One platform for the whole stack
spane collects from servers and network devices natively, then runs a single alerting, logging, and compliance layer over both. Here is what it actually does.
Server monitoring, by agent
A single static binary (the Linux core build is stdlib-only) enrolls with a one-time token, receives a unique client certificate, and pushes metrics over mutual TLS. It opens no inbound ports.
System metrics
CPU, memory, disk, and network — collected per-core, per-mount, and per-interface, on a default 30-second interval.
Service & process collection
Optional running-process and service-state collection via systemd / Windows SCM.
Role-based health
Functional checks for DNS, DHCP, NPS, Domain Controller, Web, Database, File, and Syslog roles — not just “is it up,” but “is it doing its job.”
Unified inventory
Agent metrics land in the same InfluxDB measurements as SNMP/REST collection, so servers appear on the Servers page with full drill-down.
Cross-platform
Linux amd64 / arm64 and Windows amd64, each a hardened low-privilege system service.
Network device monitoring
Discover and enrich devices across four tiers, then poll them over SNMP and SSH — with streaming telemetry where the platform supports it.
SNMP polling
SNMP v3 (recommended) or v2c, with ~1,800 vendor + standard MIBs for OID resolution and REST API enrichment (e.g. AOS-CX).
Reachability & latency
Ping/ICMP reachability with round-trip-time (RTT) latency monitoring and alerting.
Interface & environment
Interface utilization and statistics, plus environment telemetry — temperature, fans, PSU — and PoE budget tracking with alerts.
Streaming telemetry
gRPC/gNMI and Cisco MDT streaming telemetry on supported platforms, with SNMP polling as the fallback.
Discovery & enrichment
Four-tier discovery, LLDP/CDP topology mapping, ARP/MAC table collection with OUI lookup, and manual topology links for LLDP-less devices.
Flow analytics
See what is actually traversing the network, not just interface counters.
NetFlow & sFlow
NetFlow v5/v9/IPFIX on UDP 2055 and sFlow on UDP 6343, ingested and indexed for query.
DNS enrichment
Optional DNS hostname enrichment turns flow endpoints into readable names.
Flow alerting
Flow-threshold alerts feed the same unified alerting engine.
WAN & circuits
WAN circuit tracking — provider/contract/cost, bandwidth, 95th-percentile trending, and contract-expiry alerts.
Unified alerting
Servers and network gear share a single alerting pipeline — no second tool to reconcile.
Team routing & escalation
Route alerts to teams with escalation policies, so the right person is paged.
Maintenance windows
Suppress expected noise during planned work with maintenance windows.
Channels
Email, Slack, and Discord delivery, plus bulk alert actions for triage at scale.
Custom thresholds
Custom alerts over InfluxDB metrics for both agent and SNMP-sourced data.
Log forwarding & central logs
Device syslog and forwarded server logs converge in one searchable store on OpenSearch.
Syslog receiver
Devices forward syslog (UDP 514) directly to spane.
Anomaly detection
Log anomaly detection surfaces unusual patterns and feeds the unified risk score.
Searchable history
Logs and flows are indexed for fast query and retention-aware storage.
Compliance, config & CVE
Continuous configuration governance with a single weighted risk view.
Compliance scoring
Jinja2 rule engine with LLDP-aware interface rules and role-consistency checks, scored A–F and run daily, automatically.
Config backup & diff
Full config backup (SSH + REST), change detection and diffs, and running-vs-startup mismatch alerts.
CVE intelligence
CVE intelligence and lifecycle/EOL tracking, rolled into unified risk scoring.
Reports
Daily / weekly / monthly / quarterly and compliance reports, plus TV/NOC dashboards with auto-rotation.
Platform & multi-site
Built to run many sites from one self-hosted deployment, with the operational guardrails to keep it healthy.
Multi-site roll-up
Site-aware inventory, dashboards, and reporting across locations from a single deployment.
RBAC & audit
Role-based access control, audit logging, and OpenBao-backed secrets management.
Safe updates
One-command updates with a tagged rollback point, automatic DB backup, explicit migrations, and a health check.
Resilient deploy
Docker Compose deploy with AES-256 backups (local/SCP/Git/S3), watchdog auto-recovery, and systemd auto-start.
Validated platform support
Telemetry and access paths verified against lab hardware. Per-platform guides ship in the docs.
| Platform | SNMP | SSH | gNMI/MDT | Syslog | Environment |
|---|---|---|---|---|---|
| Cisco IOS / IOS-XE | ✓ | ✓ | ✓ | ✓ | — |
| Cisco NX-OS / IOS-XR | ✓ | ✓ | ✓ | ✓ | — |
| Juniper JunOS | ✓ | ✓ | ✓ | ✓ | — |
| Arista EOS | ✓ | ✓ | ✓ | ✓ | — |
| HPE AOS-CX | ✓ | ✓ | — | ✓ | ✓ |
| Fortinet FortiOS | ✓ | ✓ | — | ✓ | — |
| Palo Alto PAN-OS | ✓ | ✓ | — | ✓ | — |
| SonicWall (v7 / v8) | ✓ | ✓ | — | ✓ | — |
Plus Aruba AOS, MikroTik, and 100+ vendors via SNMP/MIB resolution. See the repo for the full, current matrix.
See it on your own infrastructure
Deploy with one command, then enroll an agent and add a device.