The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / clickhouse / clickhouse-unauthorized-ddl-drop-table

Operations Guides

ClickHouse unauthorized DROP TABLE: auditing DDL and privilege anomalies

A production table disappears. An application returns “table does not exist.” In ClickHouse, DROP TABLE removes the table definition and MergeTree data parts from disk immediately. On replicated tables, a single ON CLUSTER command propagates through the coordination service and can erase the table everywhere before you intervene. There is no native undo.

This guide is for finding out what happened, determining blast radius, and closing the gaps.

What this means

DROP TABLE is not a slow failure. It removes the table definition and data parts from disk immediately. ReplicatedMergeTree propagates the drop through the coordination service, so a single command can replicate across the cluster before you can intervene. There is no DDL rollback log.

The most common cause is an over-privileged default user. In many legacy deployments, the default account has no password and broad grants. Applications, analysts, or automation that connect as default can execute destructive DDL. Cluster-wide ON CLUSTER commands amplify the risk because they execute on every reachable node.

Common causes

CauseWhat it looks likeFirst thing to check
Over-privileged default userDROP executed by user default from an unexpected hostsystem.query_log filtered by user = 'default' and query_kind = 'Drop'
Compromised service accountDROP issued from a client host outside the known fleetclient_hostname and query timestamp in system.query_log
Human error via client toolAnalyst connected to production instead of staginguser and client_hostname at the exact event time
Application or migration bugUnintended DROP during a deploymentDDL queries from deployment hosts just before the incident, or failed migration queries in system.query_log
Malicious insider or lateral movementLarge SELECT exports followed by DROP from the same sessionCorrelate high read_bytes with DDL in system.query_log

Quick checks

Run these immediately. They are read-only.

-- Destructive DDL in the last hour by user and source host
SELECT
    event_time,
    user,
    client_hostname,
    query_kind,
    substring(query, 1, 200) AS query_prefix
FROM system.query_log
WHERE query_kind IN ('Alter', 'Create', 'Drop', 'Truncate')
  AND event_time > now() - INTERVAL 1 HOUR
ORDER BY event_time DESC;
-- Cluster DDL that did not finish on all replicas
SELECT
    entry,
    query,
    status,
    exception_text,
    query_create_time
FROM system.distributed_ddl_queue
WHERE status != 'Finished'
ORDER BY query_create_time DESC;
-- Privilege exceptions that may indicate probing
SELECT
    event_time,
    user,
    query,
    exception
FROM system.query_log
WHERE exception LIKE '%ACCESS_DENIED%'
  AND event_time > now() - INTERVAL 1 HOUR;
-- Failed login attempts
SELECT
    event_time,
    user,
    client_address,
    auth_type,
    failure_reason,
    type
FROM system.session_log
WHERE type = 'LoginFailure'
  AND event_time > now() - INTERVAL 1 HOUR;
# Verify network exposure
ss -tlnp | grep clickhouse

How to diagnose it

  1. Confirm the event. Query system.query_log for query_kind = 'Drop' around the incident window. Verify whether the query finished (type = 'QueryFinish'). A successful DROP with no exception means the data is gone.
  2. Determine if it was cluster-wide. If the query included ON CLUSTER, inspect system.distributed_ddl_queue. Entries with status != 'Finished' mean some replicas did not execute the drop, leaving schema drift. If all hosts show Finished, the drop propagated everywhere.
  3. Identify the actor. Capture user, client_hostname, and the exact query text from system.query_log. If the user is default, the over-privileged default account is the likely root cause.
  4. Check for reconnaissance. In the minutes before the DROP, look for large SELECT queries from the same user or host with abnormally high read_bytes or result_bytes. Extraction before destruction is a common attack pattern.
  5. Audit privilege grants. Review which accounts hold DDL privileges. Flag service accounts with broader grants than their workload requires.
  6. Inspect replication health. If the table was replicated and the DROP was not uniform, compare system.replicas across nodes. A replica that missed the DDL may still hold the table data, while others do not.
flowchart TD
    A[Table missing or schema changed] --> B{Query system.query_log}
    B -->|Drop found| C[Record user, host, time]
    B -->|No local entry| D{Check system.distributed_ddl_queue}
    D -->|ON CLUSTER drop| E[Check per-replica status]
    D -->|No entry| F[Check system.session_log]
    C --> G[Audit grants for that user]
    E --> H[Schema drift or full propagation]
    G --> I[Revoke excess privileges]
    F --> J[Investigate auth anomalies]
    H --> K[Restore or resync replica]

