The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

Buyer’s Guide - August 2026

The 6 best tools for monitoring Logstash itself

Logstash exposes a rich monitoring API on port 9600: JVM heap, event throughput, queue depth, per-pipeline and per-plugin stats. The tools that matter are the ones that consume that API, not the ones that merely accept the logs Logstash ships. This ranking grades six tools on metric depth, collection granularity, alerting, and what the bill looks like as your pipelines grow.

The 6 best tools for monitoring Logstash itself product interface

Why this list exists

Most “Logstash monitoring” searches surface log management platforms that ingest the logs Logstash ships. That is log shipping, not Logstash monitoring. Monitoring Logstash means watching the process and its pipelines: JVM heap and garbage collection, events in/filtered/out, event duration, persistent queue fill, plugin performance, and reload failures. The only honest source for that data is the Logstash monitoring API on port 9600, and the tools on this list are the ones that actually consume it.

The mistake buyers make is assuming their existing log platform covers the shipper itself. It usually does not. Vendors like Sematext, New Relic, and Instana integrate with Logstash as a log source and expose nothing about pipeline health. When a persistent queue fills and ingestion stalls, those platforms go quiet precisely because Logstash has stopped sending them data.

Three dimensions decide which tool fits:

  1. Metric depth. Does the tool pull node stats, JVM stats, pipeline stats, and queue stats from the monitoring API, or does it only check process up/down?
  2. Collection granularity. Queue backpressure and event-duration spikes can appear and resolve in seconds. Per-second collection catches them; 30 to 60 second polling often misses them entirely.
  3. Cost shape. Does the bill grow with hosts, with log volume, with metric cardinality, or with a second monitoring cluster you have to run yourself?

One note on pricing: we do not quote competitor list prices here. Vendor pricing pages change, tiers shift, and a stale dollar figure is worse than none. Each card links the vendor’s official pricing page so you can check current numbers. For operator-level detail on the metrics themselves, the Logstash monitoring guides cover the API endpoints, queue tuning, and heap sizing in depth.

Methodology

How we evaluated Logstash monitoring tools

We assembled the shortlist from tools with a documented Logstash integration that consumes the monitoring API on port 9600: vendor documentation, maintained open-source exporters and plugins, and community templates listed on official integration pages. Tools that only accept Logstash output as a log source were excluded.

The two heaviest criteria are metric depth and collection granularity, because they determine whether you can actually troubleshoot a pipeline stall or only confirm that the process is running. Alerting and deployment cost follow, since an integration you cannot afford to operate or that never pages you is not monitoring.

Tester credit

Compiled by the Netdata team - Updated August 12, 2026

Scoring criteria

  • Logstash metric depth and coverage 25%
    JVM, events, queues, per-pipeline and per-plugin stats from the monitoring API
  • Collection granularity 20%
    Per-second vs 30-60s polling for short-lived bottlenecks
  • Alerting and anomaly detection 15%
    Queue backpressure, heap pressure, reload failures, ML vs hand-built thresholds
  • Deployment and operational cost 15%
    What you run, what you pay, and how the bill grows
  • Ease of setup 10%
    Auto-discovery and zero config vs manual exporter and template assembly
  • Ecosystem and integrations 10%
    Kubernetes, Elasticsearch, Kafka, Prometheus, notification channels
  • Maintenance and community health 5%
    Is the integration tested against current Logstash versions

Vendor 01 / 06 · #netdata

01

Netdata

Open-source, per-second infrastructure and application monitoring with built-in ML anomaly detection and a dedicated Logstash collector.

Netdata application monitoring dashboard showing per-second metric charts for a monitored application, illustrating the real-time metric visualization used for Logstash JVM and pipeline monitoring.

