The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / zookeeper / zookeeper-connection-drop-spike

Operations Guides

ZooKeeper connection drops spiking: sessions dying in bursts

A burst in zk_connection_drop_count means connections to a ZooKeeper server are closing in a tight window, not one at a time. When the burst pushes zk_stale_sessions_expired up simultaneously, you are looking at a session expiration storm in progress or one about to land on dependent services.

Occasional single drops across a large fleet are background noise. A sustained drop rate above roughly 0.1% of total connections per minute is where the signal stops being normal churn. Bursts that fire on a rhythm (every few minutes, hourly, at the same minute past the hour) almost always point to a JVM garbage collection cycle or a scheduled job that briefly saturates the leader.

The worst version cascades. Sessions expire, ephemeral nodes vanish, watches fire, clients reconnect simultaneously. That reconnection wave can push zk_outstanding_requests toward globalOutstandingLimit, which throttles new reads from client sockets and produces another round of timeouts. This article covers how to read the burst, find the trigger, and stop the cascade.

What this means

zk_connection_drop_count is a server-side counter of connections that closed. A connection can close for four reasons: the client session expired and the server dropped it, the client process crashed or cleanly closed its handle, the network dropped the TCP session, or the server closed it (throttle rejection, large request rejection, auth failure). The counter alone does not tell you which.

Correlate the burst with adjacent signals:

  • If zk_stale_sessions_expired jumps with the same shape, sessions are timing out. The drop is the consequence; the expiry is the cause.
  • If zk_jvm_pause_time_ms p99 spikes immediately before the burst, the trigger is GC. The pause stopped the heartbeat thread long enough to miss a renewal window.
  • If zk_connection_rejected spikes instead, the server is refusing new connections at maxClientCnxns per source IP, not killing existing sessions.
  • If zk_num_alive_connections drops sharply but zk_stale_sessions_expired is flat, clients are disconnecting on their own (client-side GC, load balancer change, fleet restart, DNS issue).
flowchart TD
  A[GC pause or network event] --> B[Heartbeats missed]
  B --> C{Pause exceeds session timeout?}
  C -- yes --> D[Sessions expire en masse]
  C -- no --> H[Connections drop, then recover]
  D --> E[Ephemeral nodes vanish]
  E --> F[Watch notifications fire]
  F --> G[Reconnection thundering herd]
  G --> I[Outstanding requests spike]
  I --> J[Latency spike, more drops]

Common causes

CauseWhat it looks likeFirst thing to check
JVM Stop-the-World GCRhythmic bursts matching GC frequency. zk_jvm_pause_time_ms p99 spikes moments before each burst. Disk I/O normal.zk_jvm_pause_time_ms p99 and GC log.
Leader failoverBurst concentrated in a 30 to 60 second window. zk_looking_count increments. zk_sum_leader_unavailable_time grows.zk_server_state and zk_looking_count on all members.
Network event (partition, NIC, switch)Sharp drop in zk_num_alive_connections across many clients at once. Ephemeral count mirrors the drop.Host retransmit counters, NIC errors, cons for source IP distribution.
maxClientCnxns rejectionzk_connection_rejected increments, not zk_connection_drop_count. Common in NAT-heavy container fleets.zk_connection_rejected and source IP spread.
clientPortListenBacklog exceededNew-connection failures during reconnect storms. Default (-1) applies a socket backlog of 50 on Linux; too low for production.OS ss -ltn and SYN queue overflow counters.
jute.maxbuffer rejectionSpecific clients repeatedly dropped. zk_large_requests_rejected increments.zk_large_requests_rejected and ZooKeeper log.

Quick checks

All read-only. Run on the node that owns the burst.

