The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / nvidia-gpu / nvidia-gpu-xid-errors ▌

Operations Guides

NVIDIA Xid errors: reading NVRM Xid messages in the kernel log

You found a line like this in the kernel log, or a user reported a dead training job and you went looking:

NVRM: Xid (PCI:0000:41:00): 79, pid=1432, name=python, GPU has fallen off the bus.

Xid messages are the NVIDIA driver’s primary error-reporting channel. Every significant GPU fault, from a correctable memory event to a catastrophic PCIe link failure, is printed by the NVRM kernel module as an Xid code in the kernel log. Not in nvidia-smi output. Not in a sysfs file. In the log stream, alongside everything else the kernel has to say.

This is the biggest GPU monitoring gap in most fleets. Teams watch utilization, temperature, and memory, but never parse the kernel log. The result: GPUs degrade for weeks through ECC events and page retirements, and the first anyone hears about it is a fallen-off-the-bus event that takes a node down mid-job.

This guide covers how to read Xid messages, which codes matter, and how to alert on them without paging on noise.

What an Xid message is

When the NVIDIA driver detects a GPU fault, the NVRM kernel module prints a structured message to the kernel ring buffer. The anatomy:

NVRM: Xid (PCI:0000:41:00): 79, pid=1432, name=python, GPU has fallen off the bus.
       |        |             |    |          |
       |        |             |    |          +- Process name (when applicable)
       |        |             |    +- Process ID
       |        |             +- Xid code
       |        +- PCI bus/device/function of the affected GPU
       +- Kernel module reporting (NVRM = NVIDIA Resource Manager)

Three things to extract every time:

  • PCI address (here 0000:41:00). This is how you map the event to a physical GPU. nvidia-smi -L and nvidia-smi --query-gpu=pci.bus_id --format=csv give you the same identifier per GPU index.
  • The code (here 79). The code determines severity and response. Same message text, different code, completely different incident.
  • The process (pid/name), when present. This distinguishes “your workload did something illegal” from “the hardware failed under your workload.”

Not all Xids include a pid. Hardware-level events (fallen off bus, uncontained ECC) often stand alone.

Where Xid messages live

Xids go to the kernel log, which means:

# Kernel ring buffer, human-readable timestamps
dmesg -T | grep -i "NVRM: Xid"

# Same data via journald
journalctl -k | grep -i "NVRM: Xid"

# Persistent text logs on systems running rsyslog/syslog-ng
grep -i "NVRM: Xid" /var/log/kern.log /var/log/messages /var/log/syslog 2>/dev/null

Two operational facts that bite people:

The kernel ring buffer is circular. dmesg shows a fixed-size buffer. On a busy host, old Xids scroll away. If your only record of a page-retirement event was in the ring buffer, it is gone. Ship kernel logs to a persistent store: enable persistent journald, run a syslog daemon, or forward kern.* to your log aggregation stack.

Containers do not see host kernel logs. GPU workloads in containers lose Xid visibility entirely unless you forward host kernel logs. If your GPUs are only consumed by containers, host-level log collection is the only place Xids exist.

One more trap: DCGM exposes a “last Xid” field (DCGM_FI_DEV_XID_ERRORS), and dcgm-exporter surfaces it as a metric. It reports only the most recent Xid per GPU: a second event overwrites the first, and operators have reported the exporter metric can keep showing a stale code after the GPU recovers until the exporter restarts. Treat it as a tripwire, never as history. The kernel log is the source of truth.

Severity map

Xid codes are not a uniform severity ladder. The same log line format covers “your application has a pointer bug” and “this GPU needs an RMA.”

Hardware faults: page or urgent ticket

XidMeaningRouteFirst response
48Double-bit ECC error (uncorrectable)PAGE on new event with active production workReset GPU, validate recent outputs, check ECC counters
64ECC page retirement / row remapping failurePAGE on first transition during active work, else TICKETReset GPU; if remapped_rows.failure recurs, RMA
79GPU has fallen off the busPAGENode reboot; hardware inspection; expect recurrence
95Uncontained ECC error (A100/H100)PAGE on new eventStop workloads, reset GPU
74NVLink errorPAGE on multi-GPU systems with active jobs, else TICKETCheck nvidia-smi nvlink -s; reset GPU
119Driver-internal error (often GSP firmware RPC timeout on current drivers)TICKET, escalate if recurringCapture logs, check driver/firmware versions
61, 62Internal microcontroller events (PMU breakpoint/halt)TICKETCapture logs, check driver/firmware versions. Xid 61 is listed as unused in the current NVIDIA Xid catalog; Xid 62 (PMU_HALT_ERROR) is an internal micro-controller halt on newer drivers.

