- Network Monitor Dashboard (Technical Preview) with device inventory, metrics, topology, flows, traps and alerts
- Network Flows collection for NetFlow, IPFIX and sFlow from routers, switches and firewalls (Technical Preview)
- Network Topology mapping of Layer 2 and Layer 3 network structure via SNMP with LLDP neighbours, forwarding databases, OSPF and BGP adjacencies (Technical Preview)
- Application Dependency Mapping from Linux kernel to map processes, containers and Kubernetes workloads without instrumentation (Technical Preview)
- SNMP Trap Listener to decode traps from 800+ vendor profiles into charts and readable messages
- OpenTelemetry logs ingestion with storage and querying through the Logs interface
- Unified log engine supporting systemd journal, Windows events, OpenTelemetry logs, SNMP traps and network flows with configurable retention
- AWS CloudWatch collector for monitoring AWS resources
- macOS monitoring rebuilt natively with unified logs through Apple's OSLog framework, GPU, SMC, IOHID sensors, fans, power, battery, thermal pressure and NVMe health
- Windows Active Directory and SMB monitoring on a reworked perflib layer
- FreeBSD system-call monitoring
- Linux audit subsystem monitoring
- Netdata Cloud AI troubleshooting integration with custom MCP servers including GitHub, PagerDuty and Atlassian
- Netdata Cloud Fleet Management views with node status hexagons
- Netdata Cloud mobile app access for free plan users
- SNMP device coverage expanded from 229 to 273 profiles
- Prometheus collector rebuilt with real relabeling engine and application profiles
- Netdata Cloud Nodes and Alerts views rebuilt for 50,000-node scale
- Netdata Cloud silencing rules gained timezone-anchored scheduling
- Full support ended for RHEL 7.x, CentOS 7.x, and Amazon Linux 2
Table of Contents
- Summary
- Highlights
- Network Monitor Dashboard (Technical Preview)
- Network Flows: NetFlow, IPFIX and sFlow (Technical Preview)
- Network Topology and Application Dependencies (Technical Preview)
- SNMP Trap Listener
- Expanded SNMP Device Coverage
- Logs: OpenTelemetry Ingestion and a Unified Log Engine
- AWS CloudWatch Collector
- New Collectors
- Endpoint Monitoring: macOS, Windows, FreeBSD and Linux
- Prometheus Collector Overhaul
- Query Engine and API
- Netdata Cloud: AI Troubleshooting and MCP
- Netdata Cloud: Alerts and Notifications
- Netdata Cloud: Fleet Management and Scale
- Netdata Cloud: Dashboards and Charts
- Security Hardening
- End of Full Support for RHEL 7.x, CentOS 7.x, and Amazon Linux 2
- Acknowledgments
- Contributions
- Deprecation notice
- Support options
Release Summary
Netdata has always been exceptionally good at one particular thing: telling you, per second and with no configuration, what is happening inside a machine. v2.11.0 is the release where that stops being the boundary.
Two things happen here, and together they change what Netdata is.
First, Netdata learns the network. A new Network Monitor dashboard brings device inventory, metrics, topology, flows, traps and alerts into one place. Behind it, Network Flows receives NetFlow, IPFIX and sFlow from your routers, switches and firewalls and turns raw records into a faceted view of who is talking to whom. Network Topology walks your devices over SNMP and draws the Layer 2 and Layer 3 map — LLDP neighbours, forwarding databases, OSPF and BGP adjacencies — while Application Dependency Mapping does the same for your software, reading your Linux hosts' kernels to map what each process, container and Kubernetes workload talks to, with nothing to instrument. The SNMP Trap Listener makes Netdata a trap receiver that decodes traps from 800+ vendor profiles into charts and readable messages instead of raw OIDs. Feeding all of it, SNMP device coverage grew from 229 to 273 profiles. The usual Netdata rules still apply: the profiles are already written, collection and storage stay on your own infrastructure, and there is little to configure beyond telling Netdata where the devices are. Network Monitor, Network Flows and Network Topology ship as technical previews — complete enough to run today, open to every Netdata user while in preview, and still moving fast.
