Network monitoring is the continuous checking of routers, switches, firewalls, servers, wireless access points and links to confirm they are up, performing well and carrying the traffic you expect. A monitoring system polls devices (usually over SNMP), collects flow records (NetFlow, sFlow or IPFIX) that show who is talking to whom, optionally captures packets for deep troubleshooting, and runs synthetic tests that measure latency and loss between sites. When a metric crosses a threshold, it alerts someone before users notice.
This guide explains how network monitoring works, the four data sources behind it, the metrics worth tracking, how alerting should be set up, and what it costs in 2026. If you already know the basics and want to compare products, go straight to our guide to the best network monitoring software.
What is meant by network monitoring?
In practice, “network monitoring” covers three jobs that most tools now bundle together:
- Availability monitoring: is each device and interface reachable and up? This is the classic ping and SNMP status check, and it answers “is something down?”
- Performance monitoring: how well is the network working? Bandwidth utilisation, latency, jitter, packet loss, interface errors, CPU and memory on network gear.
- Traffic analysis: what is using the network? Which applications, hosts and conversations consume bandwidth, and is any of it unexpected?
Network monitoring is related to, but narrower than, observability platforms that also watch applications, logs and cloud services. It is also different from network management, which adds configuration backup, change control and provisioning. Many products (ManageEngine OpManager, SolarWinds, Auvik) sell both in one suite.
How does network monitoring work?
A monitoring platform has three moving parts. First, discovery: it scans IP ranges and reads neighbour tables (CDP, LLDP, ARP) to build an inventory and often a topology map. Second, collection: pollers, collectors or lightweight agents gather metrics on a schedule (every 1 to 5 minutes is common for SNMP) and receive pushed data such as SNMP traps, syslog and flow exports. Third, analysis and alerting: the platform stores time-series data, compares it with thresholds or baselines, draws dashboards and notifies the on-call engineer.
Where the collector lives matters. Self-hosted tools such as Zabbix, Nagios, Checkmk and PRTG run on a server you maintain. Cloud tools such as Auvik, Domotz, Datadog and LogicMonitor put a small collector on site and send data to the vendor’s SaaS. Distributed and multi-site networks usually need one collector per site either way.
What are the main network monitoring methods?
Four data sources do almost all of the work. Each answers a different question, and most teams combine at least two.
| Method | What it tells you | Typical granularity | Cost to run |
|---|---|---|---|
| SNMP polling and traps | Device health, interface status, bandwidth counters | Per interface, every 1 to 5 minutes | Low |
| Flow data (NetFlow, sFlow, IPFIX) | Who talked to whom, on which port, how much | Per conversation, aggregated | Medium (storage) |
| Packet capture | Every byte of every packet | Per packet | High (storage, privacy) |
| Synthetic monitoring | Latency, jitter, loss and path between two points | Per test, every few seconds to minutes | Low to medium |
SNMP (Simple Network Management Protocol)
SNMP is the backbone of device monitoring. A monitoring server (the manager) polls an agent built into the router, switch, printer or UPS on UDP port 161 and reads values such as interface octet counters, CPU load and fan status from the device’s MIB. Devices can also push unsolicited alerts, called traps, to the manager on UDP port 162. Three versions are in use: v1 and v2c authenticate with a plain-text “community string”, while v3 adds user-based authentication and encryption. If you are choosing a tool mainly for SNMP, see our comparison of SNMP monitoring tools.
Flow monitoring: NetFlow, sFlow and IPFIX
SNMP tells you a link is 90% full. Flow data tells you why. Routers and firewalls summarise each conversation (source and destination IP, ports, protocol, byte and packet counts) and export those records to a collector. NetFlow is Cisco’s format (version 9 is documented in RFC 3954); IPFIX is the IETF standard built on it (RFC 7011); sFlow takes a statistical sample of packets, which suits high-speed switches. Flow analysis is how you find the backup job, streaming session or compromised host eating your bandwidth. Our guide to network traffic monitoring tools covers the flow analysers in detail.
