The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

Observability

Network Topology Mapping Explained

How devices connect, how discovery works, and why live topology beats static diagrams
by Netdata Team · June 24, 2026

Network topology mapping is the process of discovering and visualizing how devices, endpoints, and services connect across a network. It captures both physical (Layer 2) relationships - which switch port links to which device - and logical (Layer 3) relationships - how subnets, routes, and autonomous systems reach each other. A topology map can range from a hand-drawn diagram to a live, continuously updated graph built from protocol data such as LLDP, CDP, ARP, FDB, OSPF, and BGP.

What Is Network Topology Mapping?

At its core, network topology mapping answers a deceptively simple question: “What is connected to what?” The answer matters because almost every operational task - diagnosing a slow application, planning a capacity upgrade, isolating a failed link, verifying segmentation - depends on understanding the connectivity graph.

Topology maps serve several purposes:

  • Visibility: operators can see the full fabric at a glance instead of tracing cables or reading configuration files one device at a time.
  • Root cause analysis: when an application or endpoint is unreachable, the map shows the path and highlights where it breaks.
  • Change validation: after a configuration change or hardware swap, the updated map confirms that the intended connections exist and no unexpected ones appeared.
  • Security and compliance: mapping can reveal unauthorized devices, rogue access points, or segmentation violations.

A topology map is typically represented as a graph: nodes are devices, interfaces, VLANs, or even application processes, and edges are links, adjacencies, or connections.

How Network Topology Mapping Works

Topology mapping is fundamentally a data-collection and correlation problem. The map is only as accurate as the underlying data sources, and different sources reveal different layers of connectivity.

Layer 2 (Physical) Discovery

Layer 2 topology answers “which physical port on which switch connects to which device.” The primary data sources are:

SourceWhat It RevealsLimitations
LLDP (Link Layer Discovery Protocol)Directly connected neighbors, port descriptions, chassis IDsMust be enabled on both ends; not all endpoints speak LLDP
CDP (Cisco Discovery Protocol)Same as LLDP but Cisco-proprietaryOnly works between Cisco devices
FDB / MAC address tableWhich MAC address is on which switch portMust be read from every switch; ages out quickly
STP (Spanning Tree Protocol) stateWhich ports are forwarding vs blockingOnly shows the tree, not all physical links
ARP tableIP-to-MAC mappingsPer-device; ages out (minutes to hours)

LLDP and CDP are the most reliable sources for directly connected network devices because they explicitly advertise neighbor identity and port information. However, many endpoints - servers, IoT devices, virtual machines - do not run these protocols, so their position must be inferred by combining ARP tables (IP to MAC) with FDB entries (MAC to port). Some environments also use DHCP snooping tables or 802.1X accounting logs to improve endpoint positioning.

This inference is probabilistic. If the FDB entry for a MAC has aged out, the endpoint cannot be confidently placed on a specific port. A topology built from a partial snapshot is inherently less reliable than one built from fresh, complete data.

Layer 3 (Logical) Discovery

Layer 3 topology answers “how do subnets, routes, and autonomous systems reach each other?” The data sources include:

  • Routing tables: show installed routes, next hops, and interfaces.
  • OSPF (Open Shortest Path First): link-state database reveals the full area topology, including router adjacencies and link costs.
  • BGP (Border Gateway Protocol): reveals AS-level connectivity, peering relationships, and path attributes.

Layer 3 maps are especially valuable in multi-site, data center, or cloud environments where traffic traverses multiple routing domains. They help operators understand reachability, traffic engineering paths, and failover behavior.

Application Layer Discovery

Beyond network devices, modern topology mapping can extend to the application layer. Live TCP and UDP connections between processes, containers, and services form an application connectivity graph that sits on top of the network fabric. This is critical for microservice architectures where the logical service topology changes far more frequently than the physical network.

Key Data Sources at a Glance

LayerData SourceInformation Gained
L2LLDP / CDPDirect neighbor identity and ports
L2FDB / MAC tableMAC-to-switch-port mapping
L2STP stateForwarding vs blocked links
L2ARP tableIP-to-MAC resolution
L3Routing tableInstalled routes and next hops
L3OSPF LSDBArea topology and adjacencies
L3BGPAS-level peering and path info
AppTCP/UDP connection tablesProcess and container connectivity

A Concrete Example

Consider a data center with two core switches, four top-of-rack (ToR) switches, and forty servers. LLDP is enabled on all network devices, so the core-to-ToR links are immediately visible. However, the servers do not run LLDP.