Second, and just as important, logs become a first-class pillar of the platform. This release adds OpenTelemetry
logs — OTLP log records are ingested, stored and queried from the same Logs tab that already serves systemd journal
and Windows events, with journald, filelog and syslog receivers, configurable retention, log-to-metric conversion
and parsing for unstructured lines. The deeper change is architectural: the same faceted, high-cardinality log engine now
backs systemd journal, Windows events, OpenTelemetry logs, SNMP traps and network flows alike. Five very different
signal types, one query surface, all stored on your own infrastructure.
Around those two, this release completes the major-cloud set with a new AWS CloudWatch collector — the counterpart to the Azure Monitor collector added in v2.10.0 — and rebuilds the Prometheus collector around a real relabeling engine with application profiles. Underneath all of it sits the largest stability and memory-safety effort we have ever shipped in a single release: 87 incremental parts across the database engine, streaming, ACLK, health, ML and libnetdata.
Netdata's strong endpoint monitoring capabilities have been enhanced. macOS monitoring was rebuilt natively: unified
logs through Apple's OSLog framework, GPU, SMC and IOHID sensors, fans, power and battery, thermal pressure and NVMe
health, none of which was reachable before without dropping to log show and powermetrics by hand. Windows added
Active Directory and SMB monitoring on a reworked perflib layer, FreeBSD added system-call monitoring, and
Linux added audit subsystem monitoring. One agent, four endpoint operating systems, per-second resolution on each.
In Netdata Cloud, AI troubleshooting just became more accurate and more relevant: you can now connect your own MCP servers to your Netdata Space — GitHub, PagerDuty and Atlassian, and your own custom servers — and Netdata AI will use them while investigating. Alongside that, new Fleet Management views render nodes as status hexagons, the Nodes and Alerts views were rebuilt to stay fluent in 50,000-node rooms, silencing rules gained timezone-anchored scheduling, and the mobile app opened up to everyone on free plans.
| Feature | Highlights | Details |
|---|---|---|
| Network Monitor Dashboard | One place for the whole networkTechnical Preview | • Device inventory, vendors, health and top talkers at a glance• Overview, Devices, Metrics, Topology, NetFlow, Traps and Alerts sub-tabs• Per-device and per-interface traffic, speed and error rates |
| Network Flows | NetFlow v5/v9, IPFIX, sFlowTechnical Preview | • New high-throughput flow-analysis plugin with its own four-tier journal• Cisco ASA NSEL accounting• Enrichment with cloud provider IP ranges, BGP/RIPE RIS data, and private-IP labelling |
| Network Topology | L2 and L3 topology discoveryTechnical Preview | • LLDP, FDB and STP based Layer 2 topology• L3 subnet segments plus OSPF and BGP adjacencies• MAC OUI vendor lookup and reverse DNS enrichment |
| Application Dependency Mapping | Per-host service maps, no instrumentationTechnical Preview | • What each process talks to, read from the kernel socket table• Attributed per container, image, systemd unit and Kubernetes pod/workload (Linux)• Regroup the map by process name, container or PID |
| SNMP Trap Listener | 800+ vendor trap profiles | • Profile-based trap decoding into charts and log entries• Trap enrichment and forwarding to SIEM• Configurable via the Dynamic Configuration UI |
| Expanded SNMP Device Coverage | 273 device profiles, up from 229 | • Cisco Catalyst, Cisco Nexus, FortiGate and Check Point improvements• BGP session monitoring and network-device licence monitoring• SNMPv3 context names, bitmask value mappings, ping_only mode |
| Logs | One engine, five signal types | • OpenTelemetry (OTLP) log ingestion, query and retention• journald, filelog and syslog receivers; log-to-metric conversion• Same faceted engine now backs journal, Windows events, traps and flows |
| AWS CloudWatch Collector | 47 service profiles, 800+ metrics | • Automatic resource discovery with tag filtering and multi-account support• Stock health alerts, incl. load-balancer target health and MSK• Query policies to control API cost on sparse metrics |
| New Collectors | Cato Networks, PAN-OS, and more | • SASE and firewall monitoring for Cato Networks and Palo Alto PAN-OS• New endpoint collectors for macOS, Windows, Linux and FreeBSD• HTTP service discovery, range heatmaps and chart series aggregation |
