The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / php-fpm / php-fpm-emergency-restart ▌

Operations Guides

PHP-FPM emergency restart: "failed processes threshold reached, initiating reload"

You see a NOTICE line in the PHP-FPM error log:

NOTICE: failed processes threshold (N in M sec) is reached, initiating reload

The master has watched enough children die from SIGSEGV or SIGBUS inside a configured interval and is giving up on soft recovery. It is about to execvp() itself: every pool is recycled, the OPcache shared memory segment is destroyed, and for a few seconds no PHP request can be served. When traffic returns, every worker pays a compilation penalty while the cache warms.

This is not “server reached pm.max_children” and it is not a graceful SIGUSR2 reload. It is the FPM circuit breaker, and by default it is disabled (emergency_restart_threshold = 0). If you are seeing the message, someone set the threshold to a non-zero value at some point. If you expected the master to self-heal and it never did: with the default of 0 the breaker never trips and a crash loop runs degraded for as long as the master keeps respawning workers.

A single event can self-heal: the restart clears whatever transient state caused the segfaults and the pool comes back. Repeated events are a different problem. There is a persistent bug, the breaker is now part of a crash loop, and every restart wipes OPcache again.

What this means

The mechanism is narrow and easy to misread:

  • The master counts only child exits from SIGSEGV (signal 11) and SIGBUS (signal 7). Those are the only signals that increment the counter.
  • Exits from SIGKILL (signal 9, the OOM killer), SIGTERM, SIGABRT (signal 6), or any non-zero exit code do not count toward the threshold. A worker storm killed by the OOM killer will not trip the breaker on its own.
  • If the running count inside emergency_restart_interval reaches emergency_restart_threshold, the master execvp()s itself, restarting every pool in the configuration, not just the affected one.
  • The interval defines the window. The official documentation does not specify exactly when the count resets if the threshold is not reached.
  • During the restart there is a brief window where the master has replaced itself and no workers are ready. New connections can land on the listen socket, but workers cannot accept them until they are forked.

Side effects that compound the original outage:

  • OPcache is wiped, because the shared memory segment owned by the old master is destroyed. Every script is recompiled on first hit. On a large codebase that is seconds to minutes of elevated CPU and latency.
  • Status page counters (accepted conn, max children reached, max active processes) reset to zero, which hides the original signal from monitoring that does not keep history.
  • If the same request pattern recurs when the new pool starts (client retry, popular endpoint), the new worker may hit the same code path immediately and segfault again, producing a tight restart loop.
flowchart TD
  A["Worker exits"] --> B{"Signal?"}
  B -->|SIGSEGV / SIGBUS| C["Increment crash counter"]
  B -->|SIGKILL / SIGTERM / SIGABRT / non-zero exit| D["Respawn only
counter unchanged"] C --> E{"Count >= threshold
within interval?"} E -->|No| D E -->|Yes| F["Master execvp()"] F --> G["All pools recycled"] G --> H["OPcache wiped"] H --> I["Cold-start penalty"]

Common causes

CauseWhat it looks likeFirst thing to check
Extension segfaultSame request URI across worker deaths; recent extension install or PHP upgradedmesg, disable the extension, core dump if rlimit_core is set
Corrupted OPcache shared memoryWorkers segfault on cache reads; restart temporarily clears itopcache_get_status() oom_restarts and wasted_memory before the restart
New deploymentFirst restart event within minutes of a deployDeploy timeline and artifact diff
Memory pressure corrupting OPcachedmesg shows OOM activity near the segfaultscgroup memory.events.oom_kill, per-worker RSS trend
Hardware memory errorsRepeatable crashes with no software changemcelog, dmesg for ECC corrections, edac-util
PHP version bugCrashes started after a minor PHP upgrade with no app changeReproduce on the previous PHP version, file upstream

OOM kills themselves do not trip the breaker because they are SIGKILL, not SIGSEGV. But the memory pressure that produced the OOM kills can also corrupt OPcache shared memory, and the genuine SIGSEGVs that follow will count.

Quick checks

Read-only. None of these change state. Kernel log commands require root.