To place each server on the topology map:

  1. The mapper collects the ARP table from the ToR switch, learning the MAC address associated with each server IP.
  2. It collects the FDB from the same ToR switch, learning which physical port hosts each MAC address.
  3. The two tables are joined: IP -> MAC -> port.

If a server was recently powered on and its FDB entry has not yet been learned, the mapper cannot confidently place it. Similarly, if a server has been silent for longer than the FDB aging time, its position may go stale. This is why topology that relies on a single snapshot degrades quickly.

Static Diagrams vs Live Topology

The traditional approach to topology mapping is a manually maintained diagram in a tool like Visio or draw.io. These diagrams have a well-known problem: they are accurate only at the moment of creation. Networks change constantly - devices are added, links are re-cabled, VLANs are reconfigured, failover paths activate. A static diagram is a point-in-time artifact that goes stale almost immediately.

AspectStatic DiagramLive Topology Map
FreshnessStale on creationContinuously updated
Effort to maintainManual, error-proneAutomated from protocol data
Change detectionNoneImmediate
Root cause usefulnessLimitedHigh - shows current state
ScaleHard to maintainHandles large fabrics

Live topology mapping addresses this by continuously polling or streaming discovery data from the devices themselves. The map reflects the actual state of the network, not someone’s best recollection of last quarter’s design.

Common Pitfalls and Misconceptions

“LLDP gives me the complete topology.” LLDP only reports directly connected neighbors that also run LLDP. Endpoints, virtual machines, and devices from vendors that disable LLDP by default will be invisible without supplementary FDB and ARP correlation.

“One snapshot is enough.” FDB and ARP tables age out within minutes. A topology map built from a single poll is a probabilistic snapshot, not a ground-truth statement. The more frequently data is collected, the more reliable the map.

“Layer 2 and Layer 3 are the same map.” They are related but distinct. A Layer 2 map shows physical links and switch ports. A Layer 3 map shows routing adjacencies and reachability. A single physical link can carry multiple logical paths, and a single logical path can traverse many physical links.

“Topology mapping is only for network engineers.” Application teams benefit from understanding the connectivity graph too. Knowing which container talks to which database over which network segment is essential for troubleshooting latency, planning segmentation, and validating service meshes.

Network Topology Mapping with Netdata

The Netdata Topology Viewer builds the connectivity map live, directly in the agent. It maps the SNMP device fabric using LLDP, CDP, BGP, and OSPF, supplemented by FDB and STP inference with tunable confidence levels for endpoints that do not advertise themselves via neighbor discovery protocols.

Beyond the network fabric, the Topology Viewer also maps the application layer - live TCP and UDP connections between processes and containers. This means you can see not only how switches and routers are connected, but how applications actually use those connections.

Inferred device fabric graph showing network topology

You can click any actor in the map - a network device, a container, a process, or a node - to trace its dependencies (what it connects out to) and its dependants (what connects in to it). This turns the topology map from a static picture into an interactive troubleshooting tool.

Device detail with port neighbors and connections

For teams that need end-to-end visibility, Netdata’s network device monitoring complements the topology view with per-interface metrics, SNMP-based health data, and alerts. Combined with SNMP monitoring, the topology map stays grounded in real protocol data rather than guesses.

FAQ

What is network topology mapping?

Network topology mapping is the process of discovering and visualizing how devices, endpoints, and services are connected. It covers physical (Layer 2) connections like switch ports and links, and logical (Layer 3) connections like routing adjacencies and subnets.

What protocols are used for network topology discovery?

Common discovery protocols include LLDP and CDP for direct neighbor discovery, FDB/MAC tables and ARP tables for endpoint positioning, STP for link state, and OSPF and BGP for Layer 3 routing topology.

What is the difference between Layer 2 and Layer 3 topology?

Layer 2 topology shows physical connections - which switch port links to which device. Layer 3 topology shows logical routing relationships - how subnets, areas, and autonomous systems reach each other. Both are needed for a complete picture.

Why do static network diagrams go stale?

Static diagrams are manually created snapshots. Because networks change frequently through device additions, link changes, VLAN reconfigurations, and failover events, a static diagram becomes inaccurate almost immediately after it is created.

Can topology mapping show application connections?

Yes. Modern topology tools can map live TCP and UDP connections between processes, containers, and services, providing an application-layer connectivity graph on top of the physical and logical network fabric.

How does Netdata build its topology map?

The Netdata Topology Viewer builds the map live from LLDP, CDP, BGP, OSPF, FDB/STP inference, and live application-layer connections. It supports tunable confidence levels for inferred endpoints and lets you trace dependencies and dependants for any node in the graph.