Network clarity.
Operational confidence.
On-premise, agentless network monitoring and management for multi-vendor enterprise networks. Discover devices, monitor health, understand topology, centralize alarms, analyze flows and logs, and protect configurations from one platform.
Polling + traps + flows
SNMP, ICMP, traps, NetFlow/IPFIX/sFlow, syslog and topology in one NMS.
On-premise by design
Telemetry stays on customer servers and the product is agentless on network devices.
One operating view
Bring monitoring, alarms, topology, logs and flow telemetry into one shared workspace.
Grafana analytics
Use provisioned dashboards for application health, syslog, NetFlow and alarms.
Where ArkayNMS fits
Strong fit
ArkayNMS is a strong match for on-premise, multi-vendor estates where network devices, links and services must be monitored together. It gives network teams one place to work with SNMP, traps, NetFlow, syslog and topology instead of switching between separate tools during an incident.
Good renewal trigger
It is especially useful when operators are spending too much time correlating data manually or navigating fragmented tools. Teams can use one shared operational view to move from a health alert to device context, topology, logs and flow evidence more quickly.
Not a forced fit
ArkayNMS is designed first for network operations, not as a replacement for every observability or service-management product. SaaS-only monitoring, Kubernetes-only environments, very small estates without a clear operational need, or teams seeking a complete ITSM/ITOM suite may be better served by another starting point.
How ArkayNMS works
Connect your engineering environment, monitor the work, turn signals into incidents, and use operational data to act faster.
Connect
Discover and register devices, sites, vendors and device types. Use SNMP v1, v2c or v3.
Monitor
Collect parameters, reachability, traps, flow telemetry and syslog with reusable templates and rules.
Understand & act
Combine alarms, topology, Grafana analytics and configuration history into a single operating picture.
Architecture
• Collection & services: Web and API services provide the monitoring interface while SNMP parameters, traps, syslog, flow telemetry and ping gather network signals.• Operations, data & analytics: Alarms, topology and configuration backup are supported by Postgres, Kafka, ClickHouse, Prometheus, Grafana and Alertmanager, giving teams a connected path from collection to investigation.
Deployment
Choose the appliance that matches the processor architecture of the machine that will run it; AMD64 and ARM64 use different image formats and different installation paths.
Import the OVA appliance
- In a compatible x86_64 hypervisor, choose Import appliance (or the equivalent OVA option).
- Review virtual hardware and network settings, then complete the import and start the VM.
Attach the QCOW2 boot disk
- Typical size is about 10–13 GB.
- Create an ARM64 VM with UEFI firmware, then attach the file as its primary boot disk.
- Allocate 4 vCPUs and 16 GB RAM where possible (8 GB minimum).
ARM64 platform options
Linux: KVM / QEMU
Use KVM/QEMU or virt-manager. Create an ARM64 VM, select the QCOW2 file as the existing disk image, and boot with UEFI firmware.
macOS: UTM
Create a new VM, choose Virtualize → Linux, skip the boot ISO, import the existing drive, select ARM64, then assign memory and CPUs.
Windows on ARM / cloud
On Windows ARM, convert QCOW2 to dynamic VHDX before creating a Generation 2 VM. For AWS Graviton, import the image as an AMI or convert it to raw before attaching it.
First boot and access
Bring the appliance online
- Start the VM and allow 5–15 minutes for the Docker containers to initialize.
- Find the VM IP address from your hypervisor DHCP leases or by running
ip ainside the guest. - Open
http://<VM-IP>/in your browser.
Sign in, verify and secure
- Sign in to the NMS web UI using
admin / admin. - Confirm the UI responds before relying on container health indicators on slow emulators.
- Change all default passwords after first sign-in, then confirm the core monitoring services are healthy.
Discovery & Inventory
Organize devices by site, region, branch or customer; scan subnets with SNMP; and register devices individually or in bulk.
SNMP auto-discovery
Scan IP ranges and subnets with SNMP v1/v2c/v3, identify reachable devices and register them into inventory.
Central inventory
Track IP, vendor, model, device type, credentials, site, polling intervals and status.
MIB import
Upload vendor MIB files or CSV OID definitions and use them for polling and trap definitions without code changes or restarts.