Application bugs: the GPU is fine

XidMeaningRouteFirst response
13Graphics engine exceptionINFO, TICKET if recurringFix the application (illegal memory access)
31GPU memory page faultINFO, TICKET if recurringFix the application (bad pointer)
32Invalid or corrupted push bufferTICKET if recurringApplication bug or PCIe signal quality
43GPU stopped processingINFOApplication-induced; the GPU itself is unaffected
69Graphics engine class errorINFOApplication API misuse

Informational: never page on these

XidMeaningRoute
45Preemptive cleanup from a prior errorINFO: consequence of another Xid, not an independent fault
63GPU memory remapping / page retirement eventINFO: ECC self-healing working as designed
65ECC mode change notificationINFO
92High single-bit ECC error rateINFO, but trend it: accelerating SBE rate precedes DBE

Xid 109 (context switch timeout) deserves special mention: it is not fatal by itself, but it frequently precedes more severe errors by minutes to hours. Treat it as a leading indicator and correlate forward.

flowchart TD
  A[Xid found in kernel log] --> B{Which code?}
  B -->|48, 64, 79, 95| C[Hardware fault: page]
  B -->|74, 119, 61, 62| D[Hardware suspect: ticket or page by context]
  B -->|13, 31, 32, 43, 69| E[Application bug: route to job owner]
  B -->|45, 63, 65, 92| F[Informational: log and trend]
  C --> G[Correlate ECC, retired pages, remapping]
  D --> G
  E --> H[Match pid/name to scheduler records]
  F --> I[Watch rate of change over weeks]
  G --> J{New event or historical?}
  J -->|New| K[Act now]
  J -->|Old, already handled| L[No re-alert]

Quick checks

All read-only.

# All Xid events with timestamps, this boot
dmesg -T | grep -i "NVRM: Xid"

# Xid events in the last 24h via journald (works across ring-buffer rollover if journald is persistent)
journalctl -k --since "24 hours ago" | grep -i "NVRM: Xid"

# Context around an event: the lines before often name the GPU GUID or a precursor Xid
dmesg -T | grep -i -B3 -A3 "NVRM: Xid"

# Map the PCI address from the message to a GPU index
nvidia-smi --query-gpu=index,pci.bus_id,name --format=csv

# Reachability of the affected GPU (use per-GPU query; one hung GPU can stall a full query)
timeout 5 nvidia-smi -i 0 --query-gpu=gpu_name --format=csv,noheader

# ECC state on the affected GPU
nvidia-smi -i 0 -q -d ECC

# Retired pages (delta matters, not the raw count)
nvidia-smi -i 0 -q -d PAGE_RETIREMENT

# Row remapping, Ampere and later only
nvidia-smi -i 0 -q -d ROW_REMAPPER

How to diagnose an Xid event

  1. Capture the full message and its neighborhood. Grep with context (-B3 -A3). The lines immediately before an Xid often carry a GPU GUID line or a precursor event (109, 45) that explains the sequence.
  2. Map PCI address to GPU. Use pci.bus_id from nvidia-smi. On multi-GPU nodes never assume the event hit GPU 0.
  3. Classify the code against the severity map above. This decides whether you are doing hardware triage or walking over to the ML team.
  4. Decide: new event or history. Xids are events. If your log pipeline re-surfaces an old, already-handled Xid, do not re-act on it. Track what you have seen per GPU.
  5. Correlate with hardware state. For 48/63/64/95: pull ECC counters, retired pages, row remapping. For 61/62/79: check PCIe link status (pcie.link.gen.gpucurrent, pcie.link.width.current under load) and PCIe AER errors in dmesg. For 74: nvidia-smi nvlink -s and nvidia-smi nvlink -e.
  6. Correlate with the application. For 13/31/43/69, match the pid and name in the message against scheduler records and look for CUDA error: an illegal memory access was encountered or similar in job logs. That is a code bug, not an RMA.
  7. Look for recurrence. One Xid 119 in six months is a data point. Three in a week on the same GPU is a failing component or a driver/firmware bug. Keep a per-GPU event history.
  8. Escalate with evidence. Run nvidia-bug-report.sh as root before any reboot if you intend to open a vendor ticket. It collects kernel logs and driver state that a reboot destroys.

