The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / network / network-udp-rcvbuf-errors

Operations Guides

Udp_RcvbufErrors: tuning kernel receive buffers for flow, trap, and syslog collectors

Udp_RcvbufErrors is incrementing on your flow collector. Flow charts show traffic declining during what is actually a traffic spike. The kernel is receiving datagrams from exporters but the socket receive buffer is full, so it drops them silently. No application-level counter moves. No error log fires. The dashboards lie downward while the real traffic goes upward.

Flow collectors (NetFlow v5/v9, IPFIX, sFlow), SNMP trap receivers (UDP 162), and syslog receivers (UDP 514) all depend on UDP socket buffers. When the buffer overflows, the kernel increments Udp_RcvbufErrors in /proc/net/snmp and discards the datagram. The application never sees it.

The mainline Linux kernel default for net.core.rmem_max is 212,992 bytes (~208 KiB), though RHEL-based distributions commonly ship with 4,194,304 bytes (4 MB). Either value is the starting point for most incidents at this layer. Production flow collectors typically need 16 MB or more. Very high-pps sFlow collectors may need 33 MB. But raising the ceiling alone is not always the fix: the application must request a larger buffer via SO_RCVBUF, the parser must drain it fast enough, and the global UDP memory ceiling (net.ipv4.udp_mem) can impose a separate limit.

What this means

When a UDP datagram arrives, the kernel attempts to place it in the destination socket’s receive buffer. If the buffer is full because the application has not read from it fast enough, the kernel drops the datagram and increments Udp_RcvbufErrors. The counter is system-wide across all UDP sockets. It does not tell you which socket, which port, or which exporter was affected.

Two layers of drops exist, and they have different fixes:

  • NIC ring buffer drops happen at the hardware level, before the packet reaches the socket layer. Check /proc/net/dev RX drop columns and ethtool -S <iface> for counters like rx_missed_errors.
  • Socket buffer drops happen after the NIC has accepted the packet, at the kernel-to-application delivery boundary. Check Udp_RcvbufErrors and ss -lun -m Recv-Q.

Both must be monitored. If only one is rising, it narrows the problem. If both are rising, the entire receive path is saturated.

flowchart TD
    A[UdpRcvbufErrors incrementing] --> B{NIC RX drops rising too?}
    B -- Yes --> C[Fix NIC ring buffer and RSS first]
    B -- No --> D[Problem is at socket layer]
    D --> E{ss -m: Recv-Q near limit?}
    E -- No --> F[Check udp_mem global pressure]
    E -- Yes --> G{Collector CPU pattern?}
    G -- One core at 100% --> H[RSS misconfiguration]
    G -- System-wide high --> I[Parser or TSDB bottleneck]
    G -- Low or normal --> J[Undersized rmem_max]
    J --> K[Raise rmem_max + rmem_default]
    K --> L[Verify app sets SO_RCVBUF]

Common causes

CauseWhat it looks likeFirst thing to check
Undersized rmem_maxDrops proportional to incoming packet rate; ss -m shows Recv-Q at limitsysctl net.core.rmem_max
Slow consumer (parser or TSDB write blocked)Drops during bursts; collector CPU not fully utilized (I/O bound)Collector write queue depth or parser stats
RSS misconfigurationOne CPU core pinned at 100% while others are idle; drops during high ppscat /proc/interrupts | grep <iface>
Global UDP memory pressureDrops continue even after raising rmem_max and SO_RCVBUFcat /proc/sys/net/ipv4/udp_mem
Application not requesting larger bufferrmem_max raised but ss -m shows buffer still at old sizegetsockopt return value or app config

Quick checks

All read-only and safe to run on a production collector:

# System-wide UdpRcvbufErrors counter
nstat -az UdpRcvbufErrors

# Same data via /proc/net/snmp (RcvbufErrors column)
cat /proc/net/snmp | grep '^Udp:'

# Current socket buffer fill for a flow listener on port 2055
ss -lun '( sport = :2055 )' -m

# Current rmem_max and rmem_default
sysctl net.core.rmem_max net.core.rmem_default

# Global UDP memory pressure limits (min pressure max, in pages)
cat /proc/sys/net/ipv4/udp_mem

# NIC RX drops (happen before socket layer)
cat /proc/net/dev

# Detailed NIC drop counters
ethtool -S eth0 | grep -i drop

# Per-core CPU utilization and softirq distribution
mpstat -P ALL 1 5

# IRQ distribution for the NIC
cat /proc/interrupts | grep eth0

# Kernel packet processing backpressure
cat /proc/net/softnet_stat

How to diagnose it

  1. Confirm the counter is actively incrementing. Run nstat -az UdpRcvbufErrors twice, 30 seconds apart. The second value should be higher if drops are ongoing. A historically nonzero value that is not growing may represent a past incident already resolved.

