The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

Monitoring

SNMP Traps vs Polling: What Is The Difference?

Pull metrics on a schedule or push events in real time - here is how the two SNMP models compare.
by Netdata Team · June 24, 2026

SNMP polling is a pull model where a monitoring server periodically queries a device over UDP port 161 to read metrics and state. SNMP traps are a push model where the device itself sends an unsolicited notification over UDP port 162 the instant an event occurs. The two are not competing choices: mature network monitoring uses polling for continuous metrics and traps for immediate event alerts.

What is SNMP polling?

Polling is the classic request-response model at the heart of SNMP-based monitoring. A central manager (your monitoring system) sends a GET, GETNEXT, or GETBULK request to an SNMP agent running on a router, switch, UPS, or other networked device. The agent responds with the requested values.

Key characteristics:

  • Scheduled and deterministic. You decide the interval - every 30 seconds, every minute, every five minutes - so data points arrive at a predictable cadence.
  • Ideal for continuous metrics. Interface counters, CPU load, memory usage, environmental sensor readings, and configuration state all lend themselves to polling because you want a steady time series, not a one-off event.
  • Reliable at the application layer. If a poll fails, the manager simply retries on the next cycle. Missing data points are visible as gaps, which is acceptable for trend analysis.
  • Blind between polls. If a link flaps and recovers within your poll interval, you may never see it. The faster things change, the less a fixed schedule captures.
  • Scalability ceiling. Polling thousands of OIDs across hundreds of devices at short intervals can exhaust the poller. When the poller falls behind, data becomes late or missing across the board - a problem that grows with fleet size.

What is an SNMP trap?

A trap is an unsolicited, event-driven notification pushed by the device. When something noteworthy happens - a port goes down, an authentication fails, a power supply faults, a BGP session drops - the device sends a trap to a configured management address without being asked.

Key characteristics:

  • Immediate. The notification leaves the device the moment the event is detected, not at the next scheduled poll.
  • Low overhead. The device only sends data when something happens, which is efficient for both the network and the device CPU when events are rare.
  • No delivery guarantee. Traps use UDP port 162, so there is no acknowledgement and no retry at the transport layer. A trap dropped during a burst (a power event that triggers hundreds of devices simultaneously) is gone unless something retransmits it.
  • Vendor-flavored. Trap payloads depend heavily on vendor MIBs. Two vendors may describe the same condition differently, which complicates parsing and normalization.
  • INFORMs add acknowledgement. SNMPv2c and SNMPv3 introduce INFORM requests, which are essentially acknowledged traps. The receiver must confirm receipt, enabling retransmission. This improves reliability at the cost of more protocol overhead.

Traps are not a substitute for continuous metrics. They tell you that an event happened, but they do not give you the ongoing time-series data needed to understand baselines, trends, or the full picture of device health.

SNMP traps vs polling: comparison table

DimensionPollingTraps
Communication directionPull (manager requests)Push (device sends)
Transport / portUDP / 161UDP / 162
TimingScheduled intervalEvent-driven, immediate
ReliabilityManager retries on next cycleNo transport-level guarantee (INFORMs add acknowledgement)
Best forContinuous metrics and state (counters, CPU, memory, topology)Immediate event notification (link down, auth failure, hardware fault)
Key weaknessBlind between polls; poller scalability limitsLossy under burst; vendor-specific payloads; no time-series coverage

How the two models work together

Polling and traps answer different questions. Polling answers “what is the current state and how is it trending over time?” Traps answer “what just happened that I should know about right now?”

Consider a core switch. Polling tells you that interface utilization on port 47 has been climbing for the last hour and that CPU is at 80%. A trap tells you that the BGP session to your upstream provider went down at 14:03:07. Neither message is complete on its own. The trap gives you the precise moment and nature of the event; the polled metrics give you the context to understand why it mattered and whether the device was already under stress.

A monitoring strategy that relies only on traps will miss slow degradation and capacity trends. A strategy that relies only on polling will miss transient events that occur between cycles. Doing both is the standard approach in production network operations.

