Skip to content

Network Intelligence

Know what is normal on your network — and get alerted when it isn't.

Baselines Change Detection Known Guests IP History Anomaly Alerts
4
Change event types
24hr
Dedup window
5
Device resolution strategies
3
Alert severity levels
First RMM with autonomous network baselines

Network Intelligence transforms passive discovery into continuous network monitoring — tracking baselines per subnet, detecting deviations, and surfacing anomalies before they become incidents.

Subnet Baselines

Breeze builds a living record of every device expected on each monitored subnet. Scheduled scans run automatically and compare current results against the established baseline, giving teams a clear picture of what normal looks like and an immediate signal when something changes.

Automated Change Detection

Every scan result is evaluated against the baseline and classified into four event types: new device, disappeared device, changed characteristics, and rogue device. Each event type has independent alert settings, so teams can tune signal-to-noise for their environment and focus on what actually matters.

Rogue Device Alerting

Organizations can define network policies with blocked manufacturer lists or permitted asset type allowlists. When a discovered device violates those policies, Breeze generates a high-severity rogue device alert automatically — no manual review of scan logs required.

Known Guest Management

Contractor laptops, vendor equipment, and conference room displays appear regularly on managed networks without being threats. Breeze lets MSPs register known guest MAC addresses at the partner level, suppressing false positive alerts for expected transient devices across all client sites.

Complete IP History

Breeze tracks every IP assignment for every enrolled device over time — when addresses were first seen, when they changed, and when they were released. This full addressing audit trail supports both troubleshooting and compliance reporting without any manual record-keeping.

Smart Alert Deduplication

Repeated scans detecting the same unchanged condition do not generate repeated alerts. Breeze deduplicates events within a 24-hour window based on a fingerprint of the event type, IP, MAC, and state — so operators see meaningful signals, not noise from routine scanning.

Capabilities

Subnet Baseline Monitoring

Define expected device state per subnet with configurable scan schedules and per-event-type alert toggles.

Change Event Detection

New, disappeared, changed, and rogue device events are deduplicated within 24-hour windows to prevent alert fatigue.

Known Guest Management

MSP-level MAC address whitelist suppresses alerts for expected transient devices across all customer sites.

IP Assignment History

Full timeline of interface IP changes, additions, and removals builds an audit trail for every enrolled device.