| Endpoint Monitoring | macOS, Windows, FreeBSD, Linux | • Native macOS logs, GPU, sensors, fans, power, thermal and NVMe health• Windows Active Directory and SMB on a reworked perflib layer• FreeBSD system calls; Linux audit subsystem and nfds monitoring |
| Prometheus Collector Overhaul | Relabeling and app profiles | • Full relabeling engine with job-level metric relabeling• Profile-driven application detection for chart contexts• Single-pass stream parser, migrated to the V2 collector framework |
| Query Engine and API | Top-N queries and correctness | • New limit parameter for top-N dimension queries• New latest time-grouping with a collector-cache fast path• Deterministic cardinality limiting and group-by aggregation fixes |
| Netdata Cloud: AI Troubleshooting and MCP | Bring your own MCP servers | • Connect GitHub, PagerDuty and Atlassian Cloud to a Space over OAuth• Netdata AI uses connected tools in conversations and reports• Read-only tools only, enforced by Netdata• Multi-algorithm capacity forecasting with automatic selection |
| Netdata Cloud: Alerts and Notifications | Silencing, labels, misconfiguration | • Timezone-anchored, DST-safe silencing rules with auto-expiry• Host labels included in every notification channel• Space admins notified about misconfigured alerts• New Group Email integration for shared mailing lists• Mobile app now free for all |
| Netdata Cloud: Fleet Management and Scale | 50,000-node rooms | • New Nodes Fleet Management views with node-group hexagons• Rebuilt home page with a geographic fleet map• Nodes and Alerts stay fluent at very high cardinality |
| Netdata Cloud: Dashboards and Charts | New cards and aggregations | • State Timeline, heatmap, alert-count, node-breakdown and inventory cards• Dashboard playlists, plus import and export• Percentage-of-group and latest time aggregation |
| Stability, Security and Performance | Production reliability | • Faster agent startup through optimized host-context loading• MCP endpoints protected by a dedicated ACL and bearer tokens• Large memory-safety effort across the database engine, streaming and ACLK |
Release Highlights
Network Monitor Dashboard — Technical Preview
[!NOTE] Technical Preview. The capabilities that follow — Network Monitor, Network Flows, Network Topology and Application Dependency Mapping — ship as technical previews. Everything described here works today and is open to every Netdata user while in preview. What is still moving is the shape around them: we are expanding coverage, refining the interfaces, and working out how these capabilities are ultimately packaged and supported, so expect their scope and availability to keep evolving over the next few releases. Preview feedback carries real weight, please tell us what you need through any of the support channels below.
Everything below is surfaced through one new place in the interface: a dedicated Network Monitor tab that brings device inventory, metrics, topology, flows and traps together instead of leaving them as separate tools.
Network Monitor dashboard showing device counts by type, network health, errors and drops, devices by vendor, top devices by traffic, and device inventory
| Sub-Tab | What It Shows |
|---|---|
| Overview | Device counts by type, network health, errors and drops, devices by vendor, top devices by traffic, and a full device inventory |
| Devices | Every discovered network device, with vendor, type and address |
| Metrics | Per-device and per-interface metrics: traffic in/out, interface speed, error and discard rates |
| Topology | The discovered Layer 2 and Layer 3 map |
| NetFlow | Flow analysis, with the full faceted search described below |
| Traps | Decoded SNMP traps as charts and searchable log entries |
| Alerts | Alerts raised on network devices |
The result is that an engineer investigating a network problem starts from "which devices do I have and are they healthy" and drills into flows, topology or traps without leaving the page.
Network Flows: NetFlow, IPFIX and sFlow — Technical Preview
Netdata can now receive and analyze network flow records. The new Network Flows plugin accepts NetFlow v5/v9, IPFIX and sFlow from routers, switches and firewalls, and turns them into a searchable, faceted view of who is talking to whom on your network.
Network Flows Sankey view grouping flows by source AS, protocol and destination AS, with the faceted filter sidebar
Flows can be grouped and sorted on any field and rendered as a table, Sankey diagram, time series, or country, state and city maps.
