Malmö stad runs the digital services behind a city of roughly 366,000 people. Waste collection schedules, school administration, social services intake, the public-facing sites residents use to reach any of it. The IT team responsible for keeping that infrastructure healthy is between two and five people, and it covers every environment the city operates: development, test, staging and production.
That ratio is the whole story. A team that size cannot afford to spend a day chasing one slow system, and for years the tooling gave them no way to avoid it.
A stoplight board, and not much else
The previous monitoring came from IDERA Uptime Monitor. It answered exactly one question: is this thing up or is it down. That question has value, but it is the question you can already answer by trying the service yourself. Everything a small team actually needs from monitoring begins one step later, at why.
“It was okay, but pretty old school and outdated by the time we left it. It was mostly acting as a ‘stoplight’ board for us. It also had almost no built-in troubleshooting, which Netdata has plenty of.”
Johnnie Midelf
IT-Specialist, Malmö stad
There was a second problem, quieter but more corrosive. Agent support for new Linux distributions could take months to arrive. That turns every operating system upgrade into a choice between two bad options: delay the upgrade and carry the security debt, or upgrade on schedule and run those machines unmonitored until the vendor catches up. Neither is a decision a public-sector team should have to make.
Three things decided the replacement: predictable cost, the breadth of integrations, and open source. The last one carries particular weight for a municipality. Operational telemetry from public services is public-sector data, and keeping it under the city’s own control is a governance position, not a preference.
Where Netdata AI changed the work
Replacing the tool raised the floor. What changed the shape of the team’s week was Netdata AI.
“Ever since Netdata included AI insights, I can now use Netdata to troubleshoot really difficult issues, and even detect and find attacks, memory leaks and so on. I can ask it to generate the exact reports that I want, and to look exactly like I want. Prior to Netdata, we only had one basic reporting format, that didn’t really help much.”
Johnnie Midelf
IT-Specialist, Malmö stad
Two capabilities carry most of that. The first is investigation. Rather than an engineer forming a hypothesis and then manually checking it against the evidence, the AI is pointed at the problem and reads the evidence directly, including volumes of log data no person would work through by hand. The class of problem that opens up is specific: attacks and memory leaks are both slow, distributed signals that hide well in noise and reveal themselves only across a lot of data. They are precisely what a stoplight board cannot see.
The second is reporting, which sounds administrative until you consider who it is for. A municipal IT team reports to service owners, to management, and periodically to auditors, and each of those audiences wants a different cut of the same underlying data. One fixed format serves none of them well. Being able to ask for the exact report, in the exact shape, removes a recurring tax that fell on a team with no spare capacity to pay it.
Several gigabytes of logs, in under 30 minutes
The clearest demonstration came when reports arrived that a mission-critical system was running slow. Netdata confirmed the slowdown quickly. Confirmation was never the hard part.
Time to root cause on a mission-critical slowdown, before and after Netdata AI. Both figures are the team's own.
“With Netdata AI insights I could ask it to read through several gigabytes of logs to pinpoint several issues that were the root cause. We applied the suggested solutions and the system was back to normal operation. All this was done in less than 30 minutes. Prior to Netdata this would have been a full day of work.”
Johnnie Midelf
IT-Specialist, Malmö stad
The detail worth dwelling on is that there were several causes, not one. Multi-cause problems are where manual triage quietly fails: an engineer finds the first plausible explanation, fixes it, sees partial improvement, and moves on because there is other work waiting. The remaining causes stay in place and the problem returns in a week. Reading enough evidence to find all of them is exactly the work that gets abandoned under time pressure, and it is the work that got automated here.
What it adds up to
- Root cause analysis that finishes: Investigations that would have consumed a working day now resolve in minutes, and they surface every contributing cause rather than the first one found.
- Reporting that fits the audience: The team specifies what a report should contain and how it should look, instead of reshaping one fixed format for every reader.
- A wider net: Attacks and memory leaks are now things the team detects, rather than classes of problem the old tool was structurally blind to.
- Roughly 10 engineer-hours a week returned: mostly out of reporting and troubleshooting, on a team where that is a meaningful fraction of total capacity.
- Upgrades on the city’s schedule: New Linux releases no longer mean months of unmonitored machines or a deferred upgrade.
For a team of two to five people covering a city’s infrastructure, the binding constraint was never skill or willingness. It was hours in the week. That is what changed.
Discover how Netdata can elevate your operations. Learn more.







