with security level and varbinds.
SNMP Traps. Top traps and agents, decoded varbinds and the SNMP version and security level of each trap.
Network view: the collector addresses to point equipment at for syslog, NetFlow, sFlow and SNMP traps, a sender configuration snippet, and Wi-Fi context such as gateway, SSID, signal and channel.
Network. The exact addresses to point equipment at, a ready-to-paste sender snippet and the Wi-Fi context the device is on.
How it works

Three steps, no server to build

There is no cloud account, agent rollout or collector VM. The device you carry is the collector.

  1. Install and start collecting

    Install MobiObs and open it. The collectors start listening on the device's network interfaces. On Android they run as a foreground service, so collection continues with the screen off.

  2. Point your equipment at the device

    Send logs, flows and traps to the device's IP address. The Network screen lists each address and port.

    # defaults, all configurable
    udp/5514  syslog (also tcp/5514)
    udp/2055  NetFlow v5/v9 · IPFIX
    udp/6343  sFlow v5
    udp/1162  SNMP traps · informs
  3. Watch live in the app or a browser

    Follow the dashboards on the device, or open http://<device-ip>:8080 on any machine that can reach it. Scan the QR code shown in the app to pair a browser with its access token, or use HTTPS on port 8443.

Protocol coverage

Decoded properly, not just captured

Each collector decodes the wire format into structured fields you can filter on. Unknown fields are kept rather than discarded.

Syslog RFC 5424

udp/tcp 5514 · tls 6514

Structured data with escaping and BOM handling. TCP framing is auto-detected: octet counting (RFC 6587) or LF, CRLF and NUL delimiters.

Syslog RFC 3164 / BSD

udp/tcp 5514

Cisco, Juniper and rsyslog variants, including sequence numbers and mnemonics. The year is inferred, with a rollover guard.

CEF and LEEF

inside syslog

Vendor, product, signature and extension fields are extracted, and CEF/LEEF severity is mapped onto the syslog scale.

Windows Events via NXLog

syslog JSON · Snare · text

NXLog xm_json output with EventID, channel, provider, computer, level and the full EventData map. Snare and plain text are also recognised.

NetFlow v5 and v9

udp 2055

v5 honours the sampling interval. v9 handles templates and multi-record packets, with a template cache per exporter and source ID.

IPFIX (v10)

udp 2055

Variable-length and enterprise information elements. Unmapped elements are kept as attributes, and IPv6 endpoints are supported.

sFlow v5

udp 6343

Flow samples with raw headers (Ethernet, 802.1Q, IPv4/IPv6, TCP/UDP/ICMP) and counter samples. Bytes are scaled by the sampling rate.

SNMP traps v1 and v2c

udp 1162

v1 generic traps are translated per RFC 3584, and v2c informs are acknowledged. Traps that fail the community filter are shown, not silently dropped.

SNMP v3

udp 1162

USM noAuthNoPriv, authNoPriv and authPriv with MD5, SHA-1 and SHA-2 authentication and DES or AES-128/192/256 privacy. Unauthenticated traps are flagged.

A mobile app cannot bind ports below 1024, so point exporters at the ports above instead of 514 or 162. Every port can be changed in Settings.

Where it is used

Built for the site visit, not the steady state

MobiObs does not replace your SIEM or NMS. It is for the hours when you are on site, the problem is happening now, and the permanent tooling is out of reach, not pointed at the right devices, or not there at all.

Venues & events

Arenas, stadiums and convention centres, where the network carries ticket scanners, walk-through scanners, point of sale and a wireless controller with thousands of clients.

  • Scanners at one gate start timing out 20 minutes before doors open. Point the scanners and the WLC at a mobile device on the staff VLAN, then see whether it is the validation API, 802.1X failures or an uplink that keeps flapping.
  • Follow roaming and authentication events from the controller while walking the concourse.

Datacenters

Change windows and cutovers where you want an independent view of what the equipment is reporting.

  • Collect syslog from the switches and firewalls being changed, and NetFlow from the border, to confirm that traffic moved where the plan said it would.
  • Watch for linkDown and linkUp traps during the cutover without editing the production NMS configuration.

Branch & retail

Small sites with a router, a firewall, a few access points and no local collector.

  • Plug in, point the branch firewall and router at the device, and see VPN, DHCP and authentication events next to the top talkers filling the uplink.
  • Leave a spare Android device collecting overnight to catch an intermittent fault.

Field service & MSPs

Engineers who visit customer networks and need to bring their own tooling.

  • Use Sender mode on a second MobiObs device to prove that a firewall passes UDP syslog or NetFlow before blaming the exporter.
  • Export the evidence as JSON, NDJSON or CSV and attach it to the ticket (Pro).
Features

What you get

Live tail & full-text search

Events stream live over WebSocket. Stored data is indexed with SQLite FTS5, so you can search message text and filter by severity, host, app, source IP or time range.

Default dashboards

Overview, Logs, Windows Events, Flows, SNMP Traps, Sources and Network work out of the box, with no queries to write and no panels to build.