Best for

  • Teams that want Logstash JVM, event, and pipeline metrics at per-second granularity without building a Prometheus exporter stack
  • Buyers who want anomaly detection and alerting on Logstash health without writing thresholds for every metric
  • Organizations that want to avoid per-GB log-ingest pricing for infrastructure metrics

Pricing

  • Per-node pricing: Netdata Cloud Business starts at $4.50/node/month on annual plans, with the per-node price decreasing as node count grows
  • Free Cloud tier for small fleets (up to 5 active connected nodes), with unlimited metrics and logs
  • Agents are open source (AGPL) and self-hosted; you run and operate them yourself
  • No per-GB, per-metric, or per-series charges; containers on a monitored host are included

Pros

  • Dedicated Logstash collector (go.d.plugin) polls the Logstash monitoring API with a default update_every of 1 second
  • Covers JVM threads, heap memory, garbage collection, open file descriptors, events in/filtered/out, event duration, uptime, and per-pipeline metrics
  • 800+ integrations with auto-discovery and zero configuration; dashboards and alerts come out of the box
  • Unsupervised ML runs on every metric for anomaly detection and root-cause correlation, so a queue fill or GC storm gets flagged without a hand-tuned threshold
  • Distributed architecture keeps metric data on your infrastructure; only views stream to the cloud
  • Per-node pricing means the bill does not grow with log volume or metric cardinality

Where teams pair it

  • The Logstash collector ships with no default alert rules; you configure Logstash-specific thresholds (queue growth, reload failures, heap pressure) yourself
  • No pipeline topology viewer equivalent to Elastic’s Pipeline Viewer; Netdata visualizes metrics, not the pipeline graph
  • No prebuilt Logstash-specific dashboard template; you assemble custom dashboards from the collected JVM, event, and pipeline metrics

Verdict

Netdata is the only tool on this list that combines per-second collection of the full Logstash monitoring API with built-in ML anomaly detection and zero-configuration setup, without requiring a second monitoring cluster, a separately installed community agent check, or a DIY exporter stack. When a persistent queue starts filling at 3 AM, per-second granularity is the difference between seeing the ramp and seeing a flat line followed by an outage. The honest caveats: Logstash alerting is not prebuilt, so you write those rules yourself, and there is no pipeline topology view. For teams that need the pipeline graph, pairing Netdata’s metrics with Elastic’s Pipeline Viewer is a reasonable split.

Vendor 02 / 06 · #elastic

02

Elastic Observability

The native monitoring stack for Logstash, with Stack Monitoring, a Pipeline Viewer UI, and monitoring APIs built into every Logstash node.

Best for

  • Teams already running the Elastic Stack who want Logstash monitoring in the same Kibana UI as their logs
  • Operators who need the Pipeline Viewer to see pipeline topology and plugin-level throughput
  • Organizations that want first-party support for Logstash monitoring rather than a third-party integration

Pricing

  • Elastic Cloud Hosted uses resource-based pricing, pay-as-you-go or prepaid
  • Elastic Cloud Serverless is usage-based on ingested and processed data
  • Self-managed licensing is based on node count and RAM allocated
  • The bill grows with the monitoring cluster: monitoring Logstash requires running Elasticsearch and Kibana to store and view the data, which adds footprint on top of the production stack

Pros

  • Native Stack Monitoring: Elastic Agent collects Logstash node and pipeline stats into a monitoring cluster, with the deepest Logstash-specific coverage of any vendor
  • Logstash exposes monitoring APIs by default (node info, node stats, hot threads, health report, plugins info) with no extra configuration
  • Pipeline Viewer UI shows pipeline topology, plugin events in/out, and worker utilization, which no other tool on this list matches
  • Covers JVM stats, process stats, event stats, pipeline runtime stats, and hot threads
  • Monitoring APIs can be secured with TLS and HTTP basic auth via logstash.yml

Cons

  • Requires a separate monitoring cluster (Elasticsearch plus Kibana) to store and view Logstash monitoring data, roughly doubling the Elastic footprint you operate
  • Monitoring collection adds overhead to the Logstash nodes being monitored
  • Self-managed licensing scales with node count and RAM, so the monitoring cluster itself grows the bill
  • Collection is polling-based at typical stack-monitoring intervals of tens of seconds, not per-second

Verdict

If you already run the Elastic Stack, this is the deepest Logstash monitoring available: Elastic owns Logstash, so the APIs, the Pipeline Viewer, and Stack Monitoring are first-party and current. The Pipeline Viewer alone earns it the second spot, because no third-party tool shows pipeline topology and plugin-level flow. The cost is architectural. You run a second Elastic cluster just to watch the first one, and collection granularity is polling-based, so short-lived queue spikes can slip between intervals. Elastic-centric shops should start here; everyone else pays a heavy tax for the privilege.

Vendor 03 / 06 · #datadog

03

Datadog

SaaS observability platform with an agent-based Logstash integration that collects JVM, process, pipeline, plugin, and queue metrics from the monitoring API.

