Connect Paessler PRTG
PRTG is Paessler's network and infrastructure monitoring platform. It watches servers, switches, firewalls, printers, cloud services and anything else that answers a check, and it tells you what is…
Written By Christopher Scaminaci
Last updated 6 days ago
PRTG is Paessler's network and infrastructure monitoring platform. It watches servers, switches, firewalls, printers, cloud services and anything else that answers a check, and it tells you what is up, what is down, and what has been getting slowly worse. Unlike most tools StackJack connects to, PRTG runs on your own equipment: PRTG Network Monitor and PRTG Enterprise Monitor install on a machine you own, and PRTG Hosted Monitor is the version Paessler runs for you. StackJack talks to it through the PRTG API.
Connecting PRTG to StackJack gives your AI assistant a family of prtg_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer "what is broken right now" — list the sensors currently in alarm, count how many objects sit in each state across the whole server, and narrow the same question to one site or one customer
- Look up any part of the tree — probes, groups, devices, sensors and channels, searched with PRTG's own filter language
- Read history — recent measurements for a sensor, the standard graph windows, and arbitrary date ranges for a channel
- Report on the estate — the object tree, device templates, sensor kinds, the server version and its license
- Handle alarms (on Pro plans) — acknowledge one alarm with a note, or acknowledge everything matching a filter
- Run maintenance (on Pro plans) — pause and resume sensors, devices, groups and probes, individually or by filter
- Manage the tree (on Pro plans) — create, edit, clone, move and delete objects, and run auto-discovery to find new devices and sensors
- Administer accounts (on Pro plans) — users and user groups, plus API key and password tools held behind separate permissions
The three PRTG words that do not mean what you expect
Getting these wrong will send your AI looking in the wrong place, so they are worth thirty seconds:
- A probe is a piece of PRTG software — a collector process that performs the monitoring and reports back to your PRTG server. It is not a network device. A remote site usually gets its own probe.
- A sensor is one thing being monitored on a device, such as its ping response or one disk volume. A single server commonly has a dozen sensors. PRTG licenses are counted in sensors.
- A channel is one measurement inside a sensor, such as the download speed inside a bandwidth sensor. Channels are where the numbers live.
The tree runs probe, then group, then device, then sensor, then channel. Settings flow downward, so a change made on a group reaches everything beneath it.
How StackJack authenticates to PRTG
PRTG uses an API key that you create inside your own PRTG server. There is no client ID, no second secret, and nothing that expires on a schedule.
Two separate things decide what that key can do, and both matter:
- The rights of the PRTG user who created it. A key can never reach more than its owner can. A key made by a user who only sees one customer's group stays limited to that group.
- The access level chosen for the key, which is Read, Acknowledge, Write or Full. Read allows reporting only. Acknowledge adds alarm acknowledgement. Write adds configuration changes such as pausing, scanning and editing. Full adds account and API key management.
If a tool is refused, check both. Raising the access level cannot widen a key whose owner is restricted.
Steps
- Sign in as the right PRTG user. Choose a user who can see every group and device you want StackJack to work with. On a shared PRTG server that usually means an administrator.
- Open API Keys — go to Setup, then Account Settings, then My Account, and find the API Keys section.
- Add a key and choose its access level. Name it so a later review can tell what holds it, and pick the lowest level that covers what you want StackJack to do.
- Copy the key immediately. PRTG shows it once. Treat it as a password — anyone holding it can act on your monitoring as that user.
- Find your PRTG server address — the address you reach PRTG at from the internet, including the port of the PRTG Application Server (1616 by default, see below) unless a reverse proxy publishes it on the standard port, such as
https://prtg.example.com:1616orhttps://prtg.example.com. Enter the address only; StackJack adds the rest of the path itself. - Paste both into StackJack. Open Connectors, choose Paessler PRTG, enter the server address and the API key, and run a Test Connection.
Your PRTG server has to be reachable
Because PRTG runs on your equipment, StackJack has to reach it from the internet. That means it must be published at a public address with a certificate from a public certificate authority. A private or internal-only address will not work, and neither will a self-signed certificate. If your PRTG core still serves the certificate it installed with, replace it before connecting.
A custom port is fine. A reverse proxy that publishes PRTG under a path prefix is also fine — enter the address exactly as you reach it.
StackJack talks to PRTG's API v2, which is served by the PRTG Application Server, a separate service that PRTG installs when the new UI and API v2 are activated (activated by default on new installs from PRTG 25.2; older cores activate it under Setup). It listens on its own port: 1616 for HTTPS by default, 1615 for HTTP. The classic web interface port (443 or 8443 on most installs) does not serve API v2, so a key that PRTG accepts can still be refused through that port. Enter the address and port that reach the Application Server, or publish that service through your reverse proxy.
