Features
One platform for monitoring, logs, and topology across your Grid. Everything below is included; nothing needs a separate agent on your devices.
Discovery & inventory
Find what's on the network and keep an accurate, organized inventory.
Host & service discovery
Sweep your networks for live hosts and fingerprint the running services each one exposes.
Tunable scan profiles
Light-touch to thorough scanning, with optional port scanning, per your environment.
Device classes
Group devices by type; classes carry credentials and monitoring, inherited automatically.
Live inventory
Every device with up/down status, organized by class and site, promoted from discovery in one step.
Monitoring & metrics
Know the instant a device goes offline, plus every metric that matters once it's back.
Device uptime monitoring
ICMP and SNMP reachability checked continuously; get alerted the moment a device goes offline, not after someone notices.
Agent-less collection
One lightweight collector listens for logs and traps and serves as the collection point for all telemetry, with load-balanced backup collectors for fault tolerance; no per-device agents.
Monitoring packs
Reusable packs define what to poll. Ship-with Core plus downloadable vendor bundles (Cisco, Juniper, FortiGate, and more).
Interface metrics
Per-interface traffic, packets, and errors, with per-second rates computed for you.
Interface thresholds
Per-interface limits on traffic, errors, or utilization that open an event on breach and clear on recovery.
Service monitoring
Synthetic checks for any service, with up/down events.
Custom dashboards & reports
Build the views you want; export reports on inventory, health, and utilization.
Topology & correlation
See how everything connects, and what each failure takes down with it.
Live topology graph
A graph model of your network, built from the devices and links the Grid discovers.
Neighbor discovery
Automatic links from LLDP and CDP neighbor data.
Blast radius
When a device fails, see the upstream root cause and every affected downstream device.
Layouts & filters
Filter the graph by class, layer, site, and status; multiple layouts.
Detection & logs
One detection language across your logs and your telemetry, plus full log search.
rule repeated_auth_failure { events: $e.message =~ "failed login" condition: #e >= 10 over 5m }
YARA-L detections
Write detections once and run them on logs and metrics alike, scheduled for coverage or streaming at ingest.
Field extraction
Turn raw log lines into structured, searchable fields.
Log search
Fast search over collected syslog and trap history, on the device tab or across the fleet.
Built-in rules
Sensible detections out of the box; fully editable for your environment.
Retention & cold tier
Per-tenant retention by age or size, with older logs tiered to cheaper cold storage.
Events, cases & alerting
Turn signal into prioritized events, group the noise, and alert once.
Immutable events
Every event is a timestamped, append-only record of exactly what happened — severity included, never rewritten. Whether something's down right now reads from live state, not a status you keep in sync.
Automatic case management
The investigation lifecycle lives in cases: case rules correlate related and flapping events into a single case over a window you define, then own it from open to close.
Flap suppression
A signal hovering on a threshold won't fire on every bounce — the detector records one event per state change, and cases close on their own once quiet.
Flexible alerting
Route the events you care about to email, Slack, webhooks, or PagerDuty.
RCA workbench
Investigate a case with its grouped events and the affected topology in one place.
Platform & deployment
Multi-tenant, multi-site, and yours to run in our cloud or your own.
Sites & RBAC
Organize devices by site with role-based access down to the site level.
Collectors
Outbound-only collectors assigned to networks, with health monitoring and self-upgrade.
MIB browser & pack bundles
Upload vendor MIBs and pack bundles; OIDs and tabs appear automatically.
Cloud or self-hosted
Run GridNMS managed in our cloud, or self-host the same platform with Docker.
Security & compliance
Your Grid's data is sensitive. It's isolated, encrypted, and gated behind strong auth — with keys you can hold yourself.
Field-level encryption
Device credentials — SNMP communities, SSH and webhook secrets — are envelope-encrypted with per-tenant keys before they ever touch disk.
Bring your own key
Supply your own KMS key from GCP or AWS. The Grid wraps your tenant's keys under a key only you control — revoke it in your cloud and your data at rest goes dark, even to us.
Passkey sign-in
Passwordless, phishing-resistant login with WebAuthn passkeys, alongside sessions and secure one-time codes.
Hard tenant isolation
Every customer's data lives in its own database schema, and every query is bound to your tenant at request time.
Audit trail
Administrative and account actions are recorded for review.
Put it to work on your Grid.
From $49/month. Cloud-hosted, or self-hosted with Docker.