UplivraUplivra
Uplivra is in beta and online purchasing is paused. Apply to test it: testers get a license on request and 10% off when purchasing opens.

Home › Documentation › Uplivra NOC Operations Guide

Handbook · NOC staff, operators and on-call engineers

Uplivra NOC Operations Guide

The daily work of a network operations center on Uplivra, step by step: start-of-shift checks, triaging alerts, asking Uplivra Intelligence, notices, incidents in the Service Desk or your ticketing system, maintenance windows, escalation, shift handover, the wall screen, and what to check when something looks wrong.

Uplivra Technologies LLC · Handbook for Uplivra 26.10 · Updated 1 October 2026 · Latest version: https://uplivra.com/guides/noc-operations-guide.html

Download this handbook as a PDF

Who this guide is for

NOC staff, operators and on-call engineers who watch and respond in Uplivra. You don't need to be an administrator. The NOC engineer access profile lets you acknowledge alerts, plan maintenance, read logs, take packet captures and start remote sessions; the Operator profile adds changing devices. If a menu in this guide is missing for you, your access profile doesn't include it: ask your administrator.

Menus are written like Settings › Maintenance windows. For installing and setting up Uplivra, see the Administrator Handbook.

The screens you use most

ScreenWhereWhat it tells you
OverviewFirst item in the menuDevice counts (healthy, warning, critical), network health over 24 hours, top alerts, devices with a problem, collector health
AlertsMenu, or the bell at the topEvery open alert, who is on it, and what was fixed recently
NoticesMenu, under ToolsProblems Uplivra Intelligence spotted without being asked (disks filling, half duplex, rogue DHCP…)
IntelligenceMenu, under ToolsAsk about the network in plain words
LogsMenuMessages from your devices, with search and live tail
Help deskMenu (Service Desk module)Tickets and incidents
Wall screenWall screen button on the OverviewA full-screen status view for the NOC TV

Start of shift

Do these every shift, in this order. It takes about 10 minutes.

  1. Read the handover from the last shift (see Shift handover).
  2. Overview: check the counts. Note anything critical.
  3. Collector health (on the Overview): every collector should say Reporting. A Silent collector means its whole site is not being checked: that comes first. See A collector is silent.
  4. Alerts: read every open alert. Anything with Handled by: nobody yet needs an owner (see Triage).
  5. Settings › Maintenance windows: what is In effect now and Coming up on your shift, and anything Waiting for approval (an administrator banner also says so).
  6. Notices: any new Act now notices.
  7. Help desk (if you use it): tickets assigned to you or your team, and anything close to missing its target.
  8. Check the wall screen in the NOC shows Updated with the current time. If it's old, sign it in again.

During the shift

  • Keep Alerts open in a browser tab. The count in the menu and the bell at the top show open alerts.
  • Every hour: glance at Notices and the Overview's Network health chart.
  • Before anyone works on a device, make sure a maintenance window covers it (Maintenance windows).
  • Write what you do on the alert's ticket, so the next shift can follow it.

Triage of alerts

What an alert shows

On Alerts, each open alert has its severity (Down or Warning), what (device and check), since when, and handled by. Recently fixed below lists what cleared.

Triage, step by step

  1. Is it real? Open the device (click its name). Look at its checks: if one check is red and the rest green, it's that service. If everything is red, the device or the path to it is down.
  2. Is it one device or many? Many alerts at one site at once usually mean one cause: the site's link, a core switch, or the collector. Uplivra holds back alerts for devices that sit behind a device that's down, so you normally get one alert for the switch, not fifty.
  3. Take it. Press I'm on it. Everyone sees you're handling it, "got worse" messages stop, and any escalation for it stops. You still get the "fixed" message.
  4. Understand it. Press Explain for Uplivra Intelligence's view: the likely cause, and (with the Intelligence module) what else happened at the time, recent log lines, earlier notices and what to check first.
  5. Check from the site. On the collector's page (Settings › Sites and collectors, click the collector), Test from this collector runs a ping, port check, DNS lookup or traceroute from the site's network. That tells you whether the device or the path is the problem.
  6. Record it. Press Open a ticket (or let tickets open automatically, below), and write what you found.
  7. Fix or hand on. Follow your runbook. If you can't fix it within your time limit, escalate.

How urgent is it?

