Nagios network analyzer

Network Analyzer Software for Bandwidth Monitoring & NetFlow Analysis

Nagios Network Analyzer collects NetFlow, sFlow, jFlow, and IPFIX from the devices you already run, so you can see which Hosts and ports are taking the bandwidth. Extend with Suricata for signature-based intrusion detection, Nmap for discovery, and Wireshark for packet capture.

Free 30-day trial with the full feature set. Installs on your own server, on premises.

 

nagios network analyzer overview graphic

Trusted by 10K+ Teams Worldwide

Boeing JPMorgan Chase Airbnb Panasonic Cisco Bose Burlington Verizon Paypal
FLOW-LEVEL VISIBILITY

What an Up or Down check can't tell you

A Host check tells you an interface is reachable. Nagios Network Analyzer tells you what crossed it, what the packets contained, and what else is listening on the segment.

list collapse

Who is using the link

Every flow record carries the IP addresses and ports on both ends, so a bandwidth spike resolves to named endpoints rather than a busy interface.

scan search

What the traffic actually is

Break traffic down by protocol and port, then capture packets on an interface when the flow summary does not settle the question.

crosshair

What else is on the network

Scheduled Nmap scans record the Hosts and open ports on a segment, and an Ndiff shows what changed since the last scan.

network bandwidth monitoring

Bandwidth monitoring that names the device, not the interface

A Source is a collector: a name, a port to bind to, and its own store of flow data. Bandwidth is written every five minutes, and you can chart bandwidth usage per Source, per Source Group, or per Traffic Profile, broken down by address, port, and protocol.
Bandwidth usage by address and port

Rank the endpoints taking the link, then select a value to jump straight to the Queries tab with the filter already applied. Utilization resolves to a device, not an interface total.

WhoIs and reverse DNS in place

Resolve an unfamiliar address from the top talkers table without leaving the page.

Flow-level bandwidth

Splits the total by address, port, and protocol, which is what names the source of a spike. This is what Network Analyzer does.

Interface-level bandwidth

Reads a counter on the device for one total per interface. SNMP bandwidth monitoring in Nagios XI covers this if a per-interface total is all you need.

NetFlow Traffic Analysis

One Collector For Every Flow Protocol Your Network Exports

Nagios Network Analyzer is a NetFlow monitoring tool that collects NetFlow, sFlow, jFlow, and IPFIX on one server. Each Source binds to a port, writes flow data to its own directory, and holds it for a lifetime you set. Point routers, switches, firewalls, and Linux or Windows servers at that port and data starts arriving.

Saved Queries

Build a filter in Nfdump syntax, save it as a Source Query, and reload it instead of retyping it.

Traffic Profiles

Retain the exact historical flow data you need, from any source, for extended analysis.

Retention You Control

Granular flow files expire on the lifetime you set. Aggregated bandwidth history stays.

What Flow Collection Here Gets You Beyond a Raw Collector

You write queries in Nfdump syntax, so the filtering will be familiar if you have run a collector before. What Nagios Network Analyzer adds is everything around that query, and it is all in the base install, whether or not you add the packet capture and discovery tools.

Thresholds that alert

Bandwidth and saved queries compare against Warning and Critical thresholds every five minutes, then deliver to Nagios XI, Fusion or Nagios Core over NRDP, SNMP traps, email, Slack, or a custom command.

Retention you tier

A Source's data lifetime starts at 24 hours. Traffic Profiles extend retention for the subsets that matter instead of raising the lifetime, and the disk cost, for everything.

Access you delegate

Roles template access to Sources and Groups, then apply to new and existing users. Local accounts, or Active Directory and LDAP with SSL/TLS by default.

Path analysis

Network Path & Latency Analysis with Scheduled Traceroutes

Nagios Network Analyzer runs traceroutes that show every hop between an origin and a target with the latency at each one, which tells you whether the problem is local or several networks away.

Schedule them and compare recent runs in a dedicated dashlet, so you can watch a path degrade instead of hearing about it in a ticket.