# Confirm the emergency restart happened
grep -i "failed processes threshold\|initiating reload" /var/log/php-fpm/error.log | tail

# Count child deaths by signal in the same window
grep "exited on signal" /var/log/php-fpm/error.log | tail -50

# Confirm the directives are configured (global section, not pool)
php-fpm -tt 2>&1 | grep -E "emergency_restart_(threshold|interval)"

# Kernel view of the segfaults
journalctl -k --since "1 hour ago" | grep -i "segfault\|php"
dmesg -T | grep -i "php\|traps"

# Was there an OOM event nearby?
journalctl -k --since "1 hour ago" | grep -i "out of memory\|oom"
dmesg -T | grep -i "oom"

# Did a deploy happen around the same time? (system-dependent)
journalctl --since "2 hours ago" | grep -i "deploy\|release"

# Master process start time, to bracket the restart
ps -o pid,lstart,etime,cmd -p "$(pgrep -f 'php-fpm: master' | head -1)"

Paths vary by distribution and PHP version. Adjust /var/log/php-fpm/error.log, the PID file, and the master process string to match your system.

How to diagnose it

  1. Confirm the breaker actually fired. The threshold log line is the only authoritative evidence. A bare “ready to handle connections” line without it means something else restarted FPM: systemd, an OOM kill of the master, a manual systemctl restart, or a watchdog.
  2. Bracket the event in time. Note the timestamp of the threshold message and look back across the previous emergency_restart_interval for child deaths. Deaths outside the window did not contribute.
  3. Filter the deaths to SIGSEGV and SIGBUS. Only those count. If the log shows mostly “exited on signal 9” or “exited with code 255”, the threshold count came from a minority of deaths mixed into a larger storm. That minority is the real bug.
  4. Pull the per-worker request URI from the moments before the crash. If you have a status poller (Netdata, a custom poller, an APM), look at the last known request URIs for the workers that died. A single recurring URI points at a code path. URIs spread across the application point at shared state: OPcache, an extension global, the PHP runtime itself.
  5. Get a core dump if you can. Without rlimit_core = unlimited in the pool config there is nothing to read. With it, coredumpctl list on systemd hosts, or the configured core path otherwise, gives you a backtrace with the exact extension and function. This is the single highest-value artifact for a segfault investigation.
  6. Check the deploy timeline. Most emergency restarts in production follow a deploy: new bytecode in OPcache, a new extension version, or a new PHP runtime. If the first event is within minutes of a deploy, treat the deploy as the suspect until ruled out.
  7. Decide severity. A single isolated event is a TICKET: investigate, but the restart may have cleared the corruption. Repeated events are a PAGE: there is a persistent bug and the breaker is now part of a crash loop. Each restart costs OPcache warmth, so the loop degrades throughput even between the visible outages.

Metrics and signals to monitor

SignalWhy it mattersWarning sign
Emergency restart log lineThe breaker firingAny occurrence
Worker exit rate (SIGSEGV and SIGBUS only)Trend that precedes the breaker trippingRising rate inside the configured interval
Total process countDrops during the restart, recovers slowlyCount below the configured pm floor for more than 30 seconds
Accepted connections rateGoes to zero during restartPlateau at zero while the web server is still sending traffic
OPcache hit ratePlummets after restart, climbs during warmupHit rate under 95% sustained for more than 5 minutes after restart
OPcache oom_restarts and wasted_memoryIndicates corruption pressure that can precede segfaultsoom_restarts above zero, or climbing wasted_memory
Web server 502/504 rateUser-visible impact during the restart windowSpike coincident with the threshold log line
Master process uptimeConfirms a restart actually happenedResets to zero at the event
cgroup memory.events.oom_kill (containers)Memory pressure that can corrupt OPcacheNon-zero immediately before the event

Fixes

Single isolated event: investigate, do not panic

If the line appears once and the pool recovered, the most likely explanation is transient shared-memory corruption that the restart cleared. Capture the artifacts (log lines, core dumps, deploy timeline) and treat it as a TICKET. Do not roll back yet, and do not raise the threshold to hide the signal.