Best for

  • Teams already standardized on Datadog for infrastructure and APM who want Logstash metrics alongside everything else
  • Organizations that want a fully managed SaaS with no monitoring cluster to operate
  • Buyers who need Logstash log shipping (via logstash-output-datadog_logs) and Logstash metrics in one platform

Pricing

  • Modular per-product usage-based pricing across Free, Pro, and Enterprise tiers
  • Infrastructure is billed per host; Log Management is billed per GB ingested and per million events indexed
  • Custom metrics are billed beyond per-host allotments
  • The bill grows with host count, log volume, and metric cardinality across products, which compounds quickly in log-heavy environments

Pros

  • Logstash check collects process, JVM, reload, pipeline/event, plugin, and queue metrics as gauges from the monitoring API
  • Includes a logstash.can_connect service check for availability alerting
  • Log collection via the logstash-output-datadog_logs plugin with gzip compression and regional endpoints
  • Supports the multi-pipeline metrics introduced in Logstash 6.0
  • Agent-based collection works in containers via Autodiscovery templates

Cons

  • The Logstash check is a community integration, not bundled in the Datadog Agent; it must be installed separately with datadog-agent integration install
  • Documented compatibility is Logstash 5.x-7.x; there is no verification against Logstash 8.x, including the 8.5+ flow metrics
  • Per-host plus per-GB log pricing makes the bill grow with both infrastructure size and log volume
  • The check collects no events, only metrics and one service check

Verdict

Datadog covers the right metric surface: JVM, pipelines, plugins, queues, and reloads, plus a connectivity service check, and the default 15-second check interval is respectable. Two things hold it back. The integration is community-maintained and documented only through Logstash 7.x, so current 8.x flow metrics are unverified territory. And the pricing shape, per host plus per GB plus custom metrics, is exactly the model that punishes log-pipeline-heavy infrastructure. If Datadog is already your standard, add the check. If you are choosing fresh, weigh the bill trajectory carefully.

Vendor 04 / 06 · #prometheus-grafana

04

Prometheus + Grafana

Open-source metrics stack that monitors Logstash through the actively maintained kuskoman/logstash-exporter, visualized in Grafana dashboards.

Best for

  • Teams already running Prometheus and Grafana who want Logstash metrics in the same dashboards as the rest of the stack
  • Kubernetes shops: the exporter ships a Helm chart, a controller mode for auto-discovery, and a dedicated Grafana dashboard
  • Buyers who want open-source tooling with no per-host or per-GB vendor lock-in

Pricing

  • Prometheus and Grafana are open source and self-hosted; you run and operate them, and the cost is infrastructure, storage, and engineering time
  • Grafana Cloud SaaS is usage-based: per thousand active series for metrics, per GB for logs and traces
  • The kuskoman/logstash-exporter is open source (MIT-licensed lineage) and self-hosted; you run and operate it
  • The bill grows with active series and log volume on Grafana Cloud, or with your own operational effort when self-hosted

Pros

  • kuskoman/logstash-exporter is actively maintained (v1 in production, v2 in beta) and exposes node, JVM, pipeline, plugin, queue, flow, and reload metrics
  • Grafana dashboard 18628 (Logstash on Kubernetes) provides prebuilt system, JVM, pipeline, and plugin visualizations
  • Exporter supports TLS, bearer token, and basic auth against the Logstash monitoring API
  • Kubernetes controller mode auto-discovers Logstash instances via annotations
  • The Prometheus ecosystem provides flexible alerting through Alertmanager

Cons

  • The exporter is tested against a single Logstash version; other versions may expose metrics that do not map cleanly, so verify before rollout
  • You assemble and operate Prometheus, Grafana, the exporter, and Alertmanager yourself; there is no integrated product
  • The original BonnierNews logstash_exporter is archived (read-only since November 2025), so the ecosystem depends on one maintainer’s fork
  • No built-in anomaly detection; alerting requires hand-written PromQL thresholds

Verdict

For teams that already live in the Prometheus ecosystem, this is the natural answer: the exporter covers the full monitoring API surface including Logstash 8.5+ flow metrics, the Kubernetes story is genuinely good, and nothing is locked to a vendor. The trade-off is that everything is DIY. You run four components, write your own PromQL alerts, and depend on a single maintainer’s fork now that the original exporter is archived. Scrape intervals of 15 to 30 seconds are also coarse enough to blur fast queue spikes. Strong choice for Prometheus shops; a lot of assembly for everyone else.