Packet capture
Packet capture records the actual packets crossing an interface, via a SPAN/mirror port or a network TAP. It is the most detailed evidence you can get, and the most expensive to keep: full captures fill disks fast and can contain sensitive payloads. Most teams capture on demand with Wireshark or tcpdump when a flow or SNMP alert points to a specific problem, and reserve always-on capture for security tooling.
Synthetic monitoring
Synthetic (or active) monitoring sends test traffic between agents, or from an agent to a SaaS endpoint, and measures what comes back. It catches problems that device metrics miss: a congested ISP hop, a slow VPN path or a degraded link to Microsoft 365, even when every device you own reports “healthy”. Obkio, Datadog Network Path and ThousandEyes-style tools are built around this approach.
Which network metrics should you monitor?
Start with a small set you will actually act on. These cover most outages and complaints:
| Metric | Why it matters | Where it comes from |
|---|---|---|
| Availability (up/down) | The first question in every incident | ICMP ping, SNMP ifOperStatus |
| Bandwidth utilisation | Saturated links cause slowness and drops | SNMP interface counters |
| Latency | Voice, video and SaaS apps degrade as it rises | Ping, synthetic tests |
| Jitter | Variation in delay breaks VoIP and video calls | Synthetic tests |
| Packet loss | Even 1 to 2% causes retransmits and choppy calls | Ping, synthetic tests |
| Interface errors and discards | Point to bad cables, duplex mismatches, full buffers | SNMP error counters |
| Device CPU, memory, temperature | Overloaded gear drops traffic before it fails | SNMP, vendor APIs |
| Top talkers and applications | Explain why a link is full | NetFlow, sFlow, IPFIX |
One practical detail: on fast links, use 64-bit interface counters (ifHCInOctets and ifHCOutOctets, available from SNMPv2c onward). The older 32-bit counters wrap too quickly on 1 Gbps and faster interfaces and produce false utilisation spikes.
How should network monitoring alerts be set up?
Alert fatigue kills monitoring projects faster than any missing feature. A few rules keep alerts useful:
- Alert on symptoms users feel (a site down, a WAN link above 90% for 10 minutes, loss above 2%), and send everything else to a dashboard.
- Use dependencies. If the core switch is down, suppress the 40 alerts for devices behind it. Most mature tools (PRTG, Zabbix, Nagios, Checkmk, OpManager) support parent/child dependencies.
- Require duration, not a single sample. “Above threshold for 3 consecutive polls” removes most noise.
- Route by severity. Page for outages, open a ticket for warnings, email a weekly report for capacity trends.
- Review monthly. Any alert nobody acted on should be tuned or deleted.
Which tool is used for network monitoring?
There is no single standard tool. Choices fall into four groups:
- Self-hosted suites: PRTG, SolarWinds NPM, ManageEngine OpManager and WhatsUp Gold. Mature, broad device support, you run the server.
- Open source: Zabbix, Nagios Core, Checkmk, LibreNMS and OpenNMS. No licence fee, more engineering time.
- Cloud-managed: Auvik, Domotz, LogicMonitor and Datadog. Fast to deploy, priced per device, site or host.
- Point tools: Wireshark for packet analysis, ntopng for traffic, Obkio for synthetic performance testing.
Our best network monitoring software guide compares 13 of them with vendor-published pricing, and the network monitoring software category lists more.
Does Windows have a network monitoring tool?
Windows includes basic tools, but nothing that monitors a whole network. Task Manager and Resource Monitor show per-process network use on one PC, Performance Monitor can chart interface counters, and Packet Monitor (pktmon), a command-line capture tool built into recent versions of Windows 10, Windows 11 and Windows Server, records traffic on that machine and exports pcapng files that open in Wireshark. Microsoft Network Monitor 3.4 is archived and no longer developed, and Microsoft Message Analyzer was retired on November 25, 2019; Microsoft states there is no Microsoft replacement for Message Analyzer and points users to Wireshark.
How much does network monitoring cost?
