The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / memcached / memcached-network-exposure ▌

Operations Guides

Memcached bound to 0.0.0.0: unauthenticated access on an open port

Memcached was designed for trusted internal networks. It has no authentication by default, no per-key access control, and no per-connection logging. Anyone who can open a TCP connection to the daemon can read every cached value, overwrite any key, enumerate key names and sizes, and issue flush_all to wipe the entire cache in one command. Session tokens, PII, and application secrets cached in plaintext are all readable by that caller.

The common cause of accidental exposure is the bind address. Upstream memcached defaults to INADDR_ANY (0.0.0.0) on all interfaces. Debian and Ubuntu ship package defaults that override this to -l 127.0.0.1. Source compiles, minimal container images, and some other distributions inherit the upstream 0.0.0.0 default. A single -l flag, or a Docker port publish without an IP restriction, is the difference between a loopback-only cache and a service reachable from every interface the host owns.

This guide is a detection, audit, and lockdown procedure. It assumes you have shell access to a host running memcached and can read its startup configuration. Every command in the detection section is read-only. The lockdown section is marked, and the one destructive step (a restart) is called out explicitly.

What this exposes

On an unauthenticated memcached reachable from the network, a connected client gets the full administrative surface:

CapabilityImpact
Read any key (get, stats cachedump)Bulk extraction of session tokens, PII, internal identifiers
Write any key (set)Poison application state, inject cached responses, overwrite rate-limit counters
flush_allInstant cold-cache event and backend thundering herd
stats, stats items, stats slabsReveal working set size, item counts, slab distribution, key metadata
incr / decr on countersManipulate rate limiters, distributed locks, quotas

None of these operations are logged with a source address. Memcached stats expose no client IP information. The daemon will serve a full cache dump to an attacker and leave no trace in its own counters beyond aggregate byte and command totals. Detection has to come from OS-level connection tracking, not from memcached itself.

One historical amplifier makes an open UDP port especially dangerous. Before 1.5.6, UDP was enabled by default on port 11211, and CVE-2018-1000115 turned reachable instances into DDoS reflectors with amplification factors in the tens of thousands. UDP is off by default in modern releases, but older installations and configs that explicitly set a UDP port still exist in the wild.

Prerequisites

  • Shell access to the host running memcached, or the container host.
  • Permission to read the startup configuration: the systemd unit, /etc/memcached.conf (or distro equivalent), or docker inspect for containerized deployments.
  • nc (netcat), ss, and standard coreutils.
  • Read-only intent during the audit phase.

Detecting exposure

Run these checks in order. Each one closes a gap.

1. Confirm the bind address from the running process

# Inspect the actual listening sockets owned by memcached
ss -tlnp | grep 11211

Read the Local Address:Port column. 127.0.0.1:11211 means loopback only. 0.0.0.0:11211 (or *:11211) means every interface. A specific internal IP, for example 10.0.0.5:11211, means it is bound to one interface, which is better but still needs firewalling.

ss shows the truth at runtime. The config file may say one thing while a systemd override or a docker run -p 11211:11211 says another.

2. Check the startup configuration

# Common config locations and the flags that matter here
grep -nE -- '(-l|-U|-p|-S)' /etc/memcached.conf
# Systemd unit and any drop-in overrides
systemctl cat memcached

If -l is absent, the upstream default applies: bind to all interfaces. If -U is absent and the version is older than 1.5.6, UDP may be on.

For containers, the host-side binding is what matters:

# Show published ports for a container
docker inspect <container> --format '{{json .NetworkSettings.Ports}}'

-p 11211:11211 publishes on all host interfaces. -p 127.0.0.1:11211:11211 restricts to loopback. The in-container bind is almost always 0.0.0.0; the host-side publish rule is the real boundary.

3. Verify UDP is disabled

# Query the running daemon's effective settings
echo "stats settings" | nc -w 2 127.0.0.1 11211 | grep udpport

udpport 0 means UDP is off. Any non-zero value means UDP is listening, and on a routable host that is an immediate incident. Cross-check with the kernel:

ss -ulnp | grep 11211

4. Check whether authentication is enforced

echo "stats" | nc -w 2 127.0.0.1 11211 | grep -E 'auth_(cmds|errors)'

If both counters are zero, authentication is either unused or not compiled in. Absence of auth errors does not mean access is controlled; it means the daemon never asked for credentials. Confirm SASL support exists in the binary at all:

memcached -h 2>&1 | grep -E -- '-S'

If -S is not listed, the binary was built without SASL; check separately for -Y, because ASCII authentication may still be available.

5. Enumerate current connections and build an allowlist

Memcached will not tell you who is connected. Use OS tooling.

# All established TCP connections to the memcached port, with peer addresses
ss -tnp | grep ':11211'
# Count connections by source IP
ss -tn | grep ':11211' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn

Compare the source IPs against your expected application server ranges. Anything unexpected is a misconfigured client, a scanner, or lateral movement. Maintain this list as an explicit allowlist and feed it into your firewall and your monitoring.

