GridNMS

GridNMS unifies every device, log, and metric on one living graph — so when something breaks, you see the cause and everything it affects, not a wall of disconnected alerts.

From $49/month. Cloud-hosted, or self-hosted with Docker.

0-day
Searchable log retention, correlated with your metrics and topology.
0+
Vendor monitoring packs, built from published MIBs — no scripting.
0
Inbound firewall ports. Collectors connect outbound only.
0
Graph for metrics, logs, and topology — not three disconnected tools.
The platform

Five modules. One graph. No integration project.

Monitoring, topology, logs, detection, and collection are one product that shares a single model of your network — not a stack of tools you wire together and hope stays in sync.

Device monitoring

Every device, polled and understood.

ICMP, SNMP, SSH, and REST collection through reusable monitoring packs — per-interface traffic, errors, and system health, with per-second rates already computed server-side.

  • Continuous uptime checks — alerted the moment a device drops.
  • 25+ vendor packs, MIB-verified: Cisco, Juniper, Fortinet, Aruba, and more.
Explore device monitoring
Performance › Metrics
Per-interface traffic, packet, and error charts for a device over the last 24 hours, with computed per-second rates.
Topology graph

See the blast radius before you act.

Links are discovered automatically from LLDP and CDP, then modeled on a live graph. When a device fails, the upstream root cause and every affected downstream device are right there.

  • Dependency and impact analysis across the whole topology.
  • Layouts and filters by class, layer, site, and status.
Explore the topology graph
Explore › Graph Explorer
core-rtr fw-01 dist-a dist-b · down acc-1 acc-2 acc-3 acc-4
dist-b · unreachable1 root cause · 2 downstream affected
Logs & SIEM

Syslog and traps, parsed and searchable.

Ingest syslog and SNMP traps at volume, extract structured fields from raw lines, and search across the fleet or one device — with a full year of retention and cheaper cold storage beyond it.

  • Field extraction turns raw logs into searchable, typed fields.
  • Per-tenant retention by age or size, with a queryable cold tier.
Explore logs & SIEM
Investigate › Logs
Log search across the fleet with structured fields, severity, and a time histogram.
Detections & cases

One detection language for logs and metrics.

Write detections in YARA-L and run them across logs and telemetry alike — scheduled for coverage or streaming at ingest. Every hit is an immutable event; case rules group the noise and alert once.

  • Hybrid engine: scheduled windows plus real-time streaming.
  • Related and flapping events correlate into a single case, automatically.
Explore detections & cases
Investigate › Detections
The detections list: YARA-L rules over logs and metrics with severity, source, and match counts.
Collectors

Agent-less, and outbound only.

A lightweight collector runs in your network as the single collection point for all telemetry — Docker, macOS, or Windows. It connects outbound to the Grid, so there are no inbound ports to open.

  • No per-device agents; assigned to networks, with self-upgrade.
  • Load-balanced backup collectors for per-site fault tolerance.
Explore collectors
Configure › Collectors
The collectors page: connected collectors with health, assigned networks, and version.
The pipeline

How it works

Collection runs inside your network. Correlation, detection, and alerting run in the Grid.

Discover & collect

A collector scans for hosts and services, polls SNMP/SSH/ICMP, and receives syslog and traps.

Correlate

Metrics, logs, and topology come together: devices mapped onto a live graph with their dependencies.

Detect

YARA-L detections and interface thresholds turn signal into prioritized events across logs and metrics.

Resolve

Events group into cases and alert once, to email, Slack, webhooks, or PagerDuty.

Works with your stack

The gear you already run.

Monitoring packs ship for the major vendors, built from published MIBs — and everything speaks the open protocols your network already emits.

Cisco IOS-XE
Cisco Nexus
Cisco ASA
Cisco Meraki
Juniper
Arista
Fortinet
Palo Alto
Aruba
Ubiquiti UniFi
MikroTik
F5
HPE
Dell iDRAC
APC & Eaton
Synology & QNAP
SNMP v2c / v3 SNMP traps Syslog RFC 3164 / 5424 LLDP / CDP SSH ICMP REST / HTTP WebAuthn / passkeys

Need a vendor that isn't listed? Upload its MIBs and pack bundles — OIDs and device tabs appear automatically. Browse vendor packs →

Time to value

Rapid deployment.

A guided Deployment Checklist takes you from an empty account to a fully monitored network with alerting — the moment you sign in. No guessing what to do next.

  • Self-verifying. Each step ticks itself off once the Grid confirms it's done — not just when you click.
  • Every step deep-links to the exact page that satisfies it, so you're always one click from the next action.
  • Same path everywhere — identical on GridNMS Cloud and self-hosted. Dismiss it any time and reopen it from the dashboard.
Join the beta
Pricing

Transparent, published pricing.

Cloud plans start at $49 per month, with unlimited monitored services and unlimited notifications on every tier. Or run it free, self-hosted, with the open-core Community edition. See full pricing and plans →

Cloud

Starting at $49/mo

Fully managed. We run it; you monitor.

  • Graph correlation and impact analysis
  • Host and service discovery
  • YARA-L detections on logs and metrics
  • Automatic case management and alerting
  • Managed TLS, storage, and retention
Join the beta

Self-hosted

Docker

Open-core. Run it on your own infrastructure, free with the Community edition.

  • Free Community edition — core monitoring, 10 devices
  • One-command Docker install
  • Your data stays on your hardware
  • Bring your own TLS certificate
Join the beta See self-hosted details →

Evaluating alternatives? See how the Grid compares to SolarWinds and Auvik.

See your Grid as one system.

Every device, metric, and log on one graph. From $49/month.

Take the tour Join the beta