The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / nats / nats-maximum-payload-violation ▌

Operations Guides

NATS Maximum Payload Violation: messages rejected for exceeding max_payload

A publisher calls publish, the call fails, and the NATS server log shows a Maximum Payload Violation. Seconds later the same client reconnects, publishes again, and gets disconnected again. The server is not broken: it is enforcing the configured max_payload limit, which defaults to 1 MB. The application, meanwhile, is in a publish-disconnect-reconnect loop and its messages are not flowing.

The protocol behavior is strict. When a client sends a message whose payload exceeds max_payload, the server responds with -ERR 'Maximum Payload Violation' and closes the connection. Client libraries that auto-reconnect come straight back and repeat the offense, which is why a single oversized publish looks like connection churn rather than a clean, one-time error.

This guide covers how to confirm the violation, identify the offending client and subject, decide whether the payload growth is legitimate, and raise the limit without trading this problem for a memory or slow-consumer problem.

What this means

Every NATS server enforces a maximum payload size per published message. The default is 1 MB. The limit exists because core NATS routes messages through memory in real time: each in-flight message must be read fully from the publisher’s socket into a buffer and fanned out to subscriber write buffers. Unbounded payloads would make per-connection memory unpredictable.

The limit is not advisory. The server tells each client the current value in the max_payload field of the INFO protocol message sent at connect time, and clients are expected to check it before publishing. Clients that skip that check learn about the limit the hard way: one -ERR, one closed connection.

Two consequences matter operationally:

  1. The rejection looks like churn, not like a clean error. The publish fails and the connection drops. Auto-reconnect logic brings the client back. If the application retries the same oversized message, the loop repeats. In /varz this shows up as total_connections climbing while connections stays roughly flat.
  2. The message is never delivered. This is not a queue-and-retry situation in core NATS. The rejected publish is gone. If the publisher does not handle the error, that data is lost.
flowchart LR
  P[Publisher] -->|publish N bytes| S{NATS server}
  S -->|N <= max_payload| R[Route to subscribers]
  S -->|N > max_payload| E[-ERR Maximum Payload Violation]
  E --> D[Connection closed]
  D --> RC[Client auto-reconnects]
  RC -->|retry same message| S

Common causes

CauseWhat it looks likeFirst thing to check
Payloads legitimately outgrew the 1 MB defaultViolations start after a data model change, new field, or feature rollout; byte rate climbs while message rate stays flatAverage message size: in_bytes / in_msgs trend from /varz
A new client publishes a type of message the system never had (reports, exports, file chunks, images)Violations correlate with one client or one subject; other traffic is fineServer logs for the violating connection, then that client’s subjects
Client never checks max_payload from INFO and blasts large messages on connectReconnect loop immediately after each connect; violations in burstsClient library behavior and publish error handling
Serialized format change (e.g., switching to a verbose encoding, embedding blobs in JSON)Gradual average-size creep, then a hard wall once messages cross 1 MBByte rate vs message rate divergence over weeks
Misconfiguration: limit lowered or left at default intentionally, client team unawareViolations start right after a config change or reloadCurrent max_payload in server config vs recent config changes
MQTT clients sending large messagesOversized MQTT publishes; note that some server versions did not enforce max_payload on the MQTT path at allServer version if you run the MQTT endpoint (see Fixes)

Quick checks

All of these are read-only and safe to run on a production server.

# Find payload violations in the server log
grep "Maximum Payload" /var/log/nats/nats-server.log | tail -20

The log line ties the violation to a specific connection, which is how you find the guilty client. Adjust the log path to your deployment.

# Check current throughput: message rate vs byte rate
curl -s http://localhost:8222/varz | jq '{in_msgs, out_msgs, in_bytes, out_bytes}'

Take two snapshots 10 to 60 seconds apart and compute rates. Then compute average message size as in_bytes delta / in_msgs delta. If that average is climbing toward your max_payload, you have found the trajectory before you hit the wall.

# Check connection churn: is total_connections climbing while connections is flat?
curl -s http://localhost:8222/varz | jq '{active: .connections, total: .total_connections}'

A publisher stuck in the publish-violate-disconnect-reconnect loop shows up here as churn.

# See what is currently connected and what it looks like
curl -s "http://localhost:8222/connz?sort=last&limit=10" | jq '.connections[] | {cid, name, ip, subscriptions, last_activity}'

Newly reconnected clients near the top, correlated with log timestamps, usually identify the offender. If your clients set a connection name, this is fast; if not, match by source IP.

# Confirm the configured limit the server is actually running with
grep -i max_payload /etc/nats/nats-server.conf

Also check for account-level overrides. Per-account max_payload limits can be set under account limits in the server config, and an account-scoped limit lower than the server-wide value produces exactly this symptom for only some clients.

How to diagnose it

  1. Confirm the error. Grep the server log for “Maximum Payload”. If it is not there, the publish failures have a different cause (permissions, JetStream limits, slow consumer disconnects) and this guide does not apply.

  2. Identify the connection. The log entry references the offending connection. Cross-reference the timestamp with /connz output or the client IP to find which application it is.

  3. Identify the subject and message type. Once you know the client, determine what it was publishing. A single subject (an export job, a report generator) points to a payload design problem. Every subject from that client points to a serialization or client bug.

  4. Check the trajectory. Compute average message size from /varz (in_bytes / in_msgs over an interval) and compare it to historical values. A byte-rate spike without a message-rate rise means payloads are bloating. This distinguishes “messages grew gradually and crossed the line” from “one new message type was always too big.”

