Network observability · self-hosted · MCP-native

See everything crossing your network. Then let your agents ask it questions.

NitroNet collects flow, packets, SNMP, syslog and OpenTelemetry onto one box you own, resolves every address through built-in IPAM, maps the topology and keeps device configs under version control. Your engineers get the dashboards. Your agents get all seventeen MCP tools over exactly the same data.

Free tier, no per-device fees, no sales call. One host, one command, about ten minutes.

nitronet · wan1-edge collecting
egress bps · 15m+412% @14:02
13:47 14:02
top talkers · resolved by ipambytes
Dallas · backup VLAN8.4 GB
HQ · ERP cluster3.1 GB
Austin · guest wi-fi1.8 GB
Denver · voice0.7 GB
agent session / mcp3 tools · 1.8s
get_interface_perf("wan1-edge") discards 8,411/s
diff_config("wan1-edge", since:"13:30") policer removed 13:58
check_synthetic("erp.internal") timeout ×6
conclusion · confidence 0.94

The 13:58 config push dropped the egress policer. Dallas backup traffic saturated the link four minutes later and starved ERP.

proposed: apply_config(snapshot:"13:41") awaiting approval
100Kflows / sec / node
8telemetry sources, one store
17MCP tools exposed
$0per device, ever

What you get on day one

A complete observability platform, not an API with a chat box on top.

NitroNet is a React front end over a Node backend, and it is the thing your team lives in. Flow analytics, device and interface health, TCP performance, topology, synthetics, syslog, IPAM, config history and incidents — all reading from one store, on one clock, with one address space. The agents came later. The platform came first.

Flow analytics

Who talked to whom, over what, for how long — filtered by site, subnet, application, ASN or country, and drillable from a chart down to the individual conversation.

NetFlow · IPFIX · sFlow · VPC

Devices and interfaces

SNMP health, utilisation, errors and discards per interface, with baselines rather than fixed thresholds, so the alert fires when the line moves and not when it crosses 80%.

v1–v3 · vendor-aware · AES-256-GCM

TCP performance

The packet probe turns a SPAN into flow records carrying round-trip time, retransmits, window stalls and microbursts, so “the network is slow” becomes a measurement.

RTT · retransmits · SNI via TLS/QUIC

Topology

LLDP-derived maps with role-based layout. Click a link and you are looking at the flows crossing it, not a separate tool with a separate login.

LLDP · L2/L3 · link drill-down

Synthetics and paths

The same probe binary runs as a test agent: ICMP, DNS and HTTP checks with traceroute path capture from wherever you place it, so you see the hop that changed.

icmp · dns · http · traceroute

IPAM that does real work

Prefix assignment, RFC1918 handling, CSV and REST import — and because it lives inside the platform, every flow record, alert, topology edge and agent answer is already labelled “Dallas backup VLAN” rather than 10.14.88.0/22.

subnet · site · owner

Config management

Collect and push device configuration with built-in Ansible playbooks, keep every version, and see each change land on the incident timeline next to the traffic it affected.

collect · diff · push · rollback

Incidents and reports

Signals become one scored incident with its evidence attached, routed to Slack, Teams, ServiceNow or a webhook — plus scheduled, customer-ready reports for the people who never log in.

dedupe · score · evidence · export

The data plane

Eight sources. One columnar store. One clock.

Most shops run four tools that each see a slice and none of which agree on what time it is. NitroNet lands everything in the same place, so a flow record, an interface counter, a syslog line and a config change can be read side by side — by a person or by an agent.

Flow NetFlow v5/v9, IPFIX and sFlow at line rate, enriched with GeoIP, ASN, DNS and your own IPAM labels. goflow2 → Kafka → ClickHouse
Packet probe A deployable probe that converts packets into flow records carrying the performance metrics routers never export. RTT · retransmits · microbursts · SNI
Synthetics The same probe, run as a test agent: ICMP, DNS and HTTP checks with traceroute path capture and deviation alerting. icmp · dns · http · traceroute
SNMP v1 through v3 with AES-256-GCM credential storage and vendor-aware handlers. Cisco · Arista · Juniper · Palo Alto · Fortinet · Aruba · Dell
Logs Device syslog, parsed and charted by severity beside the traffic it describes. syslog → search → dashboards
OpenTelemetry Native OTLP ingest for traces and metrics, so application spans line up beside the flow records that carried them — and the same data exports back out to whatever you already run. OTLP in & out · traces · metrics
Cloud AWS VPC flow logs enriched with account metadata and drawn into the same topology as everything else. Vector → VPC flow logs
Configs & address space Device configuration under version control and a built-in IPAM that names every address in every record, so the data arrives already labelled with the site and owner it belongs to. Ansible · prefix assignment · CSV & REST import