# Confirm the drop and adjacent signals in one pull
echo mntr | nc localhost 2181 | grep -E 'zk_(connection_drop_count|connection_rejected|stale_sessions_expired|num_alive_connections)'

# Confirm node is functional, not read-only (expect "rw")
echo isro | nc localhost 2181

# JVM pause signature on the same node
echo mntr | nc localhost 2181 | grep -E 'zk_.*jvm_pause'

# Leader and election history
echo mntr | nc localhost 2181 | grep -E 'zk_(server_state|looking_count|uptime|sum_leader_unavailable_time)'

# Rule out disk-induced election (fsync warning pattern in ZooKeeper logs)
grep "fsync-ing the write ahead log" /var/log/zookeeper/zookeeper.log | tail -20

# Server logs: "Expiring session 0x..., timeout of Nms exceeded"; client logs:
# "Client session timed out, have not heard from server in Nms for session id 0x..."
# Recent session expiry events
grep -iE "expir" /var/log/zookeeper/zookeeper.log | tail -50

# Connection distribution by source IP (expensive on large ensembles, use sparingly)
echo cons | nc localhost 2181 | grep -oE '^/[0-9.]+' | sort | uniq -c | sort -rn | head

# OS listen backlog and SYN queue drops
ss -ltn | grep 2181
nstat -az TcpExtListenOverflows TcpExtListenDrops | tail -5

How to diagnose it

  1. Confirm the burst is on the metric you think. Pull zk_connection_drop_count over the burst window. Compare against zk_stale_sessions_expired and zk_connection_rejected. If only zk_connection_rejected is moving, this is not your incident. Skip to the maxClientCnxns fix below.

  2. Time-align the burst with JVM pause and leader metrics. The single most common cause is a JVM Stop-the-World GC pause that exceeds the heartbeat cadence. If zk_jvm_pause_time_ms p99 spikes within the same minute as the burst, GC is your trigger.

  3. Check for an election in the same window. Pull zk_looking_count, zk_server_state, and zk_sum_leader_unavailable_time for all ensemble members. An election produces a burst of session expirations as clients reconnect during convergence.

  4. Quantify client impact. Pull zk_num_alive_connections and zk_ephemerals_count. If both drop by the same fraction, sessions expired and ephemeral state was lost. Downstream systems that read those ephemerals (Kafka broker registration, HBase RegionServer registration) are now reacting.

  5. Look for the network signature. OS-level TCP retransmits, NIC error counters, and listen-queue overflows all produce burst disconnects without server-side health issues. Compare burst timestamps across ensemble members: correlated bursts across all members point to a network or client-fleet event. A burst on one member points to that member’s GC or disk.

  6. Check client library versions for known regressions. ZOOKEEPER-4921 documents that the Java client shipped in ZooKeeper 3.9.3 fails to reconnect after network failures and expires the session instead of retrying; it is fixed in 3.9.4 and later. If your clients are pinned to 3.9.3, the fix is a client library upgrade, not a server-side change.

Metrics and signals to monitor

SignalWhy it mattersWarning sign
zk_connection_drop_countThe primary symptom. Burst shape reveals the trigger.Sustained rate above 0.1% of total connections per minute.
zk_stale_sessions_expiredConfirms drops are expirations, not client closes.Any non-zero rate outside maintenance.
zk_jvm_pause_time_ms (p99)Leading indicator for GC-triggered bursts.p99 approaching one-third of minSessionTimeout (default 4000ms).
zk_num_alive_connectionsMagnitude of the disconnect event.Sharp drop greater than 30% in one minute.
zk_ephemerals_countConfirms ephemeral state loss and downstream cascade.Sharp drop mirroring connection drop.
zk_looking_countElection trigger for session storms.More than one event per hour outside maintenance.
zk_outstanding_requestsConfirms cascade into pipeline saturation.Sustained above zero during the reconnection wave.
zk_packets_sentWatch notification fan-out signature.Spike without a corresponding zk_packets_received spike.
zk_large_requests_rejectedCatches the jute.maxbuffer case where a specific client is dropped repeatedly.Any non-zero rate.

Fixes

JVM GC pauses

If zk_jvm_pause_time_ms p99 aligns with the bursts, the trigger is GC. The fix is on the JVM, not on ZooKeeper itself.

  • Confirm the GC algorithm. ZooKeeper’s launcher scripts do not set a collector, so on JDK 9+ the JVM default G1GC applies. ZGC (JDK 15+) reduces pause times for heaps above a few GB.
  • Check heap sizing against data tree size. Pull zk_znode_count, zk_approximate_data_size, and zk_watch_count. If all three are growing, you are looking at the leading indicators of a GC death spiral. The fix is to cap the data tree (clean up unused znodes) or grow the heap.
  • Inspect the GC log for Full GC events longer than tickTime (default 2000ms). A Full GC that long risks leader election on top of session expiry.
  • Disable Transparent Huge Pages on the ZooKeeper host. THP can extend GC pauses significantly.