What You Get
| Feature | Details |
|---|---|
| Multi-Protocol Ingestion | NetFlow v5 and v9, IPFIX, and sFlow on configurable listeners |
| Cisco ASA NSEL | Firewall accounting records, including connection and NAT events |
| Four-Tier Local Journal | Raw records plus 1-minute, 5-minute and 1-hour rollups, stored on the agent |
| Enrichment | Cloud-provider IP ranges, BGP/RIPE RIS routing data, private-IP labelling, and reverse DNS |
| Faceted Search | Filter and group flows interactively from the Live tab |
| Accounting Charts | Per-listener and per-source metrics on records received, processed and dropped |
Where Data Lives
Flow data stays on the agent. Collection and the four-tier journal remain local under the configured journal_dir —
by default ${NETDATA_CACHE_DIR}/flows, typically /var/cache/netdata/flows/ for native packages.
[!IMPORTANT] During the Tech Preview, Network Flows is available also on the free Community tier and requires an agent connected to Netdata Cloud and a > signed-in user whose Space role permits sensitive functions. If you see Connect this agent to Netdata to use this function, the plugin is > working — the block is access control, not a failure. Connecting the agent does not move or offload its flow storage. See the access requirement for details.
The plugin ships in the static and Docker builds.
Network Topology and Application Dependencies — Technical Preview
Netdata now draws your infrastructure — twice. A new SNMP topology engine builds Layer 2 and Layer 3 maps of your network from the devices themselves. On your Linux hosts, the Network Viewer builds a second map: what each process, container and Kubernetes workload is talking to, read straight from the kernel.
SNMP network topology map showing discovered Cisco, Juniper and Aruba devices and their adjacencies, with map modes and inference strategies
Topology Discovery
| Layer | Discovered From | Produces |
|---|---|---|
| Layer 2 | LLDP neighbours, forwarding databases (FDB), STP | Switch-to-switch and switch-to-host adjacencies |
| Layer 3 | Interface addressing and subnet data | L3 subnet segments and subnet adjacencies |
| Routing | OSPF neighbour tables, BGP peer tables | OSPF and BGP adjacency links between routers |
Discovered devices are enriched with MAC OUI vendor lookup and reverse DNS, so the map is labelled with real vendor and host names rather than raw addresses.
Application Dependency Mapping
The same topology view that draws your switches also draws your software. On a monitored host, Netdata reads the kernel's live socket table and turns it into a dependency map: what each process is talking to, over which port — attributed, on Linux, to the container, image, systemd unit, or Kubernetes pod, namespace and workload that owns it.
There is nothing to instrument. No language agents, no sidecars, no code changes, no service mesh. These are the sockets your kernel already has, enumerated fresh each time you open the map and drawn as a graph — on hosts you are already monitoring, with no setup.
- Attribution down to the workload — every process in the map carries its command line and the user it runs as, plus the container, image, systemd unit or Kubernetes pod, namespace and workload behind it.
- Group the map the way you think — collapse by process name, container, or PID. A service running eight worker processes is one box when you want the architecture, and eight when you need the one misbehaving worker.
- Aggregated or detailed — the dependency graph by default, or the same graph plus the individual socket evidence behind every link.
- Linux, FreeBSD and macOS — container and Kubernetes attribution is Linux-only; on FreeBSD and macOS the map is drawn from processes and endpoints. On Windows, the Network Connections and Network Protocols tables remain available, the latter carrying SMB.
Today each host draws its own map: processes on the same host are linked to each other directly, and peers elsewhere appear as the addresses they are.
[!TIP] See the Network Topology documentation for setup and supported devices, and Application Dependency Mapping for what the connections map covers and on which platforms.
SNMP Trap Listener
Netdata can now act as an SNMP trap receiver. The new SNMP Trap Listener accepts traps from network devices, decodes them using profiles, and turns them into charts and searchable log entries.
