The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

Observability

NetFlow vs sFlow vs IPFIX: Differences & When To Use

Flow aggregation vs packet sampling - choosing the right export protocol for your network
by Netdata Team · June 24, 2026

NetFlow, sFlow, and IPFIX are three network traffic export protocols that give visibility into traffic flows without requiring full packet capture. NetFlow and IPFIX aggregate packets into flow records on the device before exporting them, providing exact (if unsampled) accounting. sFlow takes a fundamentally different approach: it exports every Nth packet header plus interface counters, making it stateless and scalable but statistical rather than exact. IPFIX is the IETF-standardized evolution of NetFlow v9, adding vendor-neutral extensibility through template-based information elements.

What is NetFlow?

NetFlow is a flow-based traffic export protocol originally developed by Cisco. A network device (router, switch, or firewall) inspects passing packets and groups them into flows based on a common set of attributes - typically the 5-tuple of source IP, destination IP, source port, destination port, and protocol. The device maintains state for each active flow, accumulating byte and packet counts, and exports a flow record when the flow expires or a timer triggers.

Key NetFlow versions:

VersionCharacteristics
v5Fixed-format fields, most widely deployed legacy version
v7Adds NetFlow export for Catalyst switches (aggregation)
v9Template-based and extensible, the basis for IPFIX

NetFlow can operate in unsampled mode (every packet is counted, giving exact accounting) or sampled mode (only a subset of packets is processed, reducing device load at the cost of statistical accuracy).

For a deeper overview, see What is NetFlow?.

What is IPFIX?

IPFIX (IP Flow Information Export), defined in RFC 7011, is the IETF standard that generalizes NetFlow v9. It takes the template-based, extensible design of NetFlow v9 and makes it vendor-neutral. Think of it as “standardized NetFlow v9.”

Key properties of IPFIX:

  • Template-based: The exporter and collector negotiate which fields are included, so the format is not hardcoded.
  • Extensible: Vendors and organizations can define enterprise-specific Information Elements (IEs) for custom fields.
  • Vendor-neutral: Any vendor can implement it, making it suitable for multi-vendor environments.
  • Transport: Typically runs over UDP, SCTP, or TCP, with SCTP offering built-in reliability.

Because IPFIX is a superset of NetFlow v9’s concepts in a standardized form, many modern network devices support both, and collectors often treat NetFlow v9 and IPFIX similarly.

What is sFlow?

sFlow (sampled flow), created by InMon, takes a fundamentally different approach from NetFlow and IPFIX. Instead of aggregating packets into flows on the device, sFlow performs statistical packet sampling: every Nth packet has its header copied and exported as a datagram, along with periodic interface counter samples.

This design has important implications:

  • Stateless on the device: The device does not maintain flow tables or track active flows. It simply samples and forwards.
  • Low overhead: Because there is no flow-state maintenance, sFlow scales to very high link speeds (100Gbps and beyond) with minimal CPU and memory impact.
  • Statistical, not exact: Totals must be scaled by the sampling rate. If 1 in 1,000 packets is sampled, estimated totals are multiplied by 1,000, which introduces statistical variance.

sFlow also exports interface counters (similar to SNMP polling) alongside packet samples, giving a blend of flow-level estimates and counter data.

How Each Protocol Works

The architectural difference between these protocols is best understood by looking at where the work happens.

NetFlow / IPFIX: Device-side aggregation

  1. The device inspects every (or sampled) packet passing through.
  2. Packets sharing the same key fields (5-tuple or extended tuple) are grouped into a flow.
  3. The device maintains state for each active flow in a flow cache.
  4. When a flow expires (timeout, TCP FIN, or cache full), the device exports the aggregated record.
  5. The collector receives complete or near-complete flow records with byte and packet totals.

This model provides accurate flow-level data but requires the device to maintain flow state, which consumes CPU and memory.

sFlow: Device-side sampling

  1. The device samples every Nth packet (configurable rate).
  2. The sampled packet header is exported immediately as a datagram.
  3. No flow state is maintained on the device.
  4. Interface counter samples are exported periodically alongside packet samples.
  5. The collector reconstructs traffic estimates by scaling sampled data.

This model is lightweight on the device but shifts the analysis burden to the collector, which must infer flows from sampled headers.

Comparison Table

DimensionNetFlowIPFIXsFlow
Data modelFlow aggregation (5-tuple based)Flow aggregation (template-based)Packet sampling (1-in-N headers)
AccuracyExact if unsampled; approximate if sampledExact if unsampled; approximate if sampledStatistical estimate only
Device overheadModerate to high (flow state + CPU)Moderate to high (flow state + CPU)Very low (stateless sampling)
StandardizationCisco proprietaryIETF standard (RFC 7011)InMon / sFlow.org
Extensibilityv9 templates; v5 is fixedEnterprise-specific IEs, highly extensibleFixed sample structure
TransportTypically UDPUDP, TCP, or SCTPUDP datagrams
Typical useFlow accounting, security analysisMulti-vendor flow export at scaleHigh-speed traffic estimation, DDoS detection
Scalability ceilingLimited by flow cache sizeLimited by flow cache sizeScales to very high speeds (100G+)

When to Use Each

Choose NetFlow or IPFIX when:

  • You need flow-level accuracy for billing, capacity planning, or compliance.
  • You want rich metadata per flow (AS paths, MPLS labels, VLAN tags, application IDs).
  • You operate in a multi-vendor environment and need standardization (IPFIX).
  • You are doing security analysis where every connection matters (e.g., detecting lateral movement, data exfiltration).

