Skip to content
Features

One platform for the whole stack

spane collects from servers and network devices natively, then runs a single alerting, logging, and compliance layer over both. Here is what it actually does.


Agent monitoring

Server monitoring, by agent

A single static binary (the Linux core build is stdlib-only) enrolls with a one-time token, receives a unique client certificate, and pushes metrics over mutual TLS. It opens no inbound ports.

System metrics

CPU, memory, disk, and network — collected per-core, per-mount, and per-interface, on a default 30-second interval.

Service & process collection

Optional running-process and service-state collection via systemd / Windows SCM.

Role-based health

Functional checks for DNS, DHCP, NPS, Domain Controller, Web, Database, File, and Syslog roles — not just “is it up,” but “is it doing its job.”

Unified inventory

Agent metrics land in the same InfluxDB measurements as SNMP/REST collection, so servers appear on the Servers page with full drill-down.

Cross-platform

Linux amd64 / arm64 and Windows amd64, each a hardened low-privilege system service.


Agentless monitoring

Network device monitoring

Discover and enrich devices across four tiers, then poll them over SNMP and SSH — with streaming telemetry where the platform supports it.

SNMP polling

SNMP v3 (recommended) or v2c, with ~1,800 vendor + standard MIBs for OID resolution and REST API enrichment (e.g. AOS-CX).

Reachability & latency

Ping/ICMP reachability with round-trip-time (RTT) latency monitoring and alerting.

Interface & environment

Interface utilization and statistics, plus environment telemetry — temperature, fans, PSU — and PoE budget tracking with alerts.

Streaming telemetry

gRPC/gNMI and Cisco MDT streaming telemetry on supported platforms, with SNMP polling as the fallback.

Discovery & enrichment

Four-tier discovery, LLDP/CDP topology mapping, ARP/MAC table collection with OUI lookup, and manual topology links for LLDP-less devices.


Traffic visibility

Flow analytics

See what is actually traversing the network, not just interface counters.

NetFlow & sFlow

NetFlow v5/v9/IPFIX on UDP 2055 and sFlow on UDP 6343, ingested and indexed for query.

DNS enrichment

Optional DNS hostname enrichment turns flow endpoints into readable names.

Flow alerting

Flow-threshold alerts feed the same unified alerting engine.

WAN & circuits

WAN circuit tracking — provider/contract/cost, bandwidth, 95th-percentile trending, and contract-expiry alerts.


One engine

Unified alerting

Servers and network gear share a single alerting pipeline — no second tool to reconcile.

Team routing & escalation

Route alerts to teams with escalation policies, so the right person is paged.

Maintenance windows

Suppress expected noise during planned work with maintenance windows.

Channels

Email, Slack, and Discord delivery, plus bulk alert actions for triage at scale.

Custom thresholds

Custom alerts over InfluxDB metrics for both agent and SNMP-sourced data.


Central logs

Log forwarding & central logs

Device syslog and forwarded server logs converge in one searchable store on OpenSearch.

Syslog receiver

Devices forward syslog (UDP 514) directly to spane.

Anomaly detection

Log anomaly detection surfaces unusual patterns and feeds the unified risk score.

Searchable history

Logs and flows are indexed for fast query and retention-aware storage.


Risk & governance

Compliance, config & CVE

Continuous configuration governance with a single weighted risk view.

Compliance scoring

Jinja2 rule engine with LLDP-aware interface rules and role-consistency checks, scored A–F and run daily, automatically.

Config backup & diff

Full config backup (SSH + REST), change detection and diffs, and running-vs-startup mismatch alerts.

CVE intelligence

CVE intelligence and lifecycle/EOL tracking, rolled into unified risk scoring.

Reports

Daily / weekly / monthly / quarterly and compliance reports, plus TV/NOC dashboards with auto-rotation.


Operations

Platform & multi-site

Built to run many sites from one self-hosted deployment, with the operational guardrails to keep it healthy.

Multi-site roll-up

Site-aware inventory, dashboards, and reporting across locations from a single deployment.

RBAC & audit

Role-based access control, audit logging, and OpenBao-backed secrets management.

Safe updates

One-command updates with a tagged rollback point, automatic DB backup, explicit migrations, and a health check.

Resilient deploy

Docker Compose deploy with AES-256 backups (local/SCP/Git/S3), watchdog auto-recovery, and systemd auto-start.


Coverage

Validated platform support

Telemetry and access paths verified against lab hardware. Per-platform guides ship in the docs.

Platform SNMP SSH gNMI/MDT Syslog Environment
Cisco IOS / IOS-XE
Cisco NX-OS / IOS-XR
Juniper JunOS
Arista EOS
HPE AOS-CX
Fortinet FortiOS
Palo Alto PAN-OS
SonicWall (v7 / v8)

Plus Aruba AOS, MikroTik, and 100+ vendors via SNMP/MIB resolution. See the repo for the full, current matrix.


See it on your own infrastructure

Deploy with one command, then enroll an agent and add a device.