Server Dashboard
At-a-glance server state: player activity, economy flow, and forensic signals. Click any account or flag to drill in.
Currently Online
Client Telemetry
Live ingestion, machine coverage, and recent client screenshotsWeekend Snapshot
This weekend vs last weekend fixed weekendSame-hour Player Comparison
Last observed CCU in each server hour · missing hours remain gapsOther Shards — Players Online
Daily peak online · this server vs other shards · shard history ≤30dPeak Concurrent Players
Daily peak · 7-day rolling average · week-over-week deltaWeekly Active Accounts
Distinct accounts with a login in the last 7 days · heavy = 4+ daysPlayers Gained vs Lost
Monthly · joined = first login that month · lost = last login 30+ days agoRetention KPIs
cohortRetention Curve
% of accounts active N days after first login · D1, D7, D30 annotated cohortD1 Retention Over Time
Is next-day retention improving or degrading? · rolling 7-day join cohortEconomy Health
Player Engagement
Daily Gold Volume
Traded gold per dayEvent Types
Top 8Top Transfer Pairs
Rich Overnight
Recent Cross-Account Checks
Login Activity
Hour × day of weekSecurity Signals
Open Risk view →Check Trail
Every bank check tracked from creation through trades to cashing.
| Amount | Created By | Created At | Chain | Cashed By | Cross? | UID |
|---|
Lingering Checks
Checks that exist in the world right now and have not been cashed — stored value parked in a bank, a backpack or a house. Outstanding value and holders come from the world save, which is the authority on what exists; the log's never-cashed count is shown alongside only as a parsing-coverage signal.
Where it's parked (top holders)
| Held by | Uncashed value | Checks |
|---|
Who writes checks (log volume)
| Created by | Written (unmatched) | Checks |
|---|
Uncashed checks
| Amount | Held by | Character | Where | UID |
|---|
Trades
Vendor Sales
Per-item player-vendor purchases. Each line links buyer → seller → item UID → price. Different from trade logs — no confirmation window, just a direct purchase from someone's vendor.
Top Sellers
Top Buyers
Gold Flow
| Time | Type | Account | Character | Amount | Details |
|---|
Gold Supply & Cash-out Activity
Known gold creation is separated from moneybox withdrawals and check-writing. Cash-out activity is custody movement, not inflation.
Daily known faucets vs moneybox cash-outs
Cumulative known gold creation
Known faucets vs Received (from others)
High received with low independently observed faucet income is the wealth-recipient shape.
| Account | Known faucet | Received | Trade in | Check in | Recv / Earn | Profile |
|---|
Off-book residual (save truth vs ledger)
Each account's real net-worth change (world-save snapshots) minus every logged gold flow. Positive residual = wealth appeared through no logged channel — the strongest off-book / RMT signal.
| Account | Δ Net worth | Explained | Adjust | Residual | Days |
|---|
Account Relationships
Directional: who gave what to whom across all trades and checks.
| From | To | Items | Gold | Checks | Check GP | Trades | Total | Net GP | Wash % |
|---|
Pair Activity
Risk Patterns
Forensic signals grouped by family. First row: economic/behavioral patterns from trade and event logs. Second row: account-security signals — failed logins, connection rejections, hardware mismatches, PIN failures.
IP Investigation
All activity across every account that used this IP address.
Account Clusters
Groups of related accounts — two independent evidence bases. IP clusters use frequency-weighted co-residency (promiscuous NAT/VPN IPs excluded). Hardware clusters share a single hw_uuid from the login database — the strongest alt-farm signal.
| # | Accounts | IPs | Conns | Internal Gold | Trades | Risk |
|---|
Staff Activity
All admin actions: jails, mutes, staff commands, player pages.
Sellers
Accounts moving real value right now: checks written and cashed by others, overpriced/wash vendor "sales", fast check pass-throughs (couriers), one-sided deliveries. Ranked by value moved inside the window.
| Account | Moved | Checks out | Cashers | Top casher | Overpay in | Wash rev | Suspect % | Courier hops | 1-sided |
|---|
Gold Custody
Cross-account gold movement from world-save ownership, nested containers, ground handoffs, trades, and checks. Moving a bag cannot hide the gold inside it.