  5. Check for account-scoped limits. If only one team’s clients are affected while others publish similar sizes fine, look for a per-account max_payload that is lower than the server-wide value; account limits have been available since v2.0.0.

  6. Rule out a JetStream limit instead. JetStream streams have their own per-stream MaxMsgSize limit that can be set lower than the server max_payload. A publish rejected by a stream’s MaxMsgSize is a different error path than the core protocol violation. If the publisher is writing to JetStream and the server log does not show the protocol -ERR, check the stream configuration; the JetStream publish acknowledgment carries error 10054, “message size exceeds maximum allowed.”

  7. Decide: legitimate growth or abuse/bug. Legitimate growth (the data model genuinely needs 2 MB messages) is a capacity decision. A bug (a client accidentally embedding a file in a field, or a pathological retry building ever-larger batches) is a code fix. Do not raise the limit to paper over a bug.

Metrics and signals to monitor

SignalWhy it mattersWarning sign
Average message size (in_bytes rate / in_msgs rate)The leading indicator. Payloads bloat long before they hit the limitSteady climb toward max_payload over days or weeks
Byte rate vs message rate divergenceSeparates “more messages” from “bigger messages”. Only byte rate catches payload bloatByte rate spikes while message rate is flat
total_connections delta vs connectionsViolating clients disconnect and reconnect, producing churn with a stable active countChurn correlated with violation log lines
Server log: Maximum Payload eventsThe authoritative record of which connection violated and whenAny occurrence in production; repeats from one client
slow_consumers and per-connection pending_bytesLarge payloads amplify slow-consumer risk: fewer messages fill a subscriber’s write bufferSlow consumer events appearing after a payload size increase
Server memory (/varz mem)Larger payloads mean larger per-message buffers in flightRSS growth after raising max_payload or after average size climbs

Fixes

Fix the client (correct in most cases)

If one client is publishing oversized messages by accident or by a design that violates the system’s contract, fix the producer: chunk large payloads, move bulky data to object storage and send a reference, or compress before publishing. This keeps NATS doing what it is good at: fast routing of small messages. The server-side limit is cheap to raise, but every megabyte you add increases memory-per-in-flight-message and the slow-consumer blast radius for all clients, not just the offender.

Raise max_payload deliberately (when payloads legitimately grew)

If the data model genuinely outgrew 1 MB, raising the limit is supported. Do it with eyes open:

  • Check the bounds. The configuration parser accepts values up to the signed 32-bit byte limit, but the server warns above 8 MB and the NATS maintainers recommend staying at or under 8 MB. max_payload must also be smaller than or equal to max_pending (default 64 MB); a config that violates this is rejected.
  • Set it explicitly in the server config, e.g. max_payload: 8MB at the top level, or per-account under that account’s limits if only one tenant needs it.
  • Reload instead of restarting. max_payload is reloadable: nats-server --signal reload updates server INFO and already-connected clients, and it enforces the new value without dropping connections.
  • Budget the memory. A larger max_payload increases the buffer the server needs to read each full message from the socket and enqueue it to outbound connections. On a server with many concurrent large publishers this shows up in RSS. Watch /varz mem after the change.
  • Tell client teams. Clients that read max_payload from the INFO message will pick up the new value on their next connect. Clients that hardcoded assumptions need to reconnect or be updated.

If you use the MQTT endpoint

A server-side bug in v2.12.x (reported on v2.12.1) meant max_payload was not enforced for messages arriving over the MQTT endpoint; oversized messages were accepted and processed. The fix shipped in v2.14.0. If you run MQTT, upgrade to v2.14.0 or later rather than relying on the limit for protection on affected releases.

If it is actually a JetStream MaxMsgSize rejection

If diagnosis showed the limit is the stream’s MaxMsgSize rather than the server max_payload, adjust the stream configuration instead (or fix the publisher). Server-wide max_payload changes will not help a stream-scoped rejection.

Prevention

  • Watch average message size as a first-class metric. The ratio of byte rate to message rate is the earliest warning that payloads are drifting toward the limit. Alert on the trend, not on violations.
  • Publish a payload contract. Give client teams a documented maximum message size (typically well under max_payload) and a pattern for bulk data: store the blob elsewhere, send the pointer.
  • Handle publish errors in clients. The -ERR plus disconnect must not become an invisible retry loop. Clients should check max_payload from INFO at connect time and fail loudly on oversized messages instead of reconnect-and-repeat.
  • Size changes deliberately. If you raise max_payload, do it per-account where possible, stay within the recommended range, and re-check memory and slow-consumer signals afterward. Large payloads mean a slow consumer’s pending buffer fills with fewer messages, so existing slow-consumer thresholds get more sensitive.

How Netdata helps

Netdata’s NATS collector polls the server’s HTTP monitoring endpoints and surfaces the signals that matter for this failure:

  • Byte rate and message rate side by side, so a payload-bloat divergence (bytes climbing, messages flat) is visible on one chart before it reaches the limit.
  • Connection churn: connections against the total_connections delta, which exposes the publish-violate-disconnect-reconnect loop even when the active connection count looks healthy.
  • Slow consumer counters, which often tick upward after payloads grow, since oversized messages fill subscriber write buffers faster.
  • Server memory (RSS) trend, to validate that a max_payload increase did not quietly raise per-connection buffer cost.
  • Long retention, so you can correlate the first violation in the logs with the week-over-week climb in average message size that preceded it.