  2. Check whether NIC-level drops are also rising. Read /proc/net/dev and ethtool -S <iface> for rx_missed_errors. If NIC drops are rising alongside UdpRcvbufErrors, fix the NIC ring buffer and RSS first. The socket buffer overflow is a downstream symptom of packets arriving faster than the kernel can process them at all.

  3. Inspect the listener socket’s current buffer state. Run ss -lun '( sport = :2055 )' -m (replace 2055 with 6343 for sFlow, 4739 for IPFIX, 162 for traps, 514 for syslog). If Recv-Q is near the buffer limit, the application is not draining fast enough.

  4. Check the effective buffer size. The ss -m output shows the actual receive buffer allocated. If you raised rmem_max but the socket still shows the old size, the application has not called setsockopt(SO_RCVBUF) with the larger value, or it was started before the sysctl change. Already-running sockets do not pick up a new rmem_max automatically.

  5. Examine CPU utilization per core. Run mpstat -P ALL 1 5. A single core at 100% in the %soft column indicates RSS is funneling all packet processing to one CPU. System-wide high CPU indicates a parser or TSDB bottleneck.

  6. Check global UDP memory pressure. If drops persist after raising rmem_max and verifying SO_RCVBUF, read cat /proc/sys/net/ipv4/udp_mem. This sets the global UDP memory ceiling across all sockets (format: min pressure max, in pages). If aggregate UDP memory exceeds the pressure threshold, the kernel drops packets even when individual socket buffers have room.

  7. Compare device-side export counts against collector inbound rate. On a Cisco device, walk the CISCO-NETFLOW-MIB (enterprise OID .1.3.6.1.4.1.9.9.387) to find per-exporter packet export counters. If the device exported significantly more than the collector received, the gap is silent loss in transit or at the socket buffer. This is the only reliable end-to-end loss detection method.

Metrics and signals to monitor

SignalWhy it mattersWarning sign
UdpRcvbufErrorsThe only direct kernel signal for socket buffer dropsAny nonzero increment in production
ss -m Recv-QShows real-time buffer fill per socketRecv-Q approaching buffer limit
UdpInDatagramsTotal UDP datagrams received, for computing drop ratioDrop ratio > 0.001 (0.1%)
NIC RX drops (/proc/net/dev)Drops at hardware layer, before socketAny nonzero RX drop rate on flow-ingress NIC
Per-core CPU %softIndicates RSS distribution problemsSingle core at 100% while others idle
Collector write queue depthSlow consumer backing up the bufferQueue growing without bound
Flow packets received rateIncoming load on the collectorSpike correlated with drop spike
udp_mem utilizationGlobal UDP memory pressureAggregate near pressure threshold
Flow inbound vs device exportedEnd-to-end loss detectionInbound significantly less than exported

Fixes

Raise rmem_max and rmem_default

The immediate fix for an undersized ceiling:

# Runtime change (takes effect for new sockets immediately)
sysctl -w net.core.rmem_max=16777216
sysctl -w net.core.rmem_default=8388608

# Persistent configuration
cat >> /etc/sysctl.d/99-udp-collector.conf << 'EOF'
net.core.rmem_max = 16777216
net.core.rmem_default = 8388608
EOF
sysctl --system

Start with 16 MB for rmem_max and 8 MB for rmem_default. For very high-volume sFlow collectors, 33 MB may be necessary. Already-running sockets do not pick up the new rmem_max automatically. The collector process must restart or re-bind its listener socket for the new ceiling to take effect.

Verify the application sets SO_RCVBUF

Raising rmem_max sets the ceiling, but the application must explicitly request a larger buffer via setsockopt(SOL_SOCKET, SO_RCVBUF, size). The kernel internally doubles the requested value for bookkeeping overhead, so getsockopt() returns roughly 2x what was requested. This doubling is documented in socket(7) and is normal behavior.