SNMP traps decoded into an events distribution chart and readable log messages, with facets for trap name, severity, vendor and source IP
Instead of an opaque OID, a trap arrives as IF-MIB::linkDown with the message "Link down on interface 30 on
MikroTik-router" — charted by trap name, filterable, and searchable alongside your other logs.
| Feature | Details |
|---|---|
| 800+ Vendor Profiles | Trap definitions covering a broad range of network-equipment vendors |
| Profile-Based Decoding | Traps are matched to profiles and rendered as meaningful charts and fields, not raw OIDs |
| Enrichment | Trap sources are enriched and deduplicated |
| SIEM Forwarding | Forward decoded traps onward to a SIEM |
| UI Configuration | Configure listeners through the Dynamic Configuration UI |
[!TIP] See the SNMP Traps documentation for listener configuration, the field reference, enrichment, and SIEM forwarding.
Expanded SNMP Device Coverage
SNMP device profiles grew from 229 to 273 in this release, and the profile engine gained several capabilities.
- Vendor improvements: Cisco Catalyst, Cisco Nexus, Fortinet FortiGate, Check Point, and Netgear (topology discovery).
- BGP session monitoring for network devices.
- Network-device licence monitoring, so you can alert before a licence lapses.
- SNMPv3 context name support.
- Structured mapping configuration and bitmask value mappings, so vendor status bitfields become readable states.
ping_onlymode for devices you want reachability for without a full SNMP walk.- More reliable collection:
snmpEngineTimeas the primary uptime source, a lower defaultMaxOIDsof 20, corrected retry serialization, and tolerance for invalid optional typed row values.
Logs: OpenTelemetry Ingestion and a Unified Log Engine
Netdata already ingested OpenTelemetry metrics over OTLP. v2.11.0 adds logs: OTLP log records are received,
stored through a dedicated storage path, and queried from the Logs tab alongside systemd journal and Windows event
logs. Retention and storage defaults are configurable, and the otel-plugin is now also built and enabled on macOS.
In practice, an OpenTelemetry Collector can forward logs to Netdata from the journald, filelog and syslog
receivers, and you can shape them on the way in — converting logs to metrics, or parsing unstructured lines into fields
you can then filter on.
One Engine, Five Signal Types
The more consequential change is what now sits underneath. Netdata's faceted, high-cardinality log engine — journal files, facet extraction, and interactive filtering — became the common substrate for everything log-shaped:
| Source | Status in v2.11.0 |
|---|---|
| systemd journal | Established; this release fixes memory retention after queries and journal access validation |
| Windows events | Established; row rendering fixes in this release |
| OpenTelemetry logs | New — OTLP ingestion with its own storage and query path |
| SNMP traps | New — decoded traps become searchable log entries, not just charts |
| Network flows | New — flow records land in a four-tier journal with the same faceted search |
This is why a NetFlow record, a decoded IF-MIB::linkDown trap and an application log line all filter, group and search
the same way. It also means improvements to the engine — indexing, retention accounting, memory behaviour — benefit all
five at once. Groundwork for virtual log functions landed in this release as well.
AWS CloudWatch Collector
Monitor your AWS estate from Netdata with the new CloudWatch collector. It reads platform metrics from the CloudWatch API with automatic resource discovery: point it at your accounts, and it finds your resources, matches them to built-in profiles, and starts collecting.
This completes the major-cloud set — Netdata v2.10.0 added Azure Monitor, and this release adds its AWS counterpart.
