The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / memcached / memcached-memory-utilization ▌

Operations Guides

Memcached memory utilization: bytes vs limit_maxbytes and why the global number lies

The bytes and limit_maxbytes fields from stats look like a clean fill gauge. Divide one by the other and you know how full the cache is. Many dashboards and alerts are built on exactly that ratio.

This article covers why the global ratio lies, what it actually measures, and which per-slab signals confirm real pressure. bytes includes per-item overhead and never quite reaches the ceiling, allocation happens in 1MB page jumps rather than smoothly, and the pool is partitioned into fixed-size slab classes that saturate independently. A cache at 50% global utilization can be evicting live, actively-requested data.

Treat bytes / limit_maxbytes as a coarse leading indicator, then confirm with stats slabs and stats items before acting.

What it is and why it matters

bytes reports memory used for item storage. limit_maxbytes is the configured ceiling, set by the -m flag in megabytes and reflected verbatim in stats.

Conventional thresholds:

RatioInterpretation
below 0.85Normal range
above 0.85Approaching saturation
above 0.95Heavily saturated, eviction churn expected

These are reasonable as a coarse indicator. The problem is that the ratio has three structural properties that make it unreliable as a saturation signal alone, and the most important one, slab partitioning, can hide an eviction storm behind a healthy-looking 50%.

How it works

Three mechanisms make the global ratio behave differently from a naive “tank filling up” model.

Per-item overhead inflates bytes. bytes is not the sum of value payloads. It includes the key, flags, exptime, internal pointers, and slab chunk padding. The per-item overhead is the item header struct, plus the key, flags, CAS value, protocol suffix, and padding to the next chunk boundary. On a default 64-bit build, sizeof(item) is 48 bytes; verify your build with stats slabs when the exact boundary matters. A 100-byte value in a 152-byte chunk contributes 152 bytes to bytes, not 100. The effective payload capacity is lower than limit_maxbytes suggests, and bytes plateaus below the ceiling even under heavy pressure.

Allocation is page-wise, not smooth. Memory is handed out in 1MB pages. When a slab class needs more storage, memcached assigns it a full page. The counter moves in steps, not continuously. Small caches show visible stair-stepping; on large caches the granularity is invisible but the mechanism is the same. The moment-to-moment bytes value is a snapshot of a step function, not a smooth fill level.

The pool is partitioned by item size. This is the big one. At startup memcached divides the -m pool into slab classes, each handling a range of item sizes. With defaults, class 1 handles items up to 96 bytes, class 2 up to 120, and class 3 up to 152; chunk sizes are rounded to 8-byte alignment and grow by the -f factor (default 1.25). Confirm the active boundaries with stats slabs. Pages are assigned to slab classes, and each class fills independently. The global bytes is the sum across all classes. If your workload concentrates in one size class, that class fills and evicts while the others sit idle, and the global ratio reports a number that has nothing to do with the pressure the hot class is under.

This is the slab imbalance trap, and it is the single most underdiagnosed memcached problem. You can be evicting actively-used items at 50% global utilization.

flowchart TD
    L["limit_maxbytes
set via -m"] --> P["divided into 1MB pages"] P --> S1["slab class A
small chunks"] P --> S2["slab class B
medium chunks"] P --> S3["slab class C
large chunks"] S1 --> U1["100% used
evicting live items"] S2 --> U2["100% used
evicting live items"] S3 --> U3["25% used
idle pages"] U1 --> B["bytes = sum of all classes"] U2 --> B U3 --> B B --> R["global ratio ~55%
reads as healthy"] R --> X["reality: A and B are saturated"]

The diagram shows the lie in one frame: three slab classes, two saturated and evicting, one idle. The global ratio sums them into a number that looks comfortable, and the operator never opens stats slabs to see the per-class breakdown.

What limit_maxbytes actually is

limit_maxbytes is the -m value converted to bytes. It is a ceiling on item storage memory, not on total process memory. Memcached uses additional memory for the hash table, connection buffers, thread stacks, and internal structures. Process RSS will exceed limit_maxbytes in steady state. The -m flag documentation is explicit that it is not a hard global limit on the process.

limit_maxbytes can be changed at runtime with the cache_memlimit command. It takes megabytes, not bytes. Passing a byte value corrupts the limit_maxbytes figure. If limit_maxbytes moves unexpectedly between samples, someone issued cache_memlimit, or the process restarted with a different -m. Lowering limit_maxbytes below current bytes is disruptive: it does not guarantee memory is returned to the OS, the allocator and kernel decide that, and active eviction may spike in the slab classes that hold the freed pages. Do not run it against a production cache without a drain plan.

Where it shows up in production

Three recurring scenarios.