Common pitfalls and misconceptions

“Traps replace polling.” They do not. Traps carry event data, not time-series metrics. You cannot reconstruct bandwidth utilization, CPU trends, or environmental baselines from traps alone.

“Polling is more reliable than traps.” Only in the sense that the manager controls the cadence and retries. But polling is subject to its own failure mode - poller overload - which can silently degrade data collection across the entire fleet.

“Traps always arrive.” Standard traps (v1 and v2c) use unacknowledged UDP. Under burst conditions or congestion, traps are dropped. If delivery matters, use INFORMs (SNMPv2c/v3) and ensure your receiver handles acknowledgements.

“All vendors describe the same trap.” Trap definitions vary significantly across vendors. A “linkDown” trap from vendor A may include different OIDs and formatting than one from vendor B. Without proper MIB coverage and decoding, traps arrive as opaque hex or generic text, limiting their usefulness.

“Polling faster solves everything.” Reducing the poll interval helps with latency to detection, but it increases load on both the poller and the devices. Eventually the poller cannot keep up, and data quality degrades across all devices, not just the busy ones.

A real-world example

A datacenter has 500 network devices. The monitoring system polls interface counters, CPU, memory, and environmental sensors every 10 seconds. This produces the baseline time series used for dashboards, capacity planning, and anomaly detection.

One morning, a power distribution unit in rack 12 reports a fault. The PDU sends a trap immediately - it does not wait for the next poll. The trap receiver decodes it, assigns a severity, and correlates it against the polled metrics for that device. The on-call engineer sees both the event (power supply fault at 03:14) and the context (the PDU’s temperature had been rising for the previous 40 minutes, visible in the polled data).

Without polling, the rising temperature trend would be invisible. Without traps, the precise moment of the fault and its vendor-specific details would be missed or delayed until the next poll cycle.

SNMP traps and polling with Netdata

Netdata supports both models, so you do not have to choose one or build a separate pipeline for each.

On the polling side, Netdata collects metrics from SNMP devices using 100+ vendor profiles, covering the OIDs and data collection patterns specific to each manufacturer. Where the device and network can sustain it, Netdata polls at per-second granularity, giving you high-resolution time series rather than coarse averages.

On the trap side, Netdata includes a native SNMP trap receiver that decodes v1, v2c, and v3 traps and INFORMs against a library of 150,000+ trap definitions from 800+ vendors. Each decoded trap becomes a structured, categorized, severity-tagged log entry. Because traps, metrics, and topology are unified in one place, you can correlate an event with the exact device metrics and surrounding context without switching tools.

Decoded, severity-tagged SNMP trap log entries

For a deeper look at setting up collection, see the SNMP monitoring guide. To understand how traps are received and decoded in detail, visit the SNMP traps feature page. For the broader picture of monitoring routers, switches, and other network infrastructure, see network device monitoring and the network monitoring solutions page.

FAQ

Should I use SNMP traps or polling?

Use both. Polling gives you continuous metrics and state over time. Traps give you immediate, event-driven notifications. Relying on only one leaves a gap in visibility - polling misses transient events, and traps miss trends and baselines.

Why are SNMP traps unreliable?

Standard SNMP traps (v1 and v2c) use unacknowledged UDP on port 162. There is no transport-level delivery guarantee, and traps can be dropped during bursts or congestion. INFORM requests (v2c and v3) add acknowledgement and retransmission, improving reliability.

What port does SNMP polling use? What port do traps use?

Polling uses UDP port 161 for GET, GETNEXT, and GETBULK requests from the manager to the agent. Traps and INFORMs use UDP port 162, sent from the device to the management station.

Can traps replace polling for monitoring?

No. Traps are event notifications, not time-series data. They tell you something happened, but they cannot provide continuous metrics like interface throughput, CPU utilization, or memory usage over time.

What is the difference between a trap and an INFORM?

A trap is an unacknowledged notification - the device sends it and moves on. An INFORM (introduced in SNMPv2c, also in v3) is an acknowledged notification - the receiver must confirm receipt, and the sender retransmits if no acknowledgement arrives. INFORMs are more reliable but add protocol overhead.