The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / apache-httpd / apache-httpd-config-test-failed ▌

Operations Guides

Apache configtest and Include wildcards: catching bad config before it bites

apachectl configtest (equivalent to httpd -t) parses your Apache configuration and reports Syntax OK or a specific error. It is the cheapest safety check in your toolchain, and it is the main thing standing between a bad edit and the stale-config trap: the state where you believe a new configuration is live, but Apache rejected it at reload time and is still running the old one.

The trap works like this. You edit a config file, run a graceful reload, and move on. If the reload fails the config check, the old configuration keeps running and the new one is discarded. Nothing in the process table or access log tells you. The only evidence is a few lines in the error log that nobody greps. Hours later, someone restarts Apache for an unrelated reason and the server fails to come up, because the config on disk was never valid.

This guide covers what configtest actually validates, the Include wildcard behaviors that quietly change which files Apache reads, the warnings that mask real problems, and how to wire configtest into your reload path so bad config never reaches a running server.

What configtest validates, and what it does not

apachectl configtest and httpd -t parse the full configuration tree and report syntax errors, unresolved directives, and structural problems. Exit code 0 on success, non-zero on failure. On Windows the equivalent is httpd.exe -t.

What it catches:

  • Syntax errors in the main config and in any file pulled in by Include or IncludeOptional.
  • Directives from modules that are not loaded, which show up as unknown directive errors.
  • SSL certificate and key path or format problems referenced in the config.
  • Structural mistakes: unclosed containers, directives in the wrong context, malformed VirtualHost blocks.

What it does not catch:

  • Runtime behavior. A config can pass configtest and still fail under traffic: backend unreachable, permissions wrong on a document root, a handler that crashes on the first request.
  • Whether the server is running or serving anything. apachectl -t validates syntax only. It proves nothing about the live process.
  • Problems that only appear when new children spawn. A graceful reload can succeed at the parent level while new-generation children fail to start on runtime errors the syntax check never saw, leaving the old children to carry the load on a shrinking pool.

Treat configtest as a gate, not a guarantee. It answers one question: will Apache accept this configuration tree? Ask it before every reload. The cost of asking is a fraction of a second; the cost of a wrong answer is the next restart.

The stale-config trap

The reload path is where config errors do the most damage, and the behavior is not uniform.

Upstream, apachectl restart and apachectl graceful run configtest before acting, so a broken config stops the restart rather than killing the running server. But whether a given distribution’s graceful path checks config before reloading varies, and plenty of reloads never go through apachectl at all: logrotate scripts, configuration management, systemd reload units, and kill -USR1 all bypass whatever wrapper logic exists.

When a direct kill -USR1 reload fails the config check, the running configuration stays, the new one is discarded, and the record is in the error log; a wrapper that runs the test first can stop before signaling. Detect it directly:

# Confirm current config is valid right now
apachectl configtest 2>&1

# Look for failed reloads versus successful ones
grep -iE "resuming normal operations|syntax error|configuration error" \
  /var/log/apache2/error.log 2>/dev/null | tail -10
# RHEL path: /var/log/httpd/error_log

If you see a syntax error timestamped after your last change and no “resuming normal operations” after it, the running server is on stale config. Fix the file, re-run configtest, and reload again. Do not assume the next deploy will sort it out: the next deploy edits the same broken file and fails the same way.

A second, quieter variant: the syntax check passes but runtime errors prevent new children from starting after a graceful restart. Old children keep serving on the old config while the pool drains. The tell is repeated child startup failures in the error log around a reload, with no matching outage in the access log. This is why “configtest passed” is necessary but never sufficient evidence that a reload landed.

Include wildcards: the quiet footgun

Include and IncludeOptional accept wildcards, which is how most distributions wire up sites-enabled/*.conf and conf.d/*.conf. Two behaviors matter operationally.

Wildcard directories accept anything. Any file matching the pattern is parsed, in full, as Apache configuration. A .conf file dropped into an included directory by a package install, a config management run, a careless cp, or a leftover from a decommissioned vhost becomes live configuration on the next reload. Nothing warns you that a file you did not write is now part of the server. The set of files Apache reads is whatever happens to be on disk, not whatever you think you deployed. Periodically audit what the wildcards actually resolve to:

# See every file a given Include wildcard will pull in
ls -1 /etc/apache2/sites-enabled/*.conf 2>/dev/null
ls -1 /etc/httpd/conf.d/*.conf 2>/dev/null

Zero matches behave differently for the two directives. Include with a wildcard that matches nothing is a hard failure: configtest errors out and the server will not start or reload. IncludeOptional with a non-matching wildcard is silently ignored. The same applies to non-existent paths: IncludeOptional ignores them (on 2.4.30 and later for plain paths without wildcards; older releases could still error). The practical rule: use Include only when a missing file should be fatal because the config is meaningless without it, and IncludeOptional for optional drop-in directories that may legitimately be empty. An empty sites-enabled directory with a plain Include will take your server down on the next restart.