IPFIX is generally the better choice over NetFlow v5 in new deployments because of its extensibility and vendor neutrality.

Choose sFlow when:

  • You operate at very high link speeds where maintaining flow state is impractical.
  • Low device overhead is a priority (you cannot spare CPU on your switches or routers).
  • You can accept statistical estimates rather than exact flow records.
  • You need near-real-time visibility for DDoS detection or traffic anomaly alerts, where directional trends matter more than exact byte counts.

Practical reality: many networks use both

Large networks often deploy sFlow on high-speed core switches (where overhead matters most) and NetFlow or IPFIX on edge routers and firewalls (where flow accuracy and rich fields are more valuable). A capable collector that ingests all three protocols lets you correlate both perspectives.

Common Pitfalls and Misconceptions

1. Treating sFlow totals as exact

sFlow exports sampled headers. If your sampling rate is 1:1,000, multiplying totals by 1,000 gives an estimate - not an exact count. Short-lived flows or low-volume conversations may be entirely missed. Always interpret sFlow data as a statistical sample, and be cautious when using it for billing or exact accounting.

2. Assuming NetFlow v5 and v9 are interchangeable

NetFlow v5 has a fixed field structure with a defined set of columns. NetFlow v9 (and IPFIX) use templates, meaning the collector must first receive and parse the template before it can decode data records. A collector that only understands v5 will not parse v9 or IPFIX correctly.

3. Ignoring sampling in NetFlow

Sampled NetFlow (e.g., 1:100 sampling on a Cisco router) is still NetFlow, but it is not exact. The flow records represent sampled data. If accuracy matters, confirm that the device is configured for unsampled NetFlow.

4. Forgetting that IPFIX is not just “NetFlow v10”

While IPFIX is based on NetFlow v9, it is a distinct IETF protocol with its own specification, transport options, and extensibility model. Treating IPFIX as identical to NetFlow v9 can lead to parsing errors when enterprise-specific IEs are present.

Flow Analysis with Netdata

Netdata’s built-in flow analyzer ingests all three protocols - NetFlow v5/v7/v9, IPFIX, and sFlow v5 - on a single UDP listener. It normalizes sampling rates across protocols, so you can mix NetFlow and sFlow exporters in the same deployment and still get coherent visualizations.

Key capabilities:

  • Top talkers by source and destination IP, with GeoIP and ASN enrichment.
  • Sankey diagrams for traffic flow visualization between endpoints.

Sankey diagram showing network traffic flows between source and destination IPs

  • Geographic maps mapping traffic to physical locations.
  • Time-series metrics for traffic volume, flow counts, and bandwidth over time.

Time-series chart of network flow metrics showing traffic volume over time

This means you do not need separate collectors for NetFlow, IPFIX, and sFlow. Netdata network monitoring normalizes all three into a unified view, which is particularly useful in heterogeneous environments where different device vendors use different export protocols.

FAQ

Is IPFIX better than NetFlow?

IPFIX is more extensible and vendor-neutral than NetFlow, making it the preferred choice for new multi-vendor deployments. However, NetFlow v5 remains the most widely supported legacy format. If your devices support IPFIX, use it. If they only support NetFlow v5 or v9, that is still perfectly useful for traffic analysis.

Can sFlow replace NetFlow?

Not in all scenarios. sFlow is excellent for high-speed traffic estimation with low device overhead, but it is statistical, not exact. If you need precise flow records for billing, compliance, or security forensics, NetFlow or IPFIX in unsampled mode is the right choice. For capacity planning and anomaly detection on high-speed links, sFlow is often sufficient and more scalable.

What sampling rate should I use for sFlow?

The ideal sampling rate depends on link speed and traffic volume. Common guidelines range from 1:1,000 for 1Gbps links to 1:10,000 or higher for 10Gbps+ links. Lower sampling rates improve accuracy but increase device overhead. Test with your specific traffic patterns to find the right balance.

Do NetFlow and sFlow use the same port?

Not necessarily. The default and most common port for NetFlow and IPFIX is UDP 2055, but this is configurable. sFlow typically uses UDP 6343. Both are configurable on both the exporter and collector. Netdata’s flow analyzer listens on a single UDP port and can accept all three protocols on that port.

Can I use NetFlow and sFlow on the same network?

Yes, and many large networks do. A common pattern is sFlow on high-speed core switches and NetFlow or IPFIX on edge routers and firewalls. As long as your collector supports all three - as Netdata does - you can correlate data from both perspectives in a single view.