Sender & test traffic

Generate syslog, NXLog-style Windows events, NetFlow v5/v9, IPFIX, sFlow and SNMP traps towards another MobiObs device or any collector, with presets and rate control. A probe checks reachability first.

Peer discovery & pairing

Other MobiObs devices on the LAN are found by broadcast and mDNS. You can also add peers manually or pair them by scanning a QR code.

HTTPS web UI with token pairing

The web UI is served over HTTP and HTTPS using a self-signed certificate whose fingerprint the app displays. Access requires a token, which the app shows as text and as a QR code.

All data stays on the device

Everything MobiObs receives is stored on the device. Nothing leaves it unless you export data or send it to another collector.

Network context

The Network screen lists every address and port to point equipment at, with a ready-to-paste sender snippet, and shows the gateway, DNS and Wi-Fi details (SSID, signal, channel) of the network the device is on.

Works offline and air-gapped

MobiObs needs no cloud account or internet connection. Licence keys are verified offline, and a store subscription keeps working offline beyond its renewal date for a grace period.

Pricing

Free, Pro and Team

The Free tier includes every collector. MobiObs never drops data from a source because of your tier, and reaching a limit never interrupts a running capture. Pricing will be announced at launch.

Features included in the Free, Pro and Team tiers
CapabilityFreeFor quick checksProFor individual engineersTeamFor organisations
PriceFreeAnnounced at launchAnnounced at launch
All collectors (Syslog, Windows, NetFlow, IPFIX, sFlow, SNMP v1/v2c), live view, dashboards and web UIIncludedIncludedIncluded
Retention1 hourUnlimited (configurable)Unlimited (configurable)
Stored rows (events, flows and counters, each)50,000ConfigurableConfigurable
SNMPv3 users (authentication and privacy)Not includedIncludedIncluded
Sender / test traffic generator1 job at a time, up to 100 messages per jobUnlimitedUnlimited
Replay stored dataNot includedIncludedIncluded
Export (JSON, NDJSON, CSV)Not includedIncludedIncluded
Peer discovery and QR pairingIncludedIncludedIncluded
Custom TLS certificateNot includedIncludedIncluded
Seats1 device1 user, up to 3 devicesPer seat, with your organisation name on the licence

Pro and Team will be available as in-app purchases through Google Play and the App Store, and as licence keys for desktop and organisations. For Team enquiries, email sales@mobiobs.com.

FAQ

Questions engineers ask

Why port 5514 and 1162 instead of 514 and 162?

Android and iOS do not let apps bind ports below 1024, so the defaults are udp/5514 for syslog (also tcp/5514), udp/2055 for NetFlow and IPFIX, udp/6343 for sFlow and udp/1162 for SNMP traps. All of them can be changed in Settings.

Most network operating systems let you set the destination port, and the Support page shows the lines for common platforms. If a device can only send to 514 or 162, forward the traffic through a relay or a destination NAT rule on a router.

Does collection keep running in the background on iOS?

On Android, MobiObs runs its collectors in a foreground service with a persistent notification, so collection continues with the screen off. You can also exempt it from battery optimisation for long captures.

iOS and iPadOS suspend apps that are not in the foreground, and a suspended app cannot receive UDP traffic. On an iPhone or iPad, keep MobiObs in the foreground during a capture, for example by setting Auto-Lock to Never while you work.

Does any of my data leave the device?

No. Everything MobiObs receives is stored on the device that received it. Data leaves only when you explicitly export it or send it to another collector with Sender or Replay. The app contains no analytics or tracking. See the privacy policy for details.

How do I get Windows Event Logs into MobiObs?

Install NXLog Community Edition on the Windows host. Configure it with xm_json and xm_syslog, and point an om_udp or om_tcp output at the device on port 5514. MobiObs recognises the events automatically and shows them under Windows Events, with event ID, channel, provider and all EventData fields. Snare format and plain syslog text also work. The Support page has a complete configuration.

What networks does it work on?

Any IP network where the sending equipment can route to the device, whether on the same subnet or through a gateway, provided no firewall or NAT blocks the path. MobiObs works with networks of any size; the limit is reachability, not device count.

The common problem is client isolation on guest and venue Wi-Fi. Isolation stops devices on the same SSID from reaching one another, so equipment cannot reach the mobile device even though both are connected. Use a staff or management SSID without isolation, a wired connection through a USB-C Ethernet adapter where the device supports one, or a VLAN that is routed to the equipment. The Network screen shows which addresses and interfaces the device is using.

Does it need an internet connection or a cloud account?

No. There is no account, and collection, dashboards and the web UI run entirely on the local network. Licence keys are verified offline. A store subscription is re-checked whenever the device is online, and it keeps working for 14 days past its renewal date while the device is offline.

Ready for the next site visit

The guides show the exact lines to send syslog, flows and traps from Cisco, Juniper, Aruba, Fortinet, MikroTik and Linux to a MobiObs device.