SECURITY & NETWORK DISCOVERY

Inspect, Detect, & Discover with Wireshark, Suricata, & Nmap

Extend traffic and security analysis beyond flow data. The onboarding, integration, and interfaces for Nmap, Wireshark, and Suricata are built in, at one core and 2 GB RAM each.

Wireshark

Packet Capture & Inspection

A flow record says what and how much. A packet capture says exactly what was sent.

  • Capture on a chosen interface for a set duration, or import a pcap produced somewhere else
  • Inspect individual packets in summary, detailed, and raw JSON views
  • Every capture gets a summary page: interface, duration, packet and byte totals, a traffic over time chart, and top talker tables
  • Start a targeted capture from a Suricata alert, or send a capture to Suricata to be scanned
Wireshark Documentation
Suricata

Signature-based Intrusion Detection

Suricata compares traffic against signature rules and records every match as an alert.

  • Scan one or more interfaces using af-packet, or scan pcap files
  • Each alert carries a Signature ID, a category, and a severity
  • Over 26 commercial and open source rulesets ship pre-loaded, and you can import your own
  • The Overview tab carries scan status, weekly alert totals, a treemap of categories, and a severity breakdown, each drilling down to the matching alerts
  • Run WhoIs, reverse DNS, or an Nmap scan against an address in an event, edit portions of the Suricata YAML in the interface, and set how long alerts are retained
Suricata Documentation
Nmap

Network Discovery & Port Scanning

Flow data shows the devices that are talking. Nmap finds the ones that are listening.

  • Use the built-in scan Profiles for common settings, or create your own
  • Run scans on demand, and schedule recurring scans for continuing visibility
  • An Ndiff compares two scans and shows the Hosts and ports added or removed since last time
  • Scans record operating system information for discovered Hosts
  • Export results, clear old scans with retention, and send any address to WhoIs or search it against Suricata alerts
Nmap Documentation

Suricata reports traffic matching a signature rule you enabled. Nmap reports the ports and Hosts that answered a scan. Both produce findings for a person or an upstream check to act on.

ALERTING & NOTIFICATIONS

Threshold-based alerting on flow data, Suricata alerts, and Nmap scans

Nagios Network Analyzer runs checks every five minutes and compares each result against Warning and Critical thresholds you set, then sends the result as a passive check into Nagios XI or Nagios Core over NRDP.

Flow Source Checks

Threshold bandwidth or a saved query on a Source, Group, or Traffic Profile.

Suricata Checks

Alert on the presence of chosen Signature IDs over a lookback period you define.

Nmap Checks

Alert on the number of open or closed ports found by a scheduled scan.

System Checks

Watch the collector itself: CPU, memory, root drive usage, and job worker availability.

Where Results Go

  • Passive check results to Nagios XI, Nagios Fusion or Nagios Core over NRDP
  • SNMP Traps to a receiver using the Nagios MIB, on SNMP v2c or v3
  • Email to Network Analyzer users, with the local timestamp included
  • Slack, using an incoming webhook
  • A custom command, with check variables passed as arguments
Start Free Trial Request a Demo

Fully functional for 30 days. Installs on your own server.

DASHBOARDS & SCHEDULED REPORTS

Build once, schedule, & stop logging in to check

Reports that send themselves

Any dashboard downloads on demand or schedules out as a PDF or JPG. Configure delivery schedules and recipient lists, edit or toggle active reports on the fly, and review delivery history with retention you set.

Dashlets you arrange

Area, bar, line, pie, and radial charts plus data tables and a traceroute topology, covering bytes, flows, packets, bits per second, top talkers, and scheduled Nmap scan results.

Import, export, and clone

Move a dashboard between servers or clone one as the starting point for the next.

Connect with nagios xi

Running alongside Nagios XI

Nagios Network Analyzer runs as its own server. Link it to Nagios XI with an API key and the two work in both directions: XI polls Network Analyzer, and Network Analyzer answers back.

Active checks from Nagios XI

The Network Analyzer Wizard under Configure > Configuration Wizards builds the checks for you, so a Source or Source Group gets polled like any other Host.

Passive results into Nagios XI

Results arrive over NRDP as passive checks, so a saturated link shows up in the same queue as a dead disk, on the same dashboards and escalations.