Largest consolidated account paths
Same pair combined across saves| From | To | Total moved | Save legs | Period |
|---|
Consolidated world-save legs
| When | From | To | Amount | Assets | Route |
|---|
Log-observed direct transfers
Top Receivers (sinks)
| Account | Received | Drops | Sources |
|---|
Top Givers (sources)
| Account | Given | Drops | Sinks |
|---|
Mule Chains (gold traced by ID)
| Accts | Path (custody order) | Amount | Span | Pile ID |
|---|
Handoffs
| Dropped by | Picked up by | Amount | Gap | Where | When |
|---|
Item Transfers
Cross-account custody changes proven by consecutive world saves. Each item is valued at the completed-sale median available before the receiving save; return trips remain separate gross transfers.
Top receivers by gross value
| Account | Gross | Moves | Sources |
|---|
Top givers by gross value
| Account | Gross | Moves | Receivers |
|---|
Transfer evidence
| Time | From | To | Item | Value | Price evidence | UID |
|---|
Pages
Player .page submissions (GM help requests) with the GM reply, handler, and in-world position. Filter by text, GM, account, or date range. Click an account to drill into the player view.
Kufur Reports
Player-filed .ihbar (swearing) reports with the captured chat transcript around the incident moment. Each row is one incident; expand to read the snippets and see who said what.
| Time | Reporter | Offender | Snippets | Status |
|---|
Errors
Engine ERROR / WARNING / CRITICAL lines, clustered into issues by message fingerprint (UIDs, coords and numbers collapsed). Spot what's frequent, what just appeared, and what's trending up — then drill in for the daily history and time-of-day pattern.
Errors per day by severity
Criminal Flags
Criminal-flag evidence ([CRIMLOG]): confirmed script transitions, player/NPC notices, guards resolutions with their exact cause, and 20-minute saw-crime memories.
Honeypot
Server-side cheat-detector trips. Each event is a client action (DoubleClick, PickUp, Target, ...) whose seed didn't match — the client interacted with a bait item (honeypot) the server never showed it. Severity-100 cheat-client signal.
Client Telemetry
Encrypted machine-fingerprint snapshots posted by the client 5 minutes into a session. Software is stored as an account + machine baseline followed by additions and removals; screenshots and session evidence remain per snapshot. Click any row to reconstruct the full state at that moment, including present, newly added, just removed, and previously seen software.
| Time | Account | Host | OS | CPU | Session | Locale | IP / Geo | Displays | Drv (unsigned) | Flags |
|---|
Live Status
Currently-online players, grouped by IP. Counts come straight from the engine's own arc_online_acc table — every connect/disconnect is a row, latest row per (account, character) where online=1 is the deterministic CCU. Multi-box IPs (most accounts on one IP) bubble to the top. Enriched with country, guild, house flag, last activity from logs, and 24h honeypot / anti-cheat hit counts.
Network Diagnostics
Windows TCP samples and smoothed transport RTT for live Sphere clients on port 2594. These diagnose the network path but are not the game's own ping measurement.
TCP RTT trend
Retransmit % is a TCP loss estimate; packet reordering can also cause retransmission.Current connections
| IP | Location | Provider / ASN | Account / character | Route / VPN signals | TCP smoothed | TCP sample | Variation | Retransmit | Traffic / interval | Socket |
|---|
Sample history
| Time | IP | Location | Provider / ASN | Account / character | Route / VPN signals | TCP smoothed | TCP sample | Retransmit | Traffic / interval |
|---|
Store dupe investigation
Identify replay sources, follow affected inventory and inspect its current concentrations.
Origin & rollback review
Physical-world items across all accounts, banks and houses. SQL-store holdings are covered separately by the store-lineage investigation below.
Missing origin evidence is a review lead, not proof of duplication. Crafting, loot and legacy creation logs are not comprehensive.
Save boundaries & rollback evidence
Evidence limits
Loading…
Raw replay evidence · row-by-row audit
These filters apply to the raw evidence below, not the investigation overview.
| Evidence | Account / character | Store row | Item | Action interval | Created UIDs | Raw proof |
|---|
Item whereabouts and custody history
Raw Stream Audit
Server-side grep of one log file using a category regex, cross-referenced against events.sqlite. Lines marked "missed" matched the regex but were parsed as OTHER — that's the silent-drop signal. "partial" means parsed as a generic type when a more specific one exists. "not_indexed" means the file isn't in events.sqlite yet.
| Status | Line | Parsed as | Raw line | Show |
|---|
Driver Analysis
Detected keyboard/mouse filter drivers per account. Categorized by type and severity — virtualization and cheat-tool drivers are flagged as alerts.