Vendor 05 / 06 · #zabbix

05

Zabbix

Open-source enterprise monitoring platform with a community Logstash template that collects pipeline and JVM metrics via the monitoring API.

Best for

  • Organizations already running Zabbix for infrastructure monitoring who want Logstash checks in the same platform
  • Teams that prefer a self-hosted platform with no license fees and a large community
  • Buyers who need Logstash monitoring alongside network, server, and application monitoring in one tool

Pricing

  • Zabbix software is open source and self-hosted; no license fees and no device limits, but you run and operate it
  • Optional support subscriptions (Silver through Global) are priced by response SLA and server count
  • Zabbix Cloud SaaS is offered in tiered plans sized by monitored environment
  • The bill grows with support coverage and cloud tier, not with hosts or metrics

Pros

  • The official Zabbix integrations page lists a Logstash solution (fredprod/logstash-zabbix) built on the Python protobix library
  • Template covers Logstash status, pipeline low-level discovery, JVM memory, and pipeline event metrics
  • Zabbix itself is actively maintained (7.4 current) with a large community and broad infrastructure coverage
  • No license fees and no host limits on the self-hosted platform

Cons

  • The Logstash template is community-maintained and targets Logstash 5.x-6.x era metrics, not current 8.x flow metrics
  • Polling at Zabbix’s typical 30-60 second intervals misses short-lived pipeline bottlenecks
  • Requires Python protobix setup and manual template import; there is no zero-config Logstash discovery
  • No Logstash-specific anomaly detection; alerting is threshold-based

Verdict

Zabbix is a capable general monitoring platform, and if your organization already runs it, adding the Logstash template costs little. But be clear-eyed about what the template is: a community artifact aimed at Logstash 5.x and 6.x, polling at intervals too coarse to catch fast queue events, with manual setup and no discovery. It answers “is Logstash up and roughly how busy” rather than “why did the pipeline stall for forty seconds.” Fine as an add-on for Zabbix shops; not a reason to adopt Zabbix.

Vendor 06 / 06 · #icinga

06

Icinga

Open-source monitoring platform with the NETWAYS check_logstash plugin for Logstash health, pipeline, flow, and reload checks.

Best for

  • Teams already running Icinga 2 who want Logstash health and pipeline checks added to their existing monitoring
  • Organizations that prefer Nagios-style check-based monitoring with open-source licensing
  • Operators who need threshold alerts on heap usage, CPU, file descriptors, and inflight events

Pricing

  • Icinga core is open source and self-hosted, with the open-source community edition covering unlimited hosts and services; you run and operate it
  • Optional paid subscriptions cover repository access for enterprise Linux, enterprise modules, and support (8x5 or 24/7)
  • Support subscriptions are priced by number of Icinga servers, not by monitored hosts
  • The bill grows with support level and enterprise OS coverage, not with Logstash nodes

Pros

  • NETWAYS check_logstash plugin provides health checks (heap, CPU, file descriptors), pipeline checks (inflight events), flow checks (queue backpressure, requires Logstash 8.5+), and reload checks
  • Supports HTTPS, bearer token, and basic auth against the Logstash monitoring API
  • Icinga 2 is actively maintained with current 2.16.x releases and a strong open-source community
  • GPLv3-licensed plugin that integrates with the broader Nagios-compatible plugin ecosystem

Cons

  • Check-based monitoring produces point-in-time status, not continuous metric streams; there is no per-second history for troubleshooting
  • No Logstash-specific visualization; you need Grafana or Icinga Web 2 add-ons for graphs
  • No anomaly detection; alerting is threshold-based on check results
  • Requires installing and configuring the plugin plus the Icinga 2 and Icinga Web 2 infrastructure

Verdict

check_logstash is a well-built plugin, and its flow check against the Logstash 8.5+ queue backpressure metrics shows the maintainer keeps it current. For an Icinga shop that wants to get paged when heap pressure climbs or a reload fails, it does the job cleanly. What it cannot do is help you troubleshoot after the page: check intervals of one to five minutes leave no fine-grained history, and there are no Logstash dashboards. Treat it as an alerting layer for Icinga users, not a Logstash metrics platform.

Frequently asked questions