Take the tour.

Six screens, one workflow: from the whole network at a glance, down to a single case with the noise already grouped. This is the product as you'll actually use it — no login required.

1

Start with the whole network at a glance.

The dashboard opens on what matters right now: how many devices are up or down, and the open events ranked by severity across your routers, switches, and firewalls. Every panel is a drag-and-drop widget, so the view is yours to arrange.

Home › Dashboard
The GridNMS dashboard with device status counters and an open-events panel ranked by severity.
2

Follow the links, and the blast radius.

The topology graph maps every device and the links discovered from LLDP and CDP, colored by live status. When something goes down, you see the upstream cause and everything downstream that went with it — not forty disconnected alerts.

Explore › Graph Explorer
core-rtr fw-01 dist-a dist-b · down acc-1 acc-2 acc-3 acc-4
dist-b · unreachable1 root cause · 2 downstream affected
3

Drill into one device, end to end.

Open any device for its interfaces, metrics, logs, and neighbors on dynamic tabs driven by its monitoring pack. Per-interface traffic, errors, and system health arrive with per-second rates already computed, so the charts read at a glance.

Inventory › Devices › core-rtr-01
A device detail page with tabs for interfaces, metrics, and logs, showing per-interface charts.
4

Search every log, structured and fast.

Syslog and traps land in one searchable store, with fields extracted from raw lines so you can filter by device, severity, or any parsed value. A full year of history stays queryable, with a cheaper cold tier beyond it.

Investigate › Logs
Fleet-wide log search with structured fields, a severity histogram, and time controls.
5

Turn signal into a prioritized event.

Detections are written once in YARA-L and run across both logs and metrics — scheduled for coverage or streaming at ingest. Each hit becomes an immutable event with a clear severity, ready for correlation and alerting.

Investigate › Detections
The detections list of YARA-L rules over logs and metrics, with severity, source, and match counts.
6

Let the noise group itself into one case.

Case rules correlate related and flapping events into a single case over a window you define, so a storm becomes one alert with full context. Cases are the workbench where you investigate and resolve — and they close on their own once things go quiet.

Investigate › Cases
A case grouping multiple related events with severity, affected devices, and status.

Ready to run it on your own network?

From $49/month. Cloud-hosted, or self-hosted with Docker.

See all features Join the beta