The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / logstash / logstash-input-specific-failure-multi-input ▌

Operations Guides

Logstash one input stopped: per-input failures masked by aggregate metrics

One of three inputs in your Logstash pipeline stops receiving events. The pipeline-level events.in counter drops by a third. But because the other two inputs keep flowing, the aggregate rate never hits zero, and your threshold-based alert stays silent. The failed input’s upstream source starts accumulating: Kafka consumer lag grows, file tails fall behind, or Beats agents buffer locally. By the time someone notices, hours or days of data from that source are delayed or lost.

The Logstash Node Stats API exposes per-input counters and, in recent versions, per-input throughput metrics that make this failure immediately visible. Most monitoring setups collect only pipeline-level aggregates.

What this means

When a single input plugin fails or stalls in a multi-input pipeline, the symptoms are subtle:

  • Pipeline status shows running. The process is alive. The monitoring API responds normally.
  • Aggregate events.in continues to grow, just more slowly. Without baseline-relative rate tracking, the partial drop is invisible.
  • Queue depth stays normal or low because the remaining inputs produce events the pipeline can comfortably process.
  • Output rate looks healthy. Events are being delivered. No output errors.
  • No alerts fire because everything is “up.”

The specific data source feeding the failed input is no longer being ingested. Depending on the source type:

  • Kafka: consumer group lag grows continuously. Data accumulates in Kafka partitions within the retention window, but if retention expires before the input recovers, data is permanently lost.
  • Beats: agents buffer events in their local memory and spool queue. Once those fill, Beats begins dropping events at the source.
  • JDBC: scheduled queries stop executing. No database polling occurs, so data accumulates in the source tables unprocessed.
  • File: file tails stop advancing. Sincedb position freezes, and once the source rotates or purges logs, the missed data is gone.
flowchart TD
    A["Multi-input pipeline"] --> B["Input A: healthy"]
    A --> C["Input B: failed"]
    A --> D["Input C: healthy"]
    B --> E["Aggregate events.in still growing"]
    C --> E
    D --> E
    E --> F["Absolute threshold: not crossed"]
    F --> G["No alert fires"]
    C --> H["Upstream data accumulates
Kafka lag, Beats buffer, files pile up"]

Common causes

CauseWhat it looks likeFirst thing to check
Kafka consumer thread deathOne Kafka input shows zero events.out while topic partitions have messages. Consumer group may show the Logstash instance as inactive. No error in some cases.Check consumer group lag on the Kafka broker and plugins.inputs[].events.out for the Kafka input.
Beats input port conflictBeats input fails to bind its listen port because another process (or a previous Logstash instance) holds it. Other inputs start normally.ss -tlnp | grep <port> and Logstash log for bind errors.
JDBC connection lostJDBC input stops running scheduled queries. No error log in some cases. Last successful query timestamp is stale.Check JDBC connection string, database reachability, and plugins.inputs[].events.out for the JDBC input.
Credential or certificate expiryInput fails TLS handshake or authentication. Error appears in logs but pipeline keeps running on other inputs.grep -Ei '(SSL|TLS|certificate|handshake|authentication|unauthorized)' /var/log/logstash/logstash-plain.log
Source-side failureThe upstream system stopped sending. Logstash input is healthy but idle because no data arrives.Check source system health independently: Kafka topic production rate, Beats agent status, database row counts.
Network partition to one sourceOne input cannot reach its source while others on different network paths are fine.Check network connectivity to the specific source host and port.

Quick checks

# Check per-input event counters - identify which input stopped
curl -sS http://127.0.0.1:9600/_node/stats/pipelines | python3 -c "
import sys,json
data = json.load(sys.stdin)
for pname, pdata in data.get('pipelines',{}).items():
    inputs = pdata.get('plugins',{}).get('inputs',[])
    for inp in inputs:
        evts = inp.get('events',{})
        print(f\"pipeline={pname} input={inp.get('id','?')} type={inp.get('name','?')} events_out={evts.get('out',0)} failures={evts.get('failures',0)}\")
"

This shows the cumulative events.out counter per input plugin. Take two samples 30 to 60 seconds apart. An input whose counter is not advancing has stopped processing.