DB Viewer
Read-only browser for the SQLite enrichment sidecar. Use Search to locate any UID across all tables; Browse for paginated table inspection; Query to run SELECT statements directly.
| Table | Rows | Columns |
|---|
Log Viewer
Accounts
Every account, ranked. Pick a starting point, then narrow it — the filters combine, so "rich, gone quiet and sharing a machine" is one question rather than three pages.
Event Feed
Everything that happened, in time order. Pick what you want to see — the columns follow. "Any event type" reaches all 119 parsed types, including the ones no page was ever built for.
Files
| File | Size | Uploaded | By |
|---|
Gold Accounting
Legitimate-gold accounting per account. Recon totals each account's DB-known gold-in (quest rewards + merchant sell revenue). The other tabs drill into each source leaderboard, plus Storage Wealth — hoarder-scale inventories.
| Account | Quest gold in | Merchant sell in | Verified in | Quests | Sells |
|---|
Player Dossier
Ground-truth per-account snapshot from the world save: exact net worth, characters, hardware, houses, pets, vendors, and full inventory.
Machines
Hardware (hwuuid) clusters — accounts sharing a physical machine, online or offline. Multibox / farm finder.
Item Integrity
Cases
What is asking for a decision. Detectors open a case when they find something; a case you dismiss stays dismissed until NEW evidence arrives, at which point it reopens and says so. This is the only table here that a rebuild cannot reproduce.
Record
World
Current world state from the .scp save — ground truth, not inferred from logs. Items, houses, vendors and client hashes in one browser. Any UID can be located to see its full container path and contents.
World Timeline
The world moving, save by save — items changing hands, characters moving, things appearing and vanishing. Pick a snapshot to see everything that changed in that ~30-minute step.
Guilds
Current guild organizations and isolated cross-guild accounts. Broad roster overlap is grouped as sister guilds; thin links stay visible for review.
Sister-guild organizations
Same master, or 3+ shared accounts covering at least 40% of the smaller roster.Add two or more guilds. They will be treated as one organization and excluded from each other's spy leads.
| Guild | Organization | Accounts | Cross-guild | Review | Houses | Master |
|---|
Houses
All 672 houses with owner character, account, coordinates, and type.
| House UID | Owner | Account | Coords | Type | Status |
|---|
Tamed Animals
Rare-mount tames from the roster (unicorns, shires, silver steeds, kirins, and the rest). High-value mounts — who tamed which, when, and where. Click an account to investigate.
By species
| Species | Tamed |
|---|
Top tamers
| Account | Tamed | Species |
|---|
Tame log
| When | Species | Tamed by | Where | Animal ID |
|---|
Verified Disguises
Character names that exist on 2+ distinct accounts in arc_stat_players — ground-truth disguise detection from DB (vs. statistical inference from logs).
| Character name | Accounts | Linked accounts |
|---|
Live Log Stream
tail-f style real-time view of every event being parsed from the SphereServer logs. Visual only — no alerts, no chimes. Use the type filter to narrow to specific signal types.
System
Live resource use, ingest throughput, and worker activity. The freshness pill in the top bar links here. Snapshots refresh every 5 seconds.
Live emitter (last 5 min)
● connectingResources (last hour)
Ingest throughput
Background workers
| Worker | Last run | Duration | Details |
|---|
Derived-table projections
| Projection | Freshness | Watermark | v |
|---|
Recent ingest activity
| Time | Type | Details |
|---|
CDC tables (last 5 min)
| Table | Events (5 min) |
|---|
Unknown patterns (parser drift)
Lines the parser tagged OTHER, grouped by signature (uids/timestamps/numbers collapsed). If you see a row with a high count here, paste the "Copy for AI" output into Claude and ask for new parser regexes.
| Count | Sample line |
|---|
Item Spawner
Search the SphereServer item catalog (arc_allitems). Click a row to copy .add <defname> to your clipboard, then paste in-game to spawn or reference.
| ID | Name | Defname | Itemdef | Copy |
|---|
Arena
Live monitoring of arena PvP. Log stream + DB system-of-record unified across 7 tabs.
Glossary
Forensic and SphereServer domain terms used across the app. Hover the dotted terms anywhere in the UI for a quick definition; read the full entries here.