MCP-native, not MCP-adjacent

Seventeen tools. Any agent that speaks MCP can call them.

Everything the UI can render, the API can return and an agent can call. NitroNet ships a full Model Context Protocol server alongside the REST API, so the platform is not only a place your team logs into — it is a capability your agents already have. Point Claude Desktop or Claude Code at it, wire it into your own orchestration, or let it back a runbook. Same tools, same data, same permissions.

Query Ask for flows, interface counters, TCP performance, syslog or synthetic results and get rows back, not summaries of rows. query_flows · get_counters · get_interface_perf · search_logs
Context Resolve an address to its subnet, site and owner, walk the topology, list devices, pull the configuration history for any of them. lookup_prefix · get_topology · list_devices · diff_config
Test Run a synthetic check or a traceroute on demand from any probe and read the path back, so an agent can confirm a fix instead of assuming one. run_synthetic · check_synthetic · trace_path
Act Push a configuration, acknowledge an incident, open a ticket — each one gated behind an approval step you control. apply_config · ack_incident · create_ticket

Connected in about a minute.

// claude_desktop_config.json
{
  "mcpServers": {
    "nitronet": {
      "url": "https://nitronet.internal/mcp",
      "headers": {
        "Authorization": "Bearer <token>"
      }
    }
  }
}

Then ask it something you would otherwise open four tabs for: which change caused the egress spike on wan1-edge this afternoon?

Open at both ends.

OTLP in, MCP and REST out. Self-hosted should mean you own your telemetry, not that it is stuck in someone else’s box — including ours. Everything the MCP server exposes is available over the REST API too, so if you would rather build against it directly, nothing is hidden behind the agent.

Run Claude for reasoning quality, or point the platform at Ollama on-premises when prompt context cannot leave the building. The tools are identical either way; the model is a setting, not an architecture.

Read the tool reference →

What the agents do with it

Reasoning you can audit, on data you can check.

An agent is only as good as what it can see, which is why the platform came first. Because the answers are queries against your store rather than inferences about a dashboard, every conclusion traces back to a tool call you can re-run yourself.

01

Correlation

Signals from flow, SNMP, syslog, config, topology and IPAM assemble into one incident with a stated cause and a confidence score. Duplicates collapse instead of paging you five times.

02

Prediction

Baseline deviation catches the slow ones — memory leaks trending toward an OOM, interfaces drifting toward saturation — while there is still time to schedule the fix.

03

Grounding

Findings are computed deterministically first; the model writes the explanation over the top. Every number in an answer came from a query, never from the model.

04

Human in the loop

Agents propose; you approve. Actions route through ServiceNow or Teams for sign-off, and every step stays on the audit trail.

Why self-hosted

Your telemetry is a map of your network. Stop mailing it out.

SaaS observability means every flow record, every device name and every topology edge lives in someone else’s account, priced by the device, renewed on their terms. For a bank, a utility or a defence supplier, that is not a pricing objection — it is a non-starter.

Run it on your own iron
SaaS observability
NitroNet
Priced per device, per month
Free tier, then flat
Telemetry stored off-site
Never leaves your network
Retention capped by tier
Capped by your disk
Egress and ingest charges
None
Four tools, four clocks
One store, one address space
Air-gapped? Not supported
Supported
Their model, their cloud
Ollama on-prem, if you like

From nothing to first flows

Three steps, and none of them involve a salesperson.

There is no trial clock, no device count to declare and no procurement conversation. Install it on a spare VM this afternoon and decide for yourself.