Reports and Host detail

Network Report and Network Query Report join the XI Reports menu, and a Network Traffic Analysis tab lands on Host and Service detail, so the traffic answer is one click from the alert.

Deployment

Enterprise deployment, on premises, with access control per team

Nagios Network Analyzer installs on your own server, on premises. Template access per team with Roles, authenticate against Active Directory or LDAP, and size the server for what you actually install.

Requirement Specification
Operating systems RHEL, CentOS, and Oracle Linux 9 and 10. Debian 12 and 13. Ubuntu 24. Exact supported releases across every product are listed in the OS compatibility matrix.
Processor and memory The system requirements are 1 core and 2 GB RAM per integration as a minimum, 2 cores and 4 GB recommended. A base install collecting flow data counts as one. Wireshark, Suricata, and Nmap each add one.
Storage 128 GB free minimum, 1 TB recommended. Actual use tracks flow volume and the Raw Data Lifetime set on each Source, which the backend documentation explains.
Exporters Routers, switches, firewalls, and Linux or Windows servers configured to send flow data to a Source port.

Full documentation in the Nagios Network Analyzer Administrator Guide.

Roles and access control

A Role templates access to flow Sources and Groups, Traceroutes, Reports, Wireshark, Nmap, and Suricata, then applies to new and existing users. Admin and User ship pre-defined, and the User Role starts as a full-visibility, read-only account on a fresh install.

Authentication

Local accounts, or Active Directory and LDAP with SSL/TLS by default; a self-signed domain controller's CA certificate uploads to Network Analyzer for validation. An administrator can change a user's password, Role, or authentication method, and enable, disable, or delete accounts.

Item Details
Interfaces Web interface plus a REST API for querying check results and building custom integrations.
Licensing Each key covers three installs: production, test or lab, and a disaster recovery server held in non-operational mode. Keys are entered during license activation.
PRICING

Perpetual License Pricing

Nagios Network Analyzer is a perpetual license: you buy it once, and it does not renew or price by seat.

Your purchase includes the first year of Maintenance & Support, covering product updates, technical support with one-business-day response, and a dedicated Customer Success Manager.

Renewing after year one keeps updates and support active.

Nagios Network Analyzer License

$4,995

Monitor and analyze the health of your network.

  • Passive check results to Nagios XI or Nagios Core over NRDP
  • SNMP Traps to a receiver using the Nagios MIB, on SNMP v2c or v3
  • Email to Network Analyzer users, with the local timestamp included
  • A custom command, with check variables passed as arguments
Network Analyzer FAQ

Frequently Asked Questions

Can I install Network Analyzer for flow collection only?

Yes. Flow collection, bandwidth charts, top talkers, queries, dashboards, alerting, and reports are all part of the base install and run without Wireshark, Suricata, or Nmap. A server that skips those three stays at the base requirement of one core and 2 GB RAM, and you can add any of them later from the interface.

Why use Nagios Network Analyzer instead of a free flow collector?

Where the results go, mostly. A free collector can threshold and email, but the alert stays inside that tool. Network Analyzer delivers each result as a passive check into Nagios XI or Nagios Core over NRDP, so a traffic problem lands in the same queue as your Host and Service checks. SNMP traps, email, Slack, and custom commands are available too.

Breadth is the other half. One alerting config covers bandwidth and saved queries, Suricata Signature IDs, the open ports from a scheduled Nmap scan, and the collector's own CPU, memory, root drive usage, and job worker availability.

Queries themselves use nfdump syntax, so the filtering is comparable. The rest of the difference is the layer around it: retention you tier through Traffic Profiles, Role-based access with Active Directory and LDAP, scheduled PDF and JPG reports, and a documented upgrade path between releases.

What is a network analyzer?

Network devices can export a summary record for each conversation crossing an interface, covering the addresses and ports on both ends, the protocol, and the volume moved. A network analyzer collects those records, stores them, and turns them into bandwidth charts, top talker rankings, and queries you can filter. It reads what the network already reports rather than installing an agent on every Host.

What is bandwidth monitoring?