What You Get
| Feature | Details |
|---|---|
| 47 Built-in Service Profiles | 800+ metrics across compute, containers, databases, networking, storage, messaging, AI/ML and billing |
| Automatic Discovery | Discovers resources and enables matching profiles without per-resource configuration |
| Multi-Account | Collect from several AWS accounts in a single collector job |
| Resource Tag Filtering | Scope discovery by resource tags, and optionally attach tags as chart labels |
| Explicit Targets | Declare exact targets, collection rules, and exact metric selections when you do not want discovery |
| Query Policies | Per-rule and per-selection policies control how sparse metrics are queried, keeping CloudWatch API cost down |
| Built-in Alerts | Stock health alerts, including load-balancer target health and MSK cluster conditions |
| Collector Activity Metrics | Profile-aware metrics on the collector's own API usage, so you can see what it is costing you |
| UI Configuration | Configure through the Netdata Dynamic Configuration UI without editing files |
Supported Services
| Category | Services via Profiles |
|---|---|
| Compute | EC2, Auto Scaling, Lambda, Step Functions |
| Containers | ECS, EKS (incl. control plane) |
| Databases | RDS, DocumentDB, DynamoDB (incl. per-operation), ElastiCache, Redshift, OpenSearch |
| Networking | ALB (incl. target and target health), NLB, ELB, NAT Gateway, Site-to-Site VPN, CloudFront, API Gateway |
| PrivateLink | Endpoints and endpoint subnets, services with per-AZ, per-load-balancer and per-VPC-endpoint breakdowns |
| Storage | S3 (incl. request metrics), EBS (incl. stalled I/O), EFS |
| Messaging | SQS, SNS, EventBridge, Kinesis, Firehose, MSK (incl. per-cluster) |
| AI & ML | Bedrock |
| Billing | Total, per-service, per-linked-account and per-linked-account-per-service cost metrics |
[!TIP] For setup and authentication options, see the CloudWatch collector documentation. To write your own profiles, see the AWS CloudWatch Profile Format.
New Collectors
| Collector | Monitors |
|---|---|
| Cato Networks | Cato SASE sites, tunnels and traffic |
| Palo Alto PAN-OS | PAN-OS firewall health, sessions and throughput |
| Linux audit subsystem | Audit events from the Linux kernel audit subsystem |
| Active Directory (windows.plugin) | Domain controller health and replication |
| SMB protocol (windows.plugin) | SMB server and client activity |
| FreeBSD system calls | System-call activity on FreeBSD |
| macOS hardware and logs | GPU, SMC and IOHID sensors and fans, power sources, thermal pressure, NVMe health and macOS unified logs — see Endpoint Monitoring below |
Also new in the collector framework: HTTP service discovery, single-instance collector support, histogram buckets rendered as range heatmaps, chart series aggregation, and mutable chart labels.
Endpoint Monitoring: macOS, Windows, FreeBSD and Linux
Several of the collectors above belong to a larger push that runs through this whole cycle: bringing every endpoint operating system up to the depth Netdata has always had on Linux. Same agent, same per-second resolution, same zero-configuration behaviour — whether the endpoint is a Linux server, a Mac in a build farm, a Windows domain controller or a FreeBSD host.
| Platform | What Landed in This Cycle |
|---|---|
| macOS | A native overhaul: unified logs, GPU, sensors and fans, power and battery, thermal pressure, NVMe health and per-application metrics — detailed below |
| Windows | Active Directory and SMB protocol monitoring, a reworked perflib layer with missing memory metrics and path translation, and Windows connection and protocol tables in the Network Viewer |
| FreeBSD | System-call monitoring, connection-map support in the Network Viewer, and build and counter-accuracy fixes |
| Linux | Linux audit subsystem monitoring, per-application nfds (open file descriptor) monitoring, and the groundwork for a new eBPF Go plugin |
macOS: Native Logs, Sensors, GPU and Hardware Health
macOS is the largest single piece. Apple silicon put Macs into build farms, CI fleets and render pipelines, but macOS
monitoring stayed shallow — for logs and hardware telemetry you dropped to log show and powermetrics by hand and
read the output yourself. Netdata now collects that natively, with the same charts, alerts and retention as everything
else.