Do not restart ZooKeeper as the first action. A restart forces leader election, which produces another burst.

Network event

If the burst has no GC signature and no election, look at the path between clients and the ensemble.

  • Pull OS retransmit counters and NIC error counters on the ZooKeeper hosts.
  • Pull listen-queue overflows (TcpExtListenOverflows). If non-zero, raise clientPortListenBacklog in zoo.cfg instead of relying on the default. The documented default of -1 applies a socket backlog of 50 on Linux, and the OS somaxconn caps the effective value; both are too low for production reconnect storms.
  • Check switch firmware and NIC offload settings. Bad firmware under load produces burst packet loss that looks identical to GC pauses from the metrics side.
  • If clients sit behind a load balancer, check whether the balancer recently changed idle timeout or health check behavior.

maxClientCnxns rejection (different symptom)

If zk_connection_rejected is the moving counter rather than zk_connection_drop_count, the fix is to raise maxClientCnxns or fix the source IP concentration. The default of 60 per source IP is easily exceeded in containerized deployments where many pods share a host IP via NAT. The rejection is silent from the server side. Clients see connection refused or timeout.

Version-specific: 3.9.3 reconnect regression

ZOOKEEPER-4921 documents that the Java client shipped with ZooKeeper 3.9.3 fails to reconnect after network failures; it is fixed in 3.9.4 and later. Sessions die after a single reconnect failure instead of retrying. The fix is a client library upgrade.

Watch storms after the burst

Once sessions have expired and ephemeral nodes have vanished, watch notifications fire for every watcher of those nodes. If zk_packets_sent spikes while zk_packets_received stays flat, you are in the watch fan-out phase. The reconnection wave that follows can push zk_outstanding_requests to globalOutstandingLimit.

If the ensemble is destabilizing, you can temporarily block new connections at the firewall to let in-flight state settle, then gradually re-admit clients. Warning: this is disruptive. It drops all clients that are mid-reconnect and can extend the outage if done wrong. Use only as a last resort when the ensemble is already failing.

Prevention

  • Monitor zk_jvm_pause_time_ms p99. GC is the number-one trigger. Alert on p99 above one-third of minSessionTimeout.
  • Monitor zk_stale_sessions_expired directly. Alert on any non-zero rate outside maintenance. This catches a session storm before dependent services page.
  • Tune clientPortListenBacklog. Set it explicitly in zoo.cfg to a value appropriate to your fleet instead of relying on the default.
  • Use the 3.6+ percentile metrics. Avg/min/max latency are cumulative since server start and hide burst behavior. p99 and p999 catch the tail.
  • Validate client session timeouts. Virtualized environments (especially burstable VMs) with sub-10s timeouts are too aggressive. The negotiated range is [2*tickTime, 20*tickTime] by default, with minSessionTimeout and maxSessionTimeout overriding.
  • Track client library versions across the fleet. Regressions like the 3.9.3 reconnect bug survive silent rollout. Pinning and inventory prevent surprise session storms.
  • Separate dataLogDir from dataDir. A shared disk produces fsync spikes that trigger elections, which in turn produce session storms.

How Netdata helps

  • Per-second collection on zk_connection_drop_count, zk_stale_sessions_expired, and zk_num_alive_connections makes the shape of the burst visible. Minute-level scraping flattens a 20-second GC-driven burst into noise.
  • ML anomaly detection on zk_jvm_pause_time_ms surfaces GC pauses before they cross a fixed threshold, which matters because the right threshold depends on each ensemble’s minSessionTimeout.
  • Correlating zk_looking_count with zk_connection_drop_count on one timeline distinguishes election-caused storms from GC-caused storms without manual log hopping.
  • Composite alerts that gate zk_connection_drop_count on zk_uptime suppress false positives from rolling restarts and cold-start reconnection waves.
  • Side-by-side per-node dashboards let you distinguish a one-node GC problem from a fleet-wide network event at a glance.