What to know before your AI uses this connector
Pausing hides outages
This is the most important thing about the PRTG connector, and it is the opposite of how "pause" usually reads. Pausing a sensor, device, group or probe suppresses both the checks and the alerting for everything beneath it. A real failure during a pause produces no alert and no red on the map — a paused estate and a healthy estate look the same at a glance.
The filtered forms make that reach much further, because one call can pause everything matching a filter. Silencing an entire site is a single tool call.
Every pause tool requires the Pro tier and has a matching resume tool. Pausing your monitoring is marked as an ordinary write rather than a destructive one — nothing is destroyed and the resume puts it back — so an AI application that only pauses on destructive actions will not pause on these. Tell your agent to confirm what a filter matches before it pauses in bulk. Pausing a PRTG user account is different: that locks a person out, so it is marked destructive. See Destructive tools and confirmation for what your AI application does with those markings.
Long lists come back one page at a time
A list tool returns one page. PRTG's own maximum page is larger than an AI agent can usefully read, so StackJack limits how many objects one call may ask for. To walk a long list, your agent moves the starting position forward by the size of the page it just read and asks again.
By default a list tool hands back exactly what PRTG sent. If your agent needs to know how many objects exist in total, or whether another page is waiting, it can ask for the totals alongside the page — that is a choice it makes per call, and it changes nothing about what the tools return otherwise.
Scans and auto-discovery send real traffic
A scan asks your PRTG probe to check something immediately rather than waiting for its schedule, so it puts real traffic on your network aimed at real devices. Auto-discovery goes further: it sweeps a range, then creates sensors, which start polling right away and count against your PRTG sensor license. Check your remaining sensor allowance before running a discovery across a group.
Deletes remove history, and PRTG has no undo
Deleting a device, group or probe removes every sensor beneath it and every measurement those sensors ever recorded. There is no recycle bin and no undo. Moving an object is gentler but not harmless: PRTG inherits settings from the parent, so re-parenting an object can quietly change how it is monitored.
Credential and password tools are held separately
Creating an API key, changing one, deleting one, and the two password-reset tools each sit behind their own permission, apart from ordinary user administration. You can allow your AI to manage users while withholding all five, and we suggest you do unless you have a specific reason not to — one of them emails a real person a password-reset link, and editing an existing key can widen what that key is allowed to reach.
Some tools use a part of the API Paessler calls experimental
Creating, updating and deleting objects reaches endpoints Paessler labels experimental and says may change between PRTG releases. They are included because they are the only way to manage the object tree through the API, and each tool says so in its own description. Reading your monitoring — status, alarms, inventory and history — does not depend on them.
Plans and limits
Read tools are available on the Free tier. Everything that acknowledges, pauses, scans, edits, deletes or administers accounts is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Paessler PRTG tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Paessler does not publish a request limit for this API, so the pacing StackJack applies exists to protect your server rather than to satisfy the vendor. Your PRTG core is a single machine doing real monitoring work, and a large report should not compete with it. Big reads are spread out instead of arriving all at once. Pacing is not a guarantee: retries are bounded, so a wide enough read can still time out — narrow it rather than repeating it, and check whether a write landed before you retry it (see Retrying a failed or timed-out write).
Several customers
Every customer has their own PRTG server. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
Troubleshooting
"PRTG rejected the API key" — two causes. Either the key was deleted or replaced (PRTG keys do not expire, so a key that stops working almost always stopped on purpose: create a new one, paste it into StackJack, and run a Test Connection), or the address reaches PRTG's classic web interface and not the PRTG Application Server. The classic interface refuses an otherwise valid key with the same message, so on a core installed before PRTG 25.2 activate the new UI and API v2 under Setup, then point the connector at the Application Server port (1616 by default; see How StackJack authenticates to PRTG above).
"PRTG accepted the key but refused this operation" — the key's reach, not a fault. Check the access level on the key and the PRTG rights of the user who created it. A Read key is refused for every write tool; a key owned by a restricted user is refused for anything outside that user's groups.
StackJack cannot reach the server at all — work through the address first. It has to be reachable from the internet, over HTTPS, with a certificate from a public authority. A self-signed certificate is the single most common cause, and it fails the same way an unreachable server does.
A device shows no sensors — check whether the device or its parent is paused before assuming discovery failed. An inherited pause from a group or a probe looks exactly like an empty device.
Auto-discovery found nothing — confirm the probe that owns the target range is connected, and that the device credentials stored in PRTG are the ones the target accepts. Discovery runs from the probe, so a probe that is disconnected or on the wrong side of a firewall finds nothing and reports no error you would notice.
A filter returns nothing — PRTG filters are a small query language rather than a list of fields, and an unrecognized term returns an empty result instead of an error. Ask for a plain list first, confirm the objects are there, then add the filter.
Paessler PRTG tools
prtg_ · 100 tools · Free 43 · Pro 57
Sensors & Alarms
Devices
Groups
Probes
Objects & Schemas
Auto-Discovery
Channels & Time Series
Users & User Groups
API Keys & Password Reset
System & Lookups
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team