1

Install

One host with 8 vCPU, 16 GB of RAM and Docker. Paste the command, wait about ten minutes, log into the UI.

2

Point things at it

Aim your flow exporters and syslog at the collector, add SNMP credentials, import your subnets from CSV. Traffic starts charting immediately.

3

Connect an agent

Add the MCP endpoint to Claude Desktop, Claude Code or your own orchestration, and start asking questions of the data you just collected.

Straight answers

Questions engineers ask before they install anything.

Is NitroNet actually free, or is this a trial?
Free, with no time limit and no per-device fee. The free tier runs the whole platform — NetFlow, IPFIX, sFlow, SNMP, OpenTelemetry, syslog, packet probes, synthetics, topology, IPAM, config management and the MCP server — on hardware you own. Paid tiers add multi-tenancy for MSPs, longer support commitments and scale-out beyond a single node.
Is there a user interface, or is this an API with a dashboard bolted on?
There is a full React front end over a Node backend, and it is where your team will spend its time: flow analytics with drill-down, per-device and per-interface views, TCP performance from the packet probes, LLDP topology maps, incident timelines with evidence, synthetic and traceroute results, syslog search, IPAM and config diffs. The REST API and the MCP server sit on the same data, so people and agents are always looking at the same numbers.
What hardware do I need to run it?
One machine with 8 vCPU, 16 GB of RAM and 200 GB of disk, running Ubuntu 22.04 or later with Docker. A single node sustains roughly 100,000 flows per second and polls thousands of devices. Retention is bounded by your disk, not by a pricing tier.
What does the packet probe do that flow does not?
It reads packets off a SPAN or tap and emits flow records enriched with performance data your routers never export: TCP round-trip time, retransmissions, window behaviour, microbursts and the SNI from TLS or QUIC handshakes. That is the difference between seeing that a conversation happened and seeing that it was slow. The same probe binary also runs as a synthetic agent — ICMP, DNS and HTTP tests with traceroute path capture — so one deployment gives you both passive and active measurement from the same vantage point.
Does any of my network data leave my network?
No. Flow records, device names, configs and topology all stay in your own ClickHouse and PostgreSQL instances. If you point the agents at Claude, prompt context goes to Anthropic; if that is unacceptable for your environment, run Ollama locally and nothing leaves the building at all. The installer reports its hostname and specs once for licensing, and that can be switched off.
Which devices and vendors are supported?
SNMP v1 through v3 with vendor-aware handlers for Cisco, Arista, Juniper, Palo Alto, Fortinet, Aruba and Dell, plus generic support for anything that speaks standard MIBs. Flow collection is vendor-neutral — any exporter emitting NetFlow v5/v9, IPFIX or sFlow works, including AWS VPC flow logs.
What does the MCP server actually let me do?
It exposes the platform as callable tools, so an agent can query flows, read interface counters and TCP performance, search syslog, diff a device configuration, resolve an address against IPAM, walk the topology and run a synthetic test on demand — then propose an action for you to approve. Point Claude Desktop or Claude Code at it, or wire it into your own orchestration. See the MCP section for the tool groups.
How is this different from SolarWinds, Kentik or Zabbix?
Three structural differences. It is self-hosted, so telemetry never sits in a vendor's cloud and pricing does not scale with device count. It is one platform rather than four products, so flow, packets, SNMP, syslog, configs, IPAM and synthetics already share a clock and an address space instead of being correlated by hand. And it ships an MCP server, so the same data your engineers read is callable by your own AI agents without anyone building an integration first.
Can I export my data back out?
Yes. OTLP works in both directions, so metrics and traces can flow out to whatever you already run, and the REST API is open and documented. Self-hosted should mean you own your telemetry, not that it is trapped in someone else's box — including ours.

Free tier · no credit card · no sales call

One box, one command, about ten minutes.

Give it 8 vCPU, 16 GB of RAM and an Ubuntu 22.04 host with Docker. Point your exporters at it and watch the first flows land.

curl -fsSL https://nitronet.ai/download/s/<your-token>.sh | sudo bash

Tell us where to send your token and the command arrives ready to paste.

Get my install command

Rather look first? Read the quickstart or book a walkthrough.