AlertAct
Down on a core switch, firewall, internet line or serverAt once. Many people are affected
A collector silentAt once: the site isn't being checked at all
Down on one access device, printer or phoneWithin your normal target
Warning (CPU, disk, temperature, slow response)Watch it; plan a fix within the shift
Notice For your information (for example "disk full in 9 days")Put it in a ticket for the day team

Alerts from logs and security findings

  • Log alerts (Log Intelligence) are raised when a search matches enough messages, such as 5 failed sign-ins in 10 minutes. Open Logs with the same search to see the messages.
  • Repeated sign-in failures, password spraying, probes and port scans from untrusted sources open alerts too. Find the source address in the alert, and check whether it's one of your own scanners before you act.
  • A zero-day (Vulnerability Scanning) opens one high-priority alert listing every affected device, and a ticket. Pass it to your network or security team.

Using Uplivra Intelligence

Ask a question

  1. Open Intelligence in the menu.
  2. Type a question in plain words under Ask about your network and press Ask.
  3. Name devices, sites or addresses, and say a time ("since 9am", "last 24 hours", "yesterday"). Put exact log text in quotes.

Questions that work well:

  • What's going on right now?
  • Why are devices down at HQ?
  • Which devices had the worst latency today?
  • Jitter and packet loss on the phones over the last 24 hours
  • Show errors in the logs from the firewall since 8am
  • Search the logs for "authentication failed" this week
  • What changed in the last 7 days?
  • Is any interface busy or dropping packets?

The answer is a summary with timelines, charts and tables. Intelligence reads devices, checks, measurements, alerts, log messages, configuration changes and collectors, only from your own server, and never changes anything. On the Logs page, Ask Intelligence turns a plain question into a log search you can check and adjust.

Notices

Notices lists problems Intelligence found without being asked: a disk that will fill, a link near capacity, a port at half duplex, a second DHCP server, port errors, loops, UPS batteries, certificates, sign-in attacks and changes outside maintenance. Each notice names the device and the port or disk, says why, and says What to do.

  1. Filter by kind if the list is long.
  2. Work Act now first, then Attention. For your information includes forecasts such as "will be full in 9 days".
  3. Notices are checked every 15 minutes and close by themselves when the problem is gone. Cleared in the last 7 days shows what went away.

Your administrator chooses which notices are emailed or posted to Teams or Slack under Settings › Intelligence notifications. Disk, duplex, rogue DHCP and the weekly summary notices are free; the others come with the Uplivra Intelligence module (free for the first 6 months of a new installation).

Incident workflow

Uplivra can record incidents in its own Service Desk (Help desk in the menu) or in your ITSM system (ServiceNow, Jira Service Management, Freshservice, Zendesk or a webhook).

Automatic incidents

If your administrator turned on Settings › Ticketing › Open incidents for alerts, Uplivra opens an incident when an alert stays open (for critical alerts only, or critical and warning, after the delay chosen), adds a note if it gets worse, and resolves it when the alert clears. The alert shows the incident's number; Incident not opened means the ticketing system refused it (the message says why).

By hand

On Alerts, press Open a ticket next to the alert.

Working an incident in the Service Desk

  1. Help desk › open the ticket. Take it assigns it to you.
  2. Set Priority (Urgent, High, Normal, Low), Type (Incident, Request, Problem, Change), Queue, Team, Category and the Device.
  3. Reply to the requester, or add an Internal note (the requester doesn't see it).
  4. Use Then to wait on the requester (the target clocks pause), mark resolved, or leave the status.
  5. Status runs New › Open › Waiting on requester › Resolved › Closed.
  6. History shows every change.

Targets pause while a ticket is Waiting on requester. See Service Desk for teams, round robin and email to ticket.

A good incident record

  • When it started (the alert's since time) and when it was fixed.
  • What was affected: devices, sites, services.
  • What you saw: alert, Explain, test results, log lines.
  • What you did, step by step, and who you told.
  • Cause, if known, and any follow-up.

Maintenance windows

Plan a window before anyone works on a device, so nobody is paged for planned work.

  1. Settings › Maintenance windows › New maintenance window.
  2. Type a Title and the reason. Choose Planned, Emergency or Unplanned (already happening).
  3. Choose What it covers: a site, devices you pick, a device group, devices with a tag, a service, or everything.
  4. Choose what happens to alerts: Hold them back (listed on the window afterwards) or Send them only to the team doing the work.
  5. Set Starts and Ends (in your computer's time zone; a start in the past means now).
  6. If your administrator set it up, open a change ticket and pick the approver.
  7. Click Save maintenance window.