To see the configuration Apache actually resolved, with all includes expanded, dump the pre-parsed tree:

# Dump the fully resolved configuration (mod_info required)
httpd -DDUMP_CONFIG -k start 2>/dev/null | head -50

This is the fastest way to answer “which of these files is actually in effect” when a vhost behaves unexpectedly. It shows the config as Apache sees it, not as you organized it.

Warnings that mask real problems

Configtest output mixes fatal errors with warnings, and the warnings train people to stop reading. Two regulars:

  • AH00548: NameVirtualHost has no effect and will be removed in the next release. The directive is deprecated; since 2.3.11 Apache enables name-based virtual hosting automatically when multiple vhosts share an address/port, and the directive currently has no effect. Remove the line: it is noise that hides real output.
  • AH01574: module security2_module is already loaded, skipping. Usually a duplicate LoadModule line, often from a wildcard include pulling the same module config twice. Harmless in itself, but it tells you your include tree has redundancy, and it sits in the same output stream as genuine syntax errors.

The failure mode is not the warnings; it is operator habit. When every configtest prints three lines of ignorable warnings, the fourth line, the real error, gets skimmed past. Hold a standard of zero errors and zero warnings from configtest, so that any output at all is signal.

Making configtest a pre-reload gate

The fix for the stale-config trap is procedural: never reload without a passing configtest immediately before it, in the same shell or the same automation step.

flowchart TD
    A[Edit config files] --> B[apachectl configtest]
    B -->|exit 0| C[graceful reload]
    B -->|exit non-zero| D[Fix config, do not touch running server]
    C --> E[Check error log for child startup failures]
    E -->|clean| F[Reload landed]
    E -->|errors| G[New children failing - old config still serving]

Manual workflow:

# Gate the reload on a clean config test
apachectl configtest && apachectl graceful

For automation, apply the same pattern in whatever runs your deploys:

  • Config management (Ansible, Puppet, Chef): validate the rendered config with httpd -t against the new files before notifying the reload handler. Most modules support a validate command on the template or file resource. A failed validation should fail the run, not skip the reload.
  • systemd reload units: check what your distribution’s ExecReload actually runs. If it is a bare kill -USR1, wrap it or prefer apachectl graceful, and keep the habit of running configtest first yourself.
  • Log rotation: rotation scripts that signal Apache should use graceful restart, not kill -HUP, which drops all connections. Rotation is not the moment to discover the config on disk is broken.

Verify reload success after the fact, not just config validity before it: check the error log for “resuming normal operations” and for child startup errors in the seconds after the reload. A reload is only done when the new generation is serving.

Signals to monitor

SignalWhy it mattersWarning sign
Configtest exit code (run in CI and pre-reload)The gate itself; non-zero means the config on disk cannot be loadedAny non-zero result reaching production unexamined
Error log around reload eventsRecords failed reloads and new-child startup failuresSyntax error or startup failure after a reload, with no “resuming normal operations”
“resuming normal operations” entriesConfirms a reload actually landedMissing entry after an expected reload; or many close together, indicating restart pile-up
ServerUptimeSeconds / restart eventsDistinguishes graceful reloads from crashes and hard restartsUnexpected restarts correlating with config changes
Files in wildcard include directoriesThe effective config surface.conf files present that no deploy created

How Netdata helps

  • Netdata collects Apache signals from mod_status at per-second granularity, so a reload that quietly failed shows up as a configuration that never changed its behavior, visible against the timeline of your deploy events.
  • Uptime and restart tracking surfaces unexpected restarts and lets you line them up against config changes, which is how you catch a bad config that only detonated on the next restart.
  • Error rate and worker utilization charts show the downstream signature of a stale config: you deploy a fix, the 5xx rate does not move, and that mismatch is the clue the reload never landed.
  • Error log pattern monitoring catches the reload-time messages (“resuming normal operations”, syntax errors, child startup failures) that operators otherwise never grep for until an outage.
  • Correlating deploy annotations with scoreboard state after a graceful restart reveals the nastier variant, where old-generation workers linger and new children fail, as a persistent shift in worker counts and memory after each reload.

Netdata’s Apache HTTP Server monitoring with Netdata brings these signals together with per-second metrics and ML anomaly detection.

The Netdata solution

Apache HTTP Server monitoring with Netdata

Netdata monitors Apache HTTP Server with per-second metrics from mod_status, pre-built dashboards, and ML-powered anomaly detection. Watch busy versus idle workers and the scoreboard state mix, requests per second, bytes served per second, and request processing duration alongside the rest of your stack, so you catch the worker-exhaustion, slow-backend, and memory incidents in these runbooks before they page anyone.