Codes everyone gets wrong

  • Xid 43 is not page retirement. It means “GPU stopped processing,” an application-induced event. Page retirement is Xid 63.
  • Xid 63 is not a thermal event. It is the page retirement / remapping notification: ECC self-healing working correctly. Informational.
  • Xid 68 is not NVLink. It is an NVDEC0 (video decoder) exception. NVLink errors are Xid 74.
  • Xid 49 is unused in current NVIDIA documentation. High single-bit ECC rate is Xid 92.
  • Xid 45 is a consequence, not a cause. It reports cleanup after a prior error. Look backwards in the log for the real event.

Routing a page to the hardware team for Xid 13, or ignoring Xid 92 because “single-bit errors are corrected,” are the two failure modes these misreadings produce.

Signals to correlate

An Xid alone tells you what happened. Correlation tells you whether it will happen again.

SignalWhy it mattersWarning sign
ECC corrected error rate (volatile)Leading indicator for 48/95Rate accelerating week over week
Retired pages countPermanent degradation from past eventsIncreasing deltas; approaching 64-page limit (pre-Ampere hardware; Ampere and later use row remapping instead)
Row remapping status (Ampere+)Self-heal capacity remainingremapped_rows.failure = true, pending remaps
PCIe link gen/width under loadContext for 61/62/79Current below max during active workloads
PCIe replay errorsLink instability before a bus dropSustained increase in replay counter rate
NVLink status and error countersContext for 74Any CRC/replay errors; link down
GPU reachability / nvidia-smi latencyAftermath of 79; prelude to wedgesSustained >2s response, or hang
Application CUDA errorsDistinguishes app bug from hardwareIllegal memory access matching Xid 13/31 pid

Prevention

  • Ship kernel logs off the host. Persistent journald at minimum; central aggregation for fleets. The ring buffer will erase your evidence.
  • Alert per code, not per pattern match. A single “NVRM: Xid found” alert either pages on Xid 45 noise or snoozes on Xid 79. Route by the severity map.
  • Alert on new events, not state. Track which Xids have been seen per GPU. Fire on the delta. A GPU with a handled Xid 64 from last month should not re-page every check cycle.
  • Mind aggregation latency. Xids hit dmesg instantly but may take minutes to reach central logging. Do not let delayed delivery cause delayed or duplicate paging.
  • Trend the informational codes. Xid 92 and Xid 63 are the early chapters of the memory-degradation story that ends in Xid 48. Plot their rate per GPU.
  • Sample fast. Xid-adjacent signals (throttle events, PCIe errors, temperature spikes) develop in seconds. Minute-resolution polling misses them; use 10-second or faster sampling for GPU metrics.
  • Forward host kernel logs into container platforms. If GPUs are consumed via Kubernetes or other container runtimes, node-level log forwarding is the only way Xids reach your alerting at all.

How Netdata helps

  • Per-second GPU metrics (utilization, temperature, power, memory, clocks) give you the before-and-after picture around an Xid timestamp: thermal runaway before a 79, or clean operating conditions pointing at hardware.
  • ECC error charts let you trend corrected error rate per GPU, so Xid 92 and Xid 63 events correlate with a visible acceleration curve instead of arriving as surprises.
  • Systemd journal centralization means kernel logs, including NVRM Xid lines, survive ring-buffer rollover and host reboots and are searchable across the fleet.
  • Throttle-reason and clock metrics provide the corroboration that separates a real hardware event from a transient: an Xid plus hw_thermal_slowdown is a different incident than an Xid alone.
  • Anomaly detection on temperature, power, and ECC series flags the slow drift (rising baseline temps, growing SBE rate) that precedes the codes you actually page on.