If the application uses SO_RCVBUFFORCE (requires CAP_NET_ADMIN or root), it can exceed rmem_max. Some hardened or containerized builds disable SO_RCVBUFFORCE, causing the application to fall back to the unprivileged SO_RCVBUF path silently. Check the application documentation for how it configures receive buffers. For rsyslog’s imudp module, the rcvbufSize parameter controls this. If rsyslog drops privileges before opening the socket, the unprivileged SO_RCVBUF call may be capped at rmem_max.

Raise udp_mem under global pressure

If UdpRcvbufErrors persists after raising rmem_max and verifying SO_RCVBUF, the system may be hitting the global UDP memory ceiling. Read cat /proc/sys/net/ipv4/udp_mem (values are in pages, typically 4 KB each). If aggregate UDP memory is near the pressure value, raise the max field proportionally. Raising rmem_max alone allows more sockets to request large buffers, which increases aggregate kernel memory pressure. Under udp_mem pressure, the kernel drops packets aggressively even within individual socket limits. The fix is to raise both rmem_max and udp_mem.max together.

Fix RSS distribution

If one CPU core is at 100% in %soft while others are idle, RSS is funneling all flow traffic to a single core. Verify IRQ distribution with cat /proc/interrupts | grep <iface>. The fix is platform-specific. Some NICs require ethtool -X to set the RSS indirection table. Others need IRQ affinity adjustments via /proc/irq/<n>/smp_affinity. The goal is to distribute receive interrupts across multiple cores so no single core becomes the bottleneck.

Fix the consumer

If collector CPU is system-wide high (not just one core), the bottleneck is the parser or the TSDB write path, not the buffer size. Raising rmem_max buys time by absorbing bursts but does not fix the throughput problem. Identify whether the parser is CPU-bound (heavy regex on every record) or I/O-bound (TSDB write queue blocking the ingestion thread). Common fixes: simplify parsing logic, batch TSDB writes, move log files to a separate volume from the TSDB, or scale the collector horizontally.

Prevention

  • Set rmem_max and rmem_default before deploying collectors. Apply the sysctl configuration as part of host provisioning, not as incident response. 16 MB is a safe baseline; 33 MB for high-volume sFlow.
  • Monitor UdpRcvbufErrors continuously. Any nonzero increment is abnormal in production. Alert on it directly, not on a derived threshold.
  • Verify SO_RCVBUF after every collector restart. Confirm the effective buffer size with ss -lun -m. Configuration changes during upgrades can silently reset buffer settings.
  • In Kubernetes, apply sysctls inside the pod network namespace. Each pod has its own network namespace. Changing rmem_max on the host node does not affect pod containers unless the setting is applied inside the pod (privileged init container or DaemonSet). CNI plugins vary in whether they inherit host sysctls, so verify empirically.
  • On Azure AKS, the default rmem_max is 1,048,576 bytes (1 MB). This is insufficient for any moderately busy collector. Use linuxOSConfig in the Node Pool API to raise netCoreRmemMax and netCoreRmemDefault before deploying UDP-based collectors.
  • Separate the TSDB volume from log storage. Log growth on the same volume as the TSDB has caused collector outages when disk fills.
  • Monitor per-core CPU. RSS misconfiguration is invisible in aggregate CPU utilization. Track per-core %soft to catch single-core saturation before it causes drops.

How Netdata helps

  • Netdata collects UdpRcvbufErrors from /proc/net/snmp natively, with per-second resolution. Alert on any nonzero increment without manual instrumentation.
  • The ipv4 collector exposes the full UDP SNMP table, including UdpInDatagrams, UdpRcvbufErrors, and UdpInErrors. Correlating receive rate against drop rate gives you the loss ratio directly.
  • Per-core CPU metrics are collected by default, making RSS misconfiguration visible as one core at 100% while others are idle.
  • NIC RX and TX drop counters from /proc/net/dev and ethtool -S are collected natively. Correlating NIC drops against socket buffer drops narrows the problem to the correct layer.
  • If Netdata is your syslog or trap receiver, the same UdpRcvbufErrors counter applies. Netdata monitors its own ingestion health.
  • Disk space and I/O metrics on the collector host help detect TSDB write bottlenecks before they back up the UDP receive buffer.
The Netdata solution

Network monitoring with Netdata

Netdata monitors network infrastructure with per-second interface metrics, SNMP, NetFlow/sFlow/IPFIX, and ML anomaly detection. Correlate interface flapping, packet drops, routing changes, and traffic spikes with the systems that depend on them.