# Check per-input throughput (Logstash 8.6+ with flow metrics)
curl -sS http://127.0.0.1:9600/_node/stats/pipelines | python3 -c "
import sys,json
data = json.load(sys.stdin)
for pname, pdata in data.get('pipelines',{}).items():
    inputs = pdata.get('plugins',{}).get('inputs',[])
    for inp in inputs:
        flow = inp.get('flow',{})
        thr = flow.get('throughput',{})
        print(f\"pipeline={pname} input={inp.get('id','?')} throughput_current={thr.get('current','N/A')} throughput_lifetime={thr.get('lifetime','N/A')}\")
"

The flow.throughput metric provides a pre-computed events/second rate per input, eliminating the need to sample counters manually. An input with throughput.current at zero while others show non-zero values is the failed input. This metric is available in Logstash 8.6 and later. On earlier versions, rely on delta sampling of plugins.inputs[].events.out.

# Search logs for errors from the specific input plugin
grep -Ei '(error|exception|failed|timeout|refused|unauthorized)' /var/log/logstash/logstash-plain.log | tail -n 200

# Check TLS/auth failures specifically
grep -Ei '(SSL|TLS|certificate|handshake|authentication|forbidden|unauthorized)' /var/log/logstash/logstash-plain.log | tail -n 200

# Verify pipeline status and aggregate event counts
curl -sS http://127.0.0.1:9600/_node/stats/pipelines | python3 -c "
import sys,json
data = json.load(sys.stdin)
for pname, pdata in data.get('pipelines',{}).items():
    print(f\"pipeline={pname} status={pdata.get('status','?')} events_in={pdata.get('events',{}).get('in',0)}\")
"

How to diagnose it

  1. Identify the stopped input. Pull per-input stats from the Node Stats API and compare events.out counters across inputs. The input with a flat counter is the one that failed. On Logstash 8.6+, use flow.throughput.current for an instant rate comparison without sampling.

  2. Determine whether the failure is in Logstash or upstream. Check the source system independently:

    • Kafka: check consumer group lag and whether the Logstash consumer is still a member of the group.
    • Beats: check whether agents are connected and sending. If Logstash backpressured the Beats input, agents may have disconnected.
    • JDBC: check whether the database is reachable and the connection string is valid.
    • File: check whether the source files still exist and are being written to.
  3. Check the Logstash log for that plugin’s errors. The log file is often the only place where plugin-level errors appear. The API gives you counts. The log gives you the cause. Search for the input plugin name or type in the log.

  4. Check whether the input’s thread is alive. Use the hot threads API to inspect thread state. A dead or blocked input thread may not produce an error in the log.

# Check hot threads for blocked or dead input threads
curl -sS 'http://127.0.0.1:9600/_node/hot_threads?threads=20&human=true'
  1. Check config reload state. A failed reload may have changed which inputs are loaded, or left the pipeline running with a stale configuration that no longer includes the affected input.
curl -sS http://127.0.0.1:9600/_node/stats/pipelines | python3 -c "
import sys,json
data = json.load(sys.stdin)
for pname, pdata in data.get('pipelines',{}).items():
    r = pdata.get('reloads',{})
    print(f\"pipeline={pname} reload_failures={r.get('failures',0)} last_error={r.get('last_error','N/A')}\")
"

Metrics and signals to monitor

SignalWhy it mattersWarning sign
Per-input events.out counterCumulative events pushed by each input. A flat counter means that input stopped.One input’s counter stops advancing while others continue.
Per-input flow.throughput.current (8.6+)Pre-computed events/second per input. Instant detection without manual sampling.Zero throughput on one input while others are non-zero.
Per-input failures counterPlugin-level error count. Non-zero values indicate the input encountered errors.Sudden increase in failures for one input.
Pipeline-level flow.input_throughputAggregate input rate. Useful as a baseline, but cannot identify which input failed.Partial drop from baseline without corresponding output or filter change.
Source-side metrics (Kafka lag, Beats queue depth)The upstream accumulation is the downstream symptom of this failure.Growing lag or queue depth at the source for one specific data feed.
reloads.failures counterA failed config reload can silently change which inputs are active.Non-zero failure count with no corresponding investigation.

Fixes

Kafka consumer thread death

Kafka input threads can die without restarting the plugin. This has been observed when a Kafka topic is deleted or a commit fails. The consumer thread dies but Logstash continues running other inputs without restarting the failed one.

Immediate fix: Restart the Logstash pipeline to reinitialize the Kafka consumer. This is one of the cases where a pipeline restart is necessary because the plugin does not self-heal.