On Settings › Maintenance windows you can see each window's state (Waiting for approval, In effect now, Coming up, Finished in the last 3 days), the problems that happened during it, and press End now when the work finishes early, or Cancel. Approvers see Approve and Turn down.

Approved planned maintenance is left out of availability reports; emergency and unplanned maintenance still count.

Escalation

Automatic escalation

Your administrator sets escalation under Settings › Where alerts go › Escalation: if an alert is still open and nobody pressed I'm on it after a number of minutes, Uplivra also tells someone else (a manager, an on-call phone), and can repeat. Pressing I'm on it stops the escalation, so take alerts you're working on.

Escalating by hand

Escalate when:

  • a core device, internet line or a whole site has been down longer than your target;
  • a collector has been silent for more than 15 minutes and you can't reach the site;
  • you suspect an attack (sign-in attacks, port scans from inside, a rogue DHCP server);
  • you're about to do something risky or outside your access.

Tell the next level by phone or your on-call tool, then write it on the ticket: who you told, when, and what you asked them to do.

Shift handover

Write a short handover at the end of every shift. Use the same format each time:

SectionWhat to write
Open incidentsTicket number, device or site, state, next step, who owns it
Alerts I'm onAnything you pressed I'm on it for that's still open. Hand it over by name
MaintenanceWindows in effect now and coming up in the next shift, and any waiting for approval
NoticesNew Act now or Attention notices and what was done
CollectorsAny that went silent, and whether they're back
ChangesAnything changed during the shift (devices added, checks paused, rules changed)
Watch forWhat the next shift should keep an eye on

Before you leave, check Alerts for anything still showing you under Handled by and hand it to a named person on the next shift.

The wall screen

  1. On the NOC display's computer, sign in to Uplivra with an account that has a view-only profile (for example Viewer).
  2. On the Overview, click Wall screen. It shows Network status: counts of Down, Warning, Up and Waiting devices, open alerts with who is on it, and each site's devices. Everything is working shows when nothing is wrong.
  3. Press F11 in the browser for full screen.

It refreshes every 30 seconds, and the time next to Updated tells you it's live. To pick which sites it shows, set Which sites under My settings for the account it's signed in with.

Common problems and what to check

A collector is silent

Its site isn't being checked, so treat it as urgent.

  1. Settings › Sites and collectors: when did it last report?
  2. Is the site itself down (power, internet line)? Check the site's router or firewall alert, or call the site.
  3. If you can reach the collector's computer, open its management page (https:// and its address) in a browser: it says why it can't connect.
  4. On a Linux collector: sudo journalctl -u uplivra-collector -n 20. On Windows: the log file C:\ProgramData\Uplivra\collector.log, and the Uplivra Collector task in Task Scheduler (click Run if it stopped).
  5. Usual causes: the firewall between the site and the server blocks HTTPS 443, the collector's clock is wrong, or the computer was turned off.
  6. While it's silent, it keeps checking devices and sends the results when it's back.

Many alerts at once

Look for the common thing: one site, one switch, one internet line. Check the core device and the site's collector first. If it's planned work, create the maintenance window now (choose Unplanned (already happening)).

A device is down but users say it works

  1. Open the check and look at its last result and message.
  2. Press Test from this collector on the site's collector page: ping and port from the site.
  3. A firewall change or a new ACL may block the collector, not the users. Ask the network team.
  4. For SNMP: the login or community may have changed on the device.

Alerts don't arrive by email, Teams or Slack

Settings › Where alerts go: Send test, then Delivery history shows what the other end answered. Ask your administrator if the email server or webhook changed.

Flapping (up, down, up)

The link or device is unstable. Look at the ping check's loss and jitter on Network › Path quality (Network Pro). Ask your administrator to raise Alert after N failures in a row on that check only if the device is known to be on a shaky link.

The wall screen stopped updating

The time next to Updated is old: the browser was signed out (idle sign-out) or lost its network. Sign in again, or move the display to a public status page.

You can't see a page or button

Your access profile doesn't include it. Settings › People and access › Check someone's access (for administrators) shows why.