If you cannot find a core dump and the artifacts are gone, set rlimit_core = unlimited in the pool configuration and reload FPM once, deliberately, so the next crash leaves evidence. This is a one-time setup step, not a fix.

Repeated events: roll back first

When the breaker fires twice within 15 minutes with live traffic, you are in a crash loop. The right first move is rollback, not debugging:

  • Roll back the most recent deploy of application code, PHP runtime, or extensions.
  • If a specific URI is implicated, block it at the web server layer to protect the rest of the site while you investigate.
  • If a specific extension is implicated, disable it in the pool config and reload.

The threshold is not the problem here. Raising emergency_restart_threshold to make the message go away makes things worse: the crash loop continues, workers spend more time dying and respawning than serving requests, and you have removed the only signal that something is wrong.

Breaker never configured: degraded by default

If you expected automatic recovery and instead discovered workers dying in a loop with no threshold message, the directives are at their default of 0. The pool has been running degraded with no circuit breaker. Setting a threshold (typical starting values are emergency_restart_threshold = 10 and emergency_restart_interval = 60) gives you a recovery path and a clear log signal.

These are global directives: they go in the [global] section of php-fpm.conf, not in a pool .conf file. Putting them in a pool file produces an error like unknown entry 'emergency_restart_threshold' and they are ignored.

Restart itself is fragile

If the breaker fires but the master hangs during the restart (workers not draining, the new master slow to come up, the systemd watchdog tripping), the recovery path is the problem. Symptoms include accepted conn staying at zero well past the expected restart window and systemd restarting FPM from the outside. In that case, treat it as a complete service outage and fall back to systemctl restart php-fpm (service name varies by distro: php-fpm, php8.2-fpm, etc.) after confirming the master PID.

Prevention

  • Configure the breaker deliberately. The default of 0 is silent degraded operation, not safe operation. Pick a threshold that fits your traffic: low enough to trip on a real crash loop, high enough not to trip on the occasional segfault from a known-flaky extension.
  • Put the directives in the global section. Pool files do not honor them. Verify with php-fpm -tt after every config change.
  • Set rlimit_core = unlimited on production pools. Without core dumps, every segfault investigation starts from nothing.
  • Bound per-worker RSS with pm.max_requests. Unbounded RSS growth leads to OOM pressure, which can corrupt OPcache shared memory and produce the genuine SIGSEGVs that trip the breaker. The leak itself does not count, but the corruption it causes does.
  • Correlate deploys with crash events. A deploy hook that records a timestamp somewhere pollable (a log line, a file, a metric label) turns “did the deploy cause this?” from an archaeology project into a one-line query.
  • Watch OPcache memory pressure. oom_restarts > 0 from opcache_get_status() is a leading indicator of the kind of shared-memory corruption that produces segfaults.
  • Do not raise the threshold to suppress noise. If the breaker is firing, the workers are crashing. Suppressing the signal does not stop the crashes.

How Netdata helps

  • The PHP-FPM collector surfaces status page counters (accepted conn, active processes, idle processes, max children reached, listen queue) at per-second resolution, so the dip-and-recover shape of an emergency restart is visible as a sharp reset to zero rather than a gradual trend that polls miss.
  • Worker exit signals from the error log, filtered to SIGSEGV and SIGBUS, line up against the threshold log line on the same timeline. The deaths that tripped the breaker are visible in the seconds before the restart, not just inferred afterward.
  • OPcache hit rate, memory usage, and `oom_restarts` sit next to the pool metrics, so the cold-start penalty after the restart is easy to separate from the original crash.
  • ML anomaly detection on accepted connections and active worker count flags the restart window even when no static threshold would have fired, which matters when the breaker is misconfigured to 0 and the only signal is degraded throughput.
  • cgroup memory pressure (memory.events.oom_kill, memory.current versus memory.max) correlates with worker deaths on containerized deployments, where the OOM killer can precede the OPcache corruption that actually trips the breaker.
  • Master process uptime (from the status page start_since field) confirms the restart happened at all, which is the first question when a status page counter has reset to zero and nobody knows why.