Root Cause Analysis – Datto RMM Merlot Devices Appearing Offline
Summary
Between 2026-07-20 11:39 UTC and 2026-07-20 15:00 UTC, Datto RMM partners on the Merlot platform experienced device connectivity degradation. During this time, some devices incorrectly appeared offline, partners may have received false offline alerts, and access to affected devices may have been reduced.
Our teams detected the issue through internal monitoring and partner reports, investigated the service degradation, and restored stability by increasing capacity across the affected connectivity infrastructure.
Root Cause
The incident was caused by elevated load and resource contention affecting a core device connectivity service. This reduced service responsiveness and caused a large number of agents to disconnect and reconnect. The resulting reconnect activity increased demand on the connectivity infrastructure, causing devices to appear offline within the platform and generating false offline alerts for some partners.
Incident Timeline
Preventative Measures
To reduce the likelihood and impact of similar incidents in the future, we are taking the following actions:
Enhancing infrastructure resiliency by reviewing scaling thresholds and improving response options for high reconnect traffic scenarios.
Improving workload isolation to reduce the risk of workloads having a critical impact on production service paths.
Improving agent reconnect handling to reduce unnecessary resource consumption during reconnect events.
Improving reconnect traffic management to better distribute reconnect attempts during large-scale events.
Enhancing monitoring and alerting to improve visibility into device connectivity, reconnect activity, service health, and related infrastructure signals.
Expanding incident response runbooks for connectivity degradation scenarios to support faster and more consistent mitigation.