Preventive measures:

  • Set enable_auto_commit => true in the Kafka input configuration so commits happen in the background rather than depending on the consumer thread remaining alive.
  • Know there is no auto-restart for dead input threads. Logstash has no mechanism to restart a failed input plugin thread; the logstash-input-kafka issue #287 thread documents consumer-thread death (for example after a topic deletion) where the plugin never self-heals and only a pipeline or process restart recovers it. pipeline.recoverable (Logstash 9.4 and later) restarts crashed pipelines, not dead input threads.

Beats input port conflict

If another process binds the Beats listen port before Logstash starts, the Beats input fails to initialize. Other inputs start normally, masking the failure.

Fix: Identify and stop the conflicting process:

# Find what holds the port
ss -tlnp | grep <port>
# Or with lsof
lsof -i :<port>

Then restart Logstash. If the conflict is from a previous Logstash instance that did not shut down cleanly, ensure the process is fully stopped before starting a new one. See Logstash address already in use for deeper coverage of port conflicts.

JDBC connection lost

JDBC input can stop executing scheduled queries without producing error logs. The input appears configured but silently goes idle. The pod or process stays in a healthy state.

Fix: Verify database connectivity from the Logstash host:

# Test raw connectivity to the database
nc -zv <db_host> <db_port>

If connectivity is fine, restart the pipeline to reinitialize the JDBC connection. Review the JDBC input’s schedule and jdbc_connection_string settings. If the database has connection timeouts or idle session limits, the JDBC driver may silently lose its connection without the input noticing.

Credential or certificate expiry

TLS certificate expiry on an input (for example, mutual TLS with a Kafka broker or HTTPS source) causes the connection to fail while other inputs on different trust chains continue.

Fix: Rotate the expired certificate or credential. Check the keystore or truststore configuration:

# Check certificate expiry
keytool -list -v -keystore <path> -storepass <password> | grep -A2 'Valid from'

For credential-based authentication, verify the credential is valid at the source and that the Logstash keystore still holds the correct value. See Logstash certificate expiry for a deeper treatment of this failure mode.

Source-side failure

If the input plugin is healthy but no data is arriving, the problem is upstream. Logstash cannot fix this. Work with the source system owners to restore the data feed. This produces per-input symptoms identical to a Logstash-side failure: a flat events.out counter with no plugin errors.

Prevention

  • Monitor per-input stats, not just pipeline aggregates. The Node Stats API exposes per-input events.out counters at plugins.inputs[].events.out. On Logstash 8.6+, flow.throughput provides per-input event rates. Alert when any individual input’s throughput drops to zero or deviates significantly from its rolling baseline.

  • Use baseline-relative alerting, not absolute thresholds. An alert like “events.in below 5000/sec” fires during low-traffic periods and stays silent when one input out of five fails during peak. Instead, alert when an individual input’s rate deviates more than 50% from its rolling average for that time window.

  • Enable pipeline.separate_logs: true for multi-pipeline deployments. This isolates log output per pipeline, making it easier to correlate log errors with the affected pipeline and its inputs.

  • Assign explicit id values to every input plugin in your configuration. Without explicit IDs, Logstash auto-generates opaque identifiers that make it difficult to map stats API output back to configuration blocks.

  • Monitor source-side signals alongside Logstash metrics. Kafka consumer group lag, Beats agent queue depth, and JDBC query timestamps provide the upstream view that Logstash’s internal metrics cannot. Correlating Logstash per-input stats with source-side metrics confirms whether a stopped input is a Logstash problem or a source problem.

  • Track config reload state. A failed reload can change which inputs are active without your knowledge. Monitor reloads.failures and reloads.last_error to catch configuration changes that silently drop or misconfigure an input.

How Netdata helps

  • Per-input throughput visibility. Netdata collects per-input plugin stats from the Logstash Node Stats API. A stopped input shows as a flat line on one series while others continue trending.

  • Correlation with source-side metrics. When a Kafka input stops, Netdata can display the Logstash input throughput and the Kafka consumer group lag side by side. Rising lag with flat input throughput confirms the input failure and quantifies the data accumulation.

  • Anomaly detection on per-input rates. Netdata’s ML-based anomaly detection flags unusual deviations in individual input throughput, catching partial drops that absolute thresholds miss. This is particularly useful for inputs with variable traffic patterns where static thresholds are noisy.

  • Log correlation. Netdata surfaces plugin errors from the Logstash log alongside metric anomalies, so you can see the input thread death error in context with the throughput drop on the same timeline.

  • Config reload monitoring. Reload failures that silently change input configuration are caught by tracking the reloads.failures counter over time, surfacing configuration drift that could cause an input to stop.