Metrics and signals to monitor

SignalWhy it mattersWarning sign
system.query_log DDL rateEarly signal of unauthorized schema changesAny Drop or Truncate from non-admin users
system.distributed_ddl_queue statusReveals silent schema drift after cluster DDLstatus != 'Finished' sustained for more than 5 minutes
system.session_log login failuresIndicates brute force or credential misuseMore than 10 failures per minute from a single source
system.query_log read_bytes per userFlags data exfiltration that may precede destructionUnexpected user scanning large volumes followed by DDL

Fixes

Immediate containment

  • Revoke DDL privileges from the affected account immediately. If the session is active, terminate any running queries and rotate the password.
  • Rotate credentials for any service account that issued the DROP.
  • If the event came from an unexpected host, verify ClickHouse is bound to internal interfaces only. ss -tlnp | grep clickhouse should not show public-facing listeners unless explicitly required.

Recovery

  • Restore from backup. ClickHouse has no native point-in-time recovery for DDL. If you have filesystem backups or object-storage snapshots, recreate the table definition and reload the data.
  • If the table was ReplicatedMergeTree and some replicas missed the DROP due to a failed distributed DDL, use SYSTEM RESTART REPLICA to force a re-check against ZooKeeper state. If a replica diverged and lost parts, SYSTEM RESTORE REPLICA re-initializes it from other replicas. Be aware that this is destructive to local divergent state.
  • If no backup exists and one replica still holds the table data, that replica is your recovery source. Do not restart or resync it until you have extracted the data.

Privilege lockdown

  • Do not run applications or ad-hoc tools as the default user. Create named accounts with restricted grants.
  • Restrict the default user to localhost-only connections, or disable it entirely if your deployment allows.
  • Apply role-based access control. Limit ALTER, DROP, CREATE, and TRUNCATE to dedicated administrative accounts.
  • Bind ClickHouse to internal network interfaces via listen_host to reduce exposure.

Guardrails

  • Set max_table_size_to_drop to require an explicit configuration override before large production tables can be dropped. This prevents accidental drops from standard clients.
  • Review distributed_ddl_task_timeout. The default is 180 seconds. If your cluster is large or nodes are under load, short timeouts can leave DDL half-applied, creating silent schema drift.

Prevention

  • Audit before events. Periodically query system.query_log for DDL from unexpected users or hosts. A five-minute audit run once per shift catches drift early.
  • Least privilege. Service accounts should have read or append access only. DDL should require a dedicated admin role.
  • Cluster DDL monitoring. Alert on system.distributed_ddl_queue entries that do not reach Finished. A stuck DDL entry blocks everything queued behind it.
  • Session forensics. Ensure session_log is enabled in the server configuration. Without it, you cannot reconstruct which client addresses connected or failed to authenticate.

How Netdata helps

  • Correlate query latency spikes or error jumps with DDL events using system.query_log trends.
  • Flag anomalous sequences such as a large SELECT followed by DROP from the same session.
  • Alert on replication health shifts (is_readonly, is_session_expired) after cluster DDL to catch skipped nodes.
  • Watch system.query_log growth for unusual volume from attack patterns or runaway automation.
The Netdata solution

ClickHouse monitoring with Netdata

Netdata monitors ClickHouse with per-second metrics and ML anomaly detection. Track merge debt, memory usage, replication lag, Keeper/ZooKeeper saturation, and disk headroom against the host signals that drive them.