For an open source network monitoring tool, the first results are ntop/ntopng, zabbix/zabbix (Zabbix is a full-featured enterprise-grade network monitoring platform with built-in SNMP, auto-discovery, real-time alerts and dashboards, flow analysis support, and distributed proxy architecture—exactly the kind of comprehensive open-source tool this search describes) and tianshiyeben/wgcloud (wgcloud is a monitoring platform that tracks network devices, servers, and containers with SNMP, real-time metrics, dashboards, and network topology visualization, aligning well with the query, though it lacks explicit flow analysis and distributed monitoring features). librenms/librenms and checkmk/checkmk round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
We curate open-source GitHub repositories matching “open-source network monitoring tools”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an
ntopng is a web-based network traffic monitoring tool with built-in SNMP management, real-time metrics, flow analysis (NetFlow/sFlow), and dashboards, along with topology discovery and scalable collector hierarchies, making it a comprehensive fit for network infrastructure monitoring.
Zabbix is an enterprise-grade open-source platform for monitoring IT infrastructure, networks, and applications. It provides real-time metrics, alerts, and dashboards, enabling organizations to track performance and availability across their entire technology stack. The platform collects metrics from virtually any source, including agents, agentless protocols, APIs, containers, databases, and cloud platforms, without requiring custom scripting. It automatically discovers IT resources by scanning network ranges and cloud environments, then applies pre-built templates for immediate monitoring.
Zabbix is a full-featured enterprise-grade network monitoring platform with built-in SNMP, auto-discovery, real-time alerts and dashboards, flow analysis support, and distributed proxy architecture—exactly the kind of comprehensive open-source tool this search describes.
wgcloud is a comprehensive suite of monitoring and management tools designed for Linux servers, network devices, containers, and middleware. It functions as a centralized dashboard for tracking real-time hardware metrics, auditing the health of Docker and Kubernetes environments, and maintaining an IT asset management system for physical and cloud infrastructure. The platform is distinguished by its integrated remote administration capabilities, featuring a web-based SSH client for executing bulk commands and managing servers directly from a browser. It further differentiates itself with AI-d
wgcloud is a monitoring platform that tracks network devices, servers, and containers with SNMP, real-time metrics, dashboards, and network topology visualization, aligning well with the query, though it lacks explicit flow analysis and distributed monitoring features.
LibreNMS is an SNMP network monitoring system and IT infrastructure management suite. It serves as an automated network discovery tool and infrastructure dashboard, enabling the identification and monitoring of network hardware and operating systems. The system differentiates itself through a rule-based alerting engine and a comprehensive IT incident workflow integration. It supports complex alert routing, including escalation sequences and direct ticket generation for project management and service desk platforms. Its observability capabilities cover multi-vendor hardware oversight, applica
LibreNMS is a full-featured network monitoring system that handles SNMP discovery, alerting, live dashboards, and flow analysis, making it a direct and comprehensive fit for infrastructure and traffic monitoring.
Checkmk - Best-in-class infrastructure & application monitoring
Checkmk is a comprehensive open-source monitoring platform that covers SNMP, real-time metrics, dashboards, auto-discovery, flow analysis, and distributed setups, making it a strong fit for network infrastructure monitoring.
WatchYourLAN is a self-hosted network discovery and monitoring tool written in Go. It scans local network interfaces using ARP requests to detect connected devices, tracks their online and offline status over time, and identifies when new or previously unseen hosts appear on the network. The application stores host data and connection history in either SQLite or PostgreSQL, and can export metrics to InfluxDB or expose a Prometheus endpoint for long-term storage and visualization in dashboards like Grafana. The tool provides a REST API for programmatic management of monitored hosts, including
WatchYourLAN is a self-hosted network discovery and monitoring tool that tracks device presence on a local network via ARP scanning, stores history, and exports metrics to Prometheus/InfluxDB — this is a genuine but narrower network monitoring tool, focused on LAN device visibility rather than full SNMP, flow analysis, or distributed monitoring.
The core of our monitoring platform with a powerful configuration language and REST API.
Icinga2 is a mature network monitoring platform that supports SNMP, real-time alerts, and dashboards (via Icinga Web 2), and can be scaled for distributed monitoring, though built-in network topology discovery and flow analysis may require additional plugins.
Main repository for munin master / node / plugins
Munin is a mature distributed monitoring tool with a master/node architecture, SNMP support via plugins, and historical graphing dashboards, making it a genuine network monitoring solution, though it focuses on periodic polling rather than real-time streaming and lacks native flow analysis.
Cacti ™
Cacti is a classic open-source network monitoring tool that uses SNMP to collect and graph device metrics, but it lacks built-in flow analysis, auto-discovery, and native distributed monitoring, so it covers some but not all of the requested features.
This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
Sniffnet is a desktop packet analyzer for real-time traffic capture and bandwidth tracking, but it focuses on local packet inspection rather than device‑level SNMP monitoring, auto‑discovery, flow analysis, or distributed infrastructure monitoring.
Pinpoint is a distributed application performance monitoring and tracing system. It functions as an application performance monitor and topology visualizer designed to analyze the execution behavior of large-scale distributed applications. The system uses bytecode instrumentation to monitor applications without requiring changes to the original source code. It captures call stacks and request flows across interconnected services to visualize system dependencies and generate real-time architectural maps of communication patterns. The platform covers a broad range of observability capabilities
Pinpoint monitors application performance and service dependencies in distributed systems, but it does not monitor network infrastructure devices, traffic, or support SNMP and flow analysis—it is an APM tool rather than a network monitoring tool.
gping is a terminal-based network latency grapher and performance monitor. It functions as a cross-platform ping client that visualizes ICMP response times as real-time line graphs directly within the command line. The tool distinguishes itself by operating as a command execution time plotter, allowing the duration of any shell command to be graphed over time to analyze performance fluctuations. It supports multi-host latency plotting and provides shorthand identifiers for monitoring connectivity across different cloud infrastructure regions. The utility covers network diagnostics and observ
gping is a command-line tool for graphing ping latencies and command execution times, but it is a focused diagnostic utility rather than a full network monitoring platform with SNMP, flow analysis, topology discovery, or distributed monitoring.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| ntop/ntopng | 7.9K | Lua | GPL-3.0 | |
| zabbix/zabbix | 5.7K | Go Template | agpl-3.0 | |
| tianshiyeben/wgcloud |
| 5.1K |
| Java |
| Apache-2.0 |
| librenms/librenms | 4.8K | PHP | NOASSERTION |
| checkmk/checkmk | 2.3K | Python | GPL-2.0 |
| aceberg/watchyourlan | 7K | Go | MIT |
| icinga/icinga2 | 2.2K | C++ | GPL-3.0 |
| munin-monitoring/munin | 2.1K | Perl | NOASSERTION |
| cacti/cacti | 1.8K | PHP | GPL-2.0 |
| gyulyvgc/sniffnet | 39.3K | Rust | Apache-2.0 |