Bandwidth monitoring measures how much of a link's capacity is being used, over time, so you can tell a saturated circuit from a healthy one. Interface-level bandwidth monitoring reads a counter on the device and gives you a single total per interface. Flow-level bandwidth monitoring reads the exported records and splits that total by address, port, and protocol, which is what tells you where the traffic came from. Network Analyzer does the second. Nagios XI covers the first through SNMP bandwidth monitoring on Host and Service checks.

How do I monitor bandwidth usage per device?

Point an exporter at a Source, then open the Source Summary page. Top talkers ranks the addresses and ports moving the most data for the window you select, and selecting a value opens the Queries tab with that filter applied. WhoIs and reverse DNS resolve an unfamiliar address in place. Attribution is as granular as the records the exporter sends, so a device behind network address translation appears as the translated address.

Which flow protocols does Nagios Network Analyzer support?

NetFlow, sFlow, jFlow, and IPFIX. Most flow protocols are close enough to NetFlow to be treated the same way. sFlow is the exception, because it samples packets and derives the rest statistically, so set the flow type correctly when you create the Source.

What is the difference between flow data and packet capture?

A flow record summarizes a conversation: endpoints, ports, protocol, and volume. A packet capture keeps the packets themselves, including payload. Flow data is cheap enough to run continuously across every exporter and answers who and how much. Captures cost far more storage and are run against a specific interface for a set duration, and answer what was actually sent. Network Analyzer does both, so you can start from the flow record and capture only where you need the detail.

Do I need Nagios XI to run Nagios Network Analyzer?

Network Analyzer runs as its own server with its own interface, users, dashboards, alerting, and reports. Running it alongside Nagios XI adds the Network Analyzer Wizard, the Network Traffic Analysis tab on Host and Service detail pages, and two Network Analyzer reports in the XI Reports menu. Nagios XI covers the availability and performance side with Host and Service checks, including network device monitoring for interface state and device health.

Are Wireshark, Suricata, and Nmap included in the installation?

The onboarding, integration, and interfaces are built in. Each tool installs alongside Network Analyzer: open its section in the interface, run the install commands it supplies, then refresh the page to reach that tool's tabs. Size the server for what you install, since each integration raises the processor and memory minimum by one core and 2 GB RAM.

Does Nagios Network Analyzer detect security threats?

The Suricata integration matches traffic against signature rules from the rulesets you enable and records each match as an alert with a Signature ID, category, and severity. Nmap reports which ports and Hosts answered a scan, and an Ndiff shows what changed between two scans. These are rule matches and scan results your team acts on, and they reflect the rules and targets you configure.

How much disk space does flow data need?

It depends on your environment, and there is no single number that fits every install. Four things drive it: how many flow records per second your exporters send, the Raw Data Lifetime you set on each Source, how many Traffic Profiles you extend retention for, and whether Wireshark and Suricata are installed, since packet captures and Suricata alerts are stored separately from flow data.

The published guideline is 128 GB free as a minimum and 1 TB or more recommended. Granular flow files are removed once they pass a Source's data lifetime, which starts at 24 hours, while aggregated bandwidth history is kept separately, so long-term charts survive after the per-flow detail is gone. If you know roughly how many flows per second you expect, email [email protected] and we can size it with you.

Can I upgrade an existing Network Analyzer 2024 server to 2026?

Yes, and the migration guide covers it. The 2026 release moved the backend to Laravel, replaced RRDTool with InfluxDB for time series data, and rebuilt the interface, so read the migration steps first. Check the operating system as well, since support for RHEL 8, Oracle 8, Debian 11, and Ubuntu 20.04 LTS and 22.04 LTS ended with 2026R1. Once on 2026R1.2 or later, further updates apply from the Check for Updates page.

How long is the trial, and what does a license cover?

30 days with the full feature set. Every license key covers three installs: a production server, a test or lab server, and a backup server held in non-operational mode for disaster recovery. Email [email protected] for licensing detail.

Get Started

Take Full Control of Your Network Traffic Today

30-day full access to all capabilities with guided demonstration of integrated network analysis features.

Download Nagios Network Analyzer