Slab calcification after a deploy. An application changes its serialization format or adds fields, shifting the item size distribution. Items that used to be 180 bytes are now 280 bytes, landing in a different slab class. The old class still holds its pages, assigned at warmup, serving a workload that no longer exists. The new class is undersized and evicting. Global memory reads 60%. Operators add memory and watch it flow to the wrong classes. The fix is per-slab inspection and slab_automove, not more RAM.

Warmup slab allocation mismatch. If warmup traffic has a different item-size distribution than steady-state, pages get assigned to the wrong classes during the initial fill. The cache enters steady-state already calcified. This is why a freshly restarted cache can show evictions at 40% global utilization within minutes of coming up.

The “we have plenty of memory” false comfort. A team sizes their cache to 70% global utilization and sets an alert at 90%. They never get paged. Meanwhile one slab class has been evicting active items for weeks, hit ratio for that size range is degraded, and nobody looks because the global gauge never crossed the line.

The common thread: the global ratio answers “how full is the pool?” when the question you actually need is “is any slab class under pressure?”

Tradeoffs and common misuses

Alerting on global ratio alone. A threshold on bytes / limit_maxbytes at 0.9 will catch genuine global undersizing, where the whole pool is full. It will not catch slab imbalance, which is the more common and more damaging failure mode at moderate utilization. Pair the global alert with per-slab eviction monitoring or you will miss the case that matters.

Assuming bytes can reach limit_maxbytes. It cannot, because of per-item overhead and chunk padding. An alert that fires only when bytes gets within a hair of limit_maxbytes will never fire. The practical ceiling is meaningfully below the configured one.

Reading a sudden bytes drop as memory pressure. A sudden drop means items disappeared: a flush_all, a mass TTL expiration, or a restart. It is not pressure, it is evacuation. Check cmd_flush, uptime, and curr_items to classify the event. After a flush, bytes can lag because flushed item memory is reclaimed gradually, mainly as it is reused or reclaimed by the crawler.

Treating cache_memlimit as a pressure-relief knob. Raising limit_maxbytes at runtime adds headroom globally, but the new memory still has to be claimed by slab classes as pages. If the pressure is in one saturated class and slab_automove is off, raising the limit may not help that class at all. Confirm where the pressure is before adjusting the ceiling.

Trusting stats sizes blindly. stats sizes gives an item-size histogram that is exactly what you need for slab analysis, but on versions before 1.4.27 it locks the entire cache while scanning. From 1.4.27 onward it is disabled by default and requires -o track_sizes at startup, returning sizes_status disabled otherwise. Know your version before running it in production.

Signals to watch in production

SignalWhy it mattersWarning sign
bytes / limit_maxbytesCoarse global fill gaugeAbove 0.85 and trending up, or any sustained value with active evictions
Per-slab used_chunks / total_chunksReal per-class saturationAny class at 100% used with free_chunks == 0
Per-slab evicted and evicted_timeWhich class is under pressure and how recently active the evicted data wasEvictions in one class while others have free chunks; low evicted_time means recently active items are being evicted, while a rising evicted rate confirms current pressure
evictions (global)Pressure exists somewhereNon-zero rate, but only actionable when broken down per slab
mem_requested per slabInternal fragmentationmem_requested well below used_chunks * chunk_size means items are wasting slab space
cmd_flush and uptimeClassify sudden bytes dropscmd_flush incrementing or uptime resetting explains a drop; otherwise suspect mass expiry
slab_automove settingWhether the server self-heals imbalanceOff (mode 0) means calcification is permanent until restart or manual reassign
Process RSS vs limit_maxbytesTotal memory footprintRSS materially above limit_maxbytes suggests connection or hash-table overhead is growing

The global ratio is the first row. Every other row is what you need to confirm or refute what the global ratio is telling you.

How Netdata helps

Netdata surfaces the global ratio and the per-slab breakdown in the same view, which is the correlation that matters for this problem.

  • The memcached collector pulls bytes and limit_maxbytes into a per-second utilization chart, so the coarse fill gauge updates frequently enough to catch step-changes from page allocation and sudden drops from flushes.
  • Per-slab charts for used_chunks, free_chunks, and eviction counts let you see which class is saturated without dropping to a shell and running stats slabs manually.
  • Eviction rate and evicted_time are tracked alongside utilization, so you can distinguish “full and evicting cold items” from “full and evicting live data” without correlating across tools.
  • ML anomaly detection flags sudden drops in bytes from flushes, restarts, or mass expiry, and unexpected shifts in the bytes / limit_maxbytes ratio including changes introduced by cache_memlimit.
  • The cmd_flush counter is tracked as a discrete event, so a sudden bytes drop is immediately attributable to a flush rather than guessed at.
  • Alerting can be layered: a global ratio alert catches whole-pool saturation, while per-slab eviction alerts catch the imbalance case the global ratio hides.