| Area | What Netdata Now Collects |
|---|---|
| Unified Logs | Read through Apple's OSLog framework, not by parsing log show output. Severity histograms, faceted filtering on level, process, PID, sender, subsystem, category, thread, activity and signpost fields, full-text search and live tail — in the same Logs tab as journald and Windows events |
| GPU (Apple Silicon) | Active-residency utilization, time-weighted clock frequency, performance-state residency, power draw and die temperature |
| Sensors and Fans | Temperature, voltage, current, power and fan speed from SMC and IOHID, summarised per subsystem with optional per-sensor detail |
| Thermal Pressure | Nominal, moderate, heavy, sleeping and trapping states, per-subsystem thermal levels for CPU, GPU and I/O, and processor-hot assertions |
| Power and Battery | Charge, voltage, current, cycle count and temperature per battery or UPS — cycle count doubling as a wear indicator across an ageing laptop fleet |
| Storage Health | NVMe health read natively through IOKit — estimated endurance, available spare, composite temperature, power-on and power-cycle counts, unsafe shutdowns, data read and written, and media errors — plus smartctl through ndsudo |
| Per-Application Metrics | CPU, memory and disk I/O, grouped the way macOS itself groups things: app bundles, framework helpers, daemons, driver extensions and third-party binaries |
| Network | Live connections with their owning processes, TCP and UDP statistics, and the process-to-endpoint topology view, on a Darwin libproc backend |
Also on macOS in this release: the otel-plugin is now built and enabled, so a Mac can ingest OpenTelemetry metrics
and logs like any other host; apps.plugin gained bounded-cardinality process grouping for machines with heavy
process churn; disk.util percent scaling was corrected; and an nd-run setenv SIGSEGV and a mach_smi stack buffer
overflow were both fixed.
Because this work was backported to 2.10.4, many macOS users already have it.
[!TIP] Native macOS Monitoring: Logs, Sensors, GPU & Hardware Health walks through the entire macOS overhaul, chart by chart, with the reasoning behind each metric.
Windows
- Active Directory monitoring in
windows.plugin— domain controller health and replication. - SMB protocol monitoring — SMB server and client activity.
- Perflib reworked, with missing memory metrics and path translation added.
- Network Viewer on Windows — the Network Connections and Network Protocols tables, the latter carrying SMB data.
- Carried in from the 2.10.x patch line: MSI installer fixes, Windows hardware detection, and Windows event row rendering.
FreeBSD
- System-call monitoring, contributed by @DavidMarec.
- Network Viewer support, so FreeBSD hosts draw a connection map from their processes and endpoints, as macOS does.
- Agent compilation on FreeBSD fixed, plus counter size mismatches and a
freebsd_ipfwoff-by-one.
Linux
- Linux audit subsystem monitoring through
debugfs.plugin— audit events from the kernel audit subsystem. nfdsmonitoring inapps.plugin, for per-application open file descriptors, contributed by @arch-yunus.- Groundwork for a new eBPF Go plugin (
ebpfgo.plugin), and the cgroups–eBPF transport moved from shared memory to netipc IPC. - The Go
sensorscollector was removed; Linux hardware sensors have been collected by the C libsensors module indebugfs.pluginsince v2.2.0, so nothing changes for users.
Cutting across platforms: a shared cross-OS sensors function and a common temperature-histogram context, so hardware
sensor readings look and query the same way regardless of which platform reported them.
Prometheus Collector Overhaul
The Prometheus collector was rebuilt on the V2 collector framework and gained the pieces users kept asking for:
- Relabeling engine, at both job level and profile level. The old
label_prefixoption is dropped in favour of it. - Application profiles (
promprofiles) that detect the exporter and give its metrics proper chart contexts, instead of one undifferentiated pile of charts. - Profile-owned relabeling and fallback types, so a profile carries its own relabeling rules and decides how metrics it does not cover are charted — no per-job configuration needed to get a curated result.
- Profile autogen selector for generating chart contexts from a profile.
- Single-pass stream parser, replacing the previous multi-pass scrape parsing.
[!TIP] See the Prometheus Profile Format for writing your own profiles, and Prometheus Metric Relabeling for the relabeling rules.
Query Engine and API
limitparameter on data queries, for efficient top-N dimension queries.- New
latesttime-grouping, with a collector-cache fast path so "what is it right now" queries do not touch the database engine. - Deterministic cardinality limiting:
cardinality_limitno longer crashes, limits only the result dataset by default, breaks ties deterministically, and reports partial results on mixed folds. The fold cut is exposed injsonwrapv2. - Group-by correctness: fixes to percentage grouping at the second grouping level with a dimensions filter, to
view.dimensions.sts.avgacrosssum/min/max/extremes/percentageaggregations, and per-row anomaly rate with a zero-denominator guard. - Accurate PARTIAL annotations: false PARTIAL annotations