Guides
How to choose a network monitoring tool
Network tools split into three jobs — device health, inside-network flow, and outside-in synthetic testing. Pick by which job you actually have.
"Network monitoring" covers three genuinely different jobs, and most of the confusion in choosing a tool comes from not naming which one you have. One is device health: is this router, switch or link up, and how loaded is it? A second is flow analytics: what traffic is actually crossing the network, from where, to where, and how much? A third is outside-in testing: how does the internet path to a service perform from somewhere that isn't inside your own network? Some vendors do one of these well; a few try to do more than one. Naming your job first eliminates most of the field before you compare a single feature.
Job one: device health monitoring
This is the classic category — poll routers and switches over SNMP, alert before a device or link fails, and show utilization trends over time. SolarWinds NPM, Nagios, Zabbix and LibreNMS all do this job, and Auvik and DX NetOps extend it with automated discovery and topology mapping. If your question is "is our own hardware healthy," this is the job you have, and the deciding factors are usually deployment model and licensing, not detection sophistication — see below.
Job two: inside-network flow analytics
Device health tells you a link is at 80% utilization; it doesn't tell you which application, which customer, or which peer is responsible. Kentik and ntopng ingest NetFlow, sFlow or IPFIX data and let you query traffic by application, ASN, geography or device, which is the job for capacity planning, peering/transit cost analysis, or finding the source of a DDoS or anomalous traffic spike. Kentik works at enterprise/service-provider scale with cloud VPC flow log analytics across AWS, Azure and GCP; ntopng does the same job self-hosted and open source, sized from a home lab (free Community edition) up to enterprise deployments with paid Pro/Enterprise editions.
Job three: outside-in synthetic testing
Neither of the first two jobs tells you how your service actually performs for a user on the other side of the internet — through an ISP, a CDN, a DNS resolver you don't control. Cisco ThousandEyes and Catchpoint run scheduled synthetic tests from external vantage points and visualize exactly where in that path a problem occurs: your app, a CDN, a specific ISP, or the last mile to the user. This is the right job when your team is accountable for services that depend on the public internet or third-party SaaS, not just infrastructure you own end to end.
Some tools blur the lines deliberately — Kentik layers in its own synthetic and agent-based tests for teams that want flow analytics and outside-in testing from one platform, and SolarWinds' NetPath adds path visualization to a device-monitoring core. Ask directly whether a secondary capability is a first-class feature or a bolt-on before relying on it.
Deployment and who runs it
Within device-health monitoring specifically, the split is stark: Nagios Core, Zabbix and LibreNMS are self-hosted and free at the core — Zabbix with no feature gating at all, Nagios Core requiring plugins and text-file configuration, LibreNMS entirely community-governed with no official vendor upsell path. SolarWinds NPM, Auvik and DX NetOps are commercial, quote-priced products aimed at teams that want a supported product rather than a self-run open-source stack; Auvik in particular is built for MSPs managing many client networks from one multi-tenant console. Flow analytics and outside-in testing are effectively SaaS-only in this category — Kentik, ntopng's paid tiers, ThousandEyes and Catchpoint are all cloud-delivered (ntopng's free Community edition is the exception, self-hosted).
How pricing scales
Device-health tools price per monitored node or device: Nagios XI by node count, SolarWinds NPM by monitored elements, Auvik per managed device with many types free. Flow analytics tends to price by volume: Kentik's published Pro tier starts from an annual flow-per-second allocation, with Premier negotiated for larger scale. Outside-in testing prices by test volume and vantage points, and neither ThousandEyes nor Catchpoint publishes a rate card — both require a sales conversation sized to your test coverage. None of the quote-only vendors here should be assumed cheaper or more expensive than the others without an actual proposal against your scale.
A shortlist by situation
- If you need basic SNMP device health monitoring, free and self-hosted, look at Zabbix or LibreNMS.
- If you're an MSP monitoring many client networks, look at Auvik for its multi-tenant console and automated discovery.
- If you run a large, multi-vendor enterprise network needing centralized fault correlation, look at DX NetOps.
- If you need to know what traffic is actually crossing your network, not just whether a link is up, look at Kentik or, self-hosted, ntopng.
- If you're accountable for services that depend on the public internet or third-party SaaS, look at Cisco ThousandEyes or Catchpoint for outside-in testing.
- If your network is substantially Cisco already, ThousandEyes carries integration advantages the others don't.
Questions to ask vendors
- Which of the three jobs — device health, flow analytics, outside-in testing — does this actually do natively, and which is a secondary or bolt-on feature?
- What is the real cost at our current device/flow/test volume, not a starter tier?
- For self-hosted options, what hardware and ongoing maintenance does running this at our scale require?
- How does the tool distinguish a real outage from a single noisy sensor or transient blip?
- If we're evaluating a multi-tenant or MSP use case, how does per-client billing and access separation actually work?
Common mistakes
Buying a device-health tool and expecting it to answer flow-level questions it was never built for, then blaming the tool instead of the job mismatch. Assuming self-hosted means free — the SNMP polling, alert tuning and upgrade cycle for any of these is real, ongoing labor. And skipping outside-in testing entirely because internal dashboards look fine, when the actual complaint reaching your support queue is about performance on a network segment you don't monitor at all.
For head-to-head detail on two pairs practitioners search most, see Catchpoint vs ThousandEyes and Nagios vs Zabbix. See every tool in this category.