Device workspace
| Workspace | Purpose |
|---|---|
| Device Summary | High-level health and identity overview. |
| Switch Details | Port status, bandwidth, stack health and performance for switch device types. |
| WLC Details | Wireless LAN controller parameter views. |
| Configure Params | Attach parameter groups, set intervals and enable or disable monitoring. |
| Configure Traps | Attach trap processor groups to devices. |
| View Params | View live and historical polled values and download monitoring data. |
| Config Backup | Capture, compare and restore saved device configuration snapshots. |
Features
Monitoring, visibility, alerting, topology, configuration protection and reporting work together in the same platform, so operators can investigate issues without jumping between disconnected tools.
Monitoring overview
ArkayNMS combines scheduled SNMP parameters, ICMP reachability, traps, flow telemetry, syslog and application-path testing into one operating picture.
SNMP monitoring
Reusable parameter groups hold scalar and table OIDs; groups can be attached per device, scheduled at chosen intervals, and used to create threshold alarms.
| Capability | What it does |
|---|---|
| Parameter groups | Reusable global OID groups; import/export as JSON. |
| Per-device monitoring | Attach groups to devices and set intervals per device. |
| Threshold alarms | Raise severity-based alarms when configured conditions are breached. |
| Parameter history | View live and historical polled values; download monitoring data. |
| SNMPv3 | Use authentication and privacy security levels for secure access. |
SNMP traps
Receive, decode and enrich traps, persist the history, acknowledge trap-driven alarms and optionally forward traps to multiple destinations.
Flow telemetry
Collect NetFlow v5/v9, IPFIX and sFlow v5 records, then turn traffic into useful views such as top talkers, protocols and exporter health.
Syslog
Receive syslog, analyze volume and severity, and turn matching patterns into unified alarms.
Topology
ArkayNMS computes an interactive L2/L3 map using LLDP as primary discovery, CDP as fallback and FDB as a last resort. Layouts include ring, force-directed, hierarchy and grid.
Automatic
Shows verified discovery only—best for understanding what the latest evidence confirms today.
Semi-automatic
The default view: retain verified discovery while adding, replacing, or hiding links when operators need a correction.
Fully manual
Shows only user-defined links—ideal for planned diagrams, greenfield sites, or CSV-driven documentation.
Work with the map
Find and investigate
- Search by device name or IP, then highlight one-hop neighbours.
- Double-click a device to open its details; press Escape to clear a focused view.
- Use Tools to focus one to three hops or highlight the path between two devices.
Adapt the view
- Pan, zoom, fit, or use Immersive view for a larger canvas.
- Toggle labels, link capacity, and live link traffic where available.
- Save node positions independently for each site and map view.
Device health is refreshed from SNMP sysUpTime with ICMP ping fallback. Cross-site links can be shown as site stubs or full remote devices, and CSV export supports discovery reports and manual-link records.
Route Insights
See the actual network path from a site to a specific application or service. Compare the same destination across sites and quickly identify where latency, loss or degradation begins.
Application path visibility
Understand the route to the service instead of looking only at endpoint health.
Site comparison
Compare healthy and affected sites against the same application endpoint.
Faster troubleshooting
Use path-level evidence to focus investigation on the area of the network that is actually degrading.
Alerts & incidents
Unified alarms cover SNMP parameters, traps, ping, syslog rules, NetFlow rules and configuration-backup events. Active and historical views are separated, with real-time WebSocket updates.
Configuration backup
Capture
Scheduled and on-demand running-config capture over SSH or Telnet.
Compare
Snapshot history with a configuration diff viewer and golden-baseline drift detection.
Restore
Apply a saved configuration back to a device when recovery requires it.
Dashboards & reporting
Dashboards give operators an immediate view of fleet and per-site health, helping them spot devices, links or services that need attention before users report an issue. When an alert needs investigation, Grafana provides deeper views across application health, syslog, NetFlow and alarms so teams can compare signals in context. Operational and inventory reports can be exported to PDF or Excel for handovers, reviews and stakeholder updates.
Users, security and access
| Capability | Details |
|---|---|
| Local authentication | Username/password login with JWT. |
| Keycloak SSO / OIDC | Enterprise single sign-on via Keycloak. |
| Users & roles | User management, password reset and role assignment. |
| RBAC | Fine-grained view/add/update/delete privileges across modules. |
| Site-scoped users | Restrict operators to assigned sites. |
| Data residency | Telemetry stays on customer servers. |
Settings
Administration covers parameter groups and trap processor groups, notification providers, trap-forwarding destinations, retention TTLs, web alarm media, and NCB credentials/vendor collectors.
API Usage
REST API
ArkayNMS exposes a broad REST API surface with OpenAPI documentation. Use the API for path and neighbor queries, operational integrations and programmatic access to platform capabilities.