Network observability · self-hosted · MCP-native
NitroNet collects flow, packets, SNMP, syslog and OpenTelemetry onto one box you own, resolves every address through built-in IPAM, maps the topology and keeps device configs under version control. Your engineers get the dashboards. Your agents get all seventeen MCP tools over exactly the same data.
Free tier, no per-device fees, no sales call. One host, one command, about ten minutes.
The 13:58 config push dropped the egress policer. Dallas backup traffic saturated the link four minutes later and starved ERP.
What you get on day one
NitroNet is a React front end over a Node backend, and it is the thing your team lives in. Flow analytics, device and interface health, TCP performance, topology, synthetics, syslog, IPAM, config history and incidents — all reading from one store, on one clock, with one address space. The agents came later. The platform came first.
Who talked to whom, over what, for how long — filtered by site, subnet, application, ASN or country, and drillable from a chart down to the individual conversation.
NetFlow · IPFIX · sFlow · VPCSNMP health, utilisation, errors and discards per interface, with baselines rather than fixed thresholds, so the alert fires when the line moves and not when it crosses 80%.
v1–v3 · vendor-aware · AES-256-GCMThe packet probe turns a SPAN into flow records carrying round-trip time, retransmits, window stalls and microbursts, so “the network is slow” becomes a measurement.
RTT · retransmits · SNI via TLS/QUICLLDP-derived maps with role-based layout. Click a link and you are looking at the flows crossing it, not a separate tool with a separate login.
LLDP · L2/L3 · link drill-downThe same probe binary runs as a test agent: ICMP, DNS and HTTP checks with traceroute path capture from wherever you place it, so you see the hop that changed.
icmp · dns · http · traceroutePrefix assignment, RFC1918 handling, CSV and REST import — and because it lives inside the platform, every flow record, alert, topology edge and agent answer is already labelled “Dallas backup VLAN” rather than 10.14.88.0/22.
subnet · site · ownerCollect and push device configuration with built-in Ansible playbooks, keep every version, and see each change land on the incident timeline next to the traffic it affected.
collect · diff · push · rollbackSignals become one scored incident with its evidence attached, routed to Slack, Teams, ServiceNow or a webhook — plus scheduled, customer-ready reports for the people who never log in.
dedupe · score · evidence · exportThe data plane
Most shops run four tools that each see a slice and none of which agree on what time it is. NitroNet lands everything in the same place, so a flow record, an interface counter, a syslog line and a config change can be read side by side — by a person or by an agent.
MCP-native, not MCP-adjacent
Everything the UI can render, the API can return and an agent can call. NitroNet ships a full Model Context Protocol server alongside the REST API, so the platform is not only a place your team logs into — it is a capability your agents already have. Point Claude Desktop or Claude Code at it, wire it into your own orchestration, or let it back a runbook. Same tools, same data, same permissions.
// claude_desktop_config.json { "mcpServers": { "nitronet": { "url": "https://nitronet.internal/mcp", "headers": { "Authorization": "Bearer <token>" } } } }
Then ask it something you would otherwise open four tabs for: which change caused the egress spike on wan1-edge this afternoon?
OTLP in, MCP and REST out. Self-hosted should mean you own your telemetry, not that it is stuck in someone else’s box — including ours. Everything the MCP server exposes is available over the REST API too, so if you would rather build against it directly, nothing is hidden behind the agent.
Run Claude for reasoning quality, or point the platform at Ollama on-premises when prompt context cannot leave the building. The tools are identical either way; the model is a setting, not an architecture.
What the agents do with it
An agent is only as good as what it can see, which is why the platform came first. Because the answers are queries against your store rather than inferences about a dashboard, every conclusion traces back to a tool call you can re-run yourself.
Signals from flow, SNMP, syslog, config, topology and IPAM assemble into one incident with a stated cause and a confidence score. Duplicates collapse instead of paging you five times.
Baseline deviation catches the slow ones — memory leaks trending toward an OOM, interfaces drifting toward saturation — while there is still time to schedule the fix.
Findings are computed deterministically first; the model writes the explanation over the top. Every number in an answer came from a query, never from the model.
Agents propose; you approve. Actions route through ServiceNow or Teams for sign-off, and every step stays on the audit trail.
Why self-hosted
SaaS observability means every flow record, every device name and every topology edge lives in someone else’s account, priced by the device, renewed on their terms. For a bank, a utility or a defence supplier, that is not a pricing objection — it is a non-starter.
Run it on your own ironFrom nothing to first flows
There is no trial clock, no device count to declare and no procurement conversation. Install it on a spare VM this afternoon and decide for yourself.
One host with 8 vCPU, 16 GB of RAM and Docker. Paste the command, wait about ten minutes, log into the UI.
Aim your flow exporters and syslog at the collector, add SNMP credentials, import your subnets from CSV. Traffic starts charting immediately.
Add the MCP endpoint to Claude Desktop, Claude Code or your own orchestration, and start asking questions of the data you just collected.
Straight answers
Free tier · no credit card · no sales call
Give it 8 vCPU, 16 GB of RAM and an Ubuntu 22.04 host with Docker. Point your exporters at it and watch the first flows land.
curl -fsSL https://nitronet.ai/download/s/<your-token>.sh | sudo bash
Tell us where to send your token and the command arrives ready to paste.
Get my install commandRather look first? Read the quickstart or book a walkthrough.