6. Look for exfiltration patterns

# Compare outbound bytes to read volume
echo "stats" | nc -w 2 127.0.0.1 11211 | grep -E 'bytes_written|cmd_get'

A spike in bytes_written without a proportional rise in cmd_get means either values got larger or someone is pulling bulk data. stats cachedump lets an attacker enumerate key names and sizes systematically, slab class by slab class. Upstream builds can disable flush_all in-process with -F / --disable-flush-all, but that requires a restart and is not commonly enabled.

The decision flow for the audit:

flowchart TD
    A["ss: bound to 0.0.0.0?"] -->|Yes| B["On a routable interface?"]
    A -->|No, loopback or internal IP| F["Firewalled anyway?"]
    B -->|Yes| C["Exposed: treat as incident"]
    B -->|No| F
    C --> D["UDP on? stats settings udpport"]
    D -->|udpport non-zero| E["Amplification risk"]
    D -->|udpport 0| G["Auth enforced? auth_cmds / auth_errors"]
    E --> G
    G -->|No auth| H["Full read, write, flush to anyone"]
    G -->|SASL on| I["Verify binary protocol clients"]
    H --> J["Enumerate conns: ss -tn grep 11211"]
    I --> J
    F -->|Yes| K["Monitor for drift"]
    F -->|No| C

Locking it down

The fixes below are ordered by impact. The one restart required causes complete cache loss: every cached item disappears and the full read load shifts to your backend until the cache warms. Do not restart during a peak window without a warming plan.

Restrict the bind address

Set -l to a loopback or internal interface in your config file or systemd unit:

-l 127.0.0.1

For a cache shared across hosts on a private subnet, bind to the internal interface IP only. This is the single highest-value change. It requires a restart.

Firewall the port

Even with a restricted bind, run a host firewall that denies 11211 from all sources except the application tier. The firewall is defense in depth against future configuration drift and container republishing mistakes.

Disable UDP explicitly

In modern releases UDP is off by default, but make it explicit so an upgrade or a copied config cannot silently re-enable it:

-U 0

There is no legitimate reason to run UDP memcached on a production network in 2026. If any client uses UDP on purpose, move it to TCP.

Evaluate SASL, knowing its limits

SASL authentication (-S) requires the binary protocol. Enabling SASL will break any text-protocol client. SASL must also be compiled in, requires a configured SASL password database, and 1.6.42 fixed two timing side-channel issues (CVE-2026-47783 for username data and CVE-2026-47784 for password data) in SASL password-database authentication. Treat SASL as a layered control, not a replacement for network isolation.

Upstream ASCII auth via -Y / --auth-file was introduced in 1.5.15 and remains marked experimental; it should not anchor a production security posture.

Fix container publishing

Replace -p 11211:11211 with -p 127.0.0.1:11211:11211, or do not publish the port at all and use a Docker network so only sibling containers can reach it. Re-run docker inspect to confirm.

Verifying the lockdown

Re-run the detection checks from the host, then test from an untrusted vantage point.

# From the host, after restart: confirm the new bind
ss -tlnp | grep 11211
# Confirm UDP is gone
ss -ulnp | grep 11211

From a host that should not have access, the port should refuse or time out:

nc -vz -w 2 <memcached-host-ip> 11211

From an allowed application host, a version probe should still succeed.

Common pitfalls

  • Distro defaults can mislead. Debian and Ubuntu look safe out of the box, but a source compile, a minimal container image, or a config copied from another host may inherit the upstream 0.0.0.0 default. Always verify with ss, never trust the package default.
  • Docker publish without an IP is wide open. -p 11211:11211 binds the published port on all host interfaces, including the public one if the host has one.
  • SASL breaks text clients. Forcing binary protocol is a client-side change. PHP clients, for example, must enable binary mode explicitly.
  • flush_all is usually enabled in-process. Network isolation is the primary control; only explicitly added -F disables the command.
  • No source IP logging means no forensic trail. If you discover exposure, assume it has been abused and rotate any secrets that were cached in plaintext.

Signals to monitor

SignalWhy it mattersWarning sign
curr_connections source distribution via ssDetects unexpected clients talking to the cacheIPs outside the application-tier allowlist
udpport in stats settingsBinary flag for amplification exposureAny non-zero value on a routable host
auth_cmds / auth_errorsIndicates whether auth is even activeBoth zero means no auth is enforced
bytes_written vs cmd_get ratioBulk read pattern suggests enumeration or exfiltrationbytes_written rising faster than cmd_get
cmd_flushflush_all is destructive and unauthenticatedAny increment outside planned maintenance
Host firewall drops on 11211Confirms the port is being probedSustained drop rate from external ranges

How Netdata helps

Netdata’s per-second collection turns several of these checks into continuous signals rather than ad hoc audits.

  • The memcached collector surfaces curr_connections, cmd_flush, bytes_written, and auth_errors per second, so a sudden external reader or an unexpected flush_all appears immediately instead of at the next manual audit.
  • Anomaly detection on the bytes_written to cmd_get ratio catches the signature of bulk key enumeration.
  • Correlating memcached connection counts with host-level network metrics from the same agent helps distinguish legitimate application scaling from an unfamiliar source IP range.
  • Because memcached exposes no source IPs itself, pairing the memcached collector with the host’s socket and firewall metrics is how you reconstruct who is actually talking to the cache.