Pricing models vary more than the features do. These are vendor-published figures, checked September 2026:
| Pricing model | Example | Published price |
|---|---|---|
| Open source | Zabbix, Nagios Core, LibreNMS | $0 licence; you pay for the server and staff time |
| Freemium | PRTG Freeware | Free up to 100 sensors (about 10 devices) |
| Per sensor, subscription | PRTG 500 | $200 per month, paid annually, up to 500 sensors |
| Per device | Datadog Network Device Monitoring | $7 per device per month, billed annually |
| Per site | Domotz (IT teams) | $35 per location per month |
| Per agent | Obkio Starter | From $249 per month with 5 agents |
| Quote-only | Auvik, LogicMonitor, NinjaOne | Not published |
For a small office of 10 to 50 devices, a free tier or open-source tool is often enough. Once you have multiple sites, an MSP client base or a compliance requirement for audit trails, paid tools earn their cost through faster setup, maintained device templates and support.
How to tell if someone is monitoring your network?
On a business network, assume it is monitored: IT teams collect SNMP, flow and firewall logs as routine, and most acceptable-use policies say so. Signs of unauthorised monitoring are different: unknown devices on the network, a switch port set to mirror traffic without a change record, unexpected SNMP community strings or new flow export destinations in router configs, and unfamiliar root certificates on endpoints (a sign of TLS interception). An inventory scan and a configuration diff against your last known-good backup will surface most of these. A current network diagram makes rogue devices much easier to spot.
How to start monitoring your network in five steps
- Inventory and map. List devices, links and sites. If you need a refresher on layouts, see network topology basics.
- Enable SNMPv3 on routers, switches, firewalls and UPS units, with a read-only user for the monitoring server.
- Export flows from your internet edge and WAN routers to a collector.
- Add synthetic tests between sites and to the SaaS apps your business depends on.
- Set a handful of alerts, then expand once the team trusts them.
Frequently asked questions
What is network monitoring in simple terms?
It is software that watches your network devices and links around the clock, records how they perform, and tells you when something breaks or slows down.
What are the three main types of monitoring?
For networks, the usual split is availability monitoring (is it up?), performance monitoring (how well is it working?) and traffic analysis (what is using it?). Broader IT teams sometimes list infrastructure, application and security monitoring instead.
Is network monitoring the same as network security monitoring?
No. Network monitoring focuses on uptime and performance. Security monitoring (IDS, NDR, SIEM) looks for attacks and policy violations. They share data sources such as flow records and packet captures, so many teams feed the same collectors into both.
What is the difference between SNMP and NetFlow?
SNMP reports device and interface counters, so it shows how busy a link is. NetFlow reports conversations, so it shows which hosts and applications are making it busy. Most tools use both.
Can I monitor my network for free?
Yes. Zabbix, Nagios Core, LibreNMS and Checkmk’s community edition are free and open source, and PRTG’s freeware edition covers up to 100 sensors. You trade licence cost for setup and maintenance time.
How often should network devices be polled?
Every 1 to 5 minutes suits most SNMP metrics. Critical WAN links and latency tests can run every 30 to 60 seconds; capacity trends are fine at 5 minutes.
What replaced Microsoft Network Monitor?
Nothing officially. Network Monitor 3.4 is archived, and Message Analyzer was retired in November 2019 with no Microsoft replacement. In practice, admins use the built-in Packet Monitor (pktmon) for quick captures and Wireshark for full protocol analysis.
Compare alternatives to the tools in this post

- Independent picks for exactly what you just read about
- Matched to your team size & needs
- Vendors don't pay for placement
Step 1 of 4
How big is your team?
We tailor recommendations to companies your size.
Related Articles
IT Management
Microsoft Intune Pricing 2026: Plan 1, Plan 2, Suite and What Microsoft 365 Includes
Continue reading →
IT Management
Best Remote Access Software 2026: 11 Tools Compared by Price
Continue reading →
IT Management
Splashtop Pricing 2026: Solo, Pro, Performance and SOS Costs
Continue reading →
IT Management
Atera Pricing 2026: Every Plan, Per-Technician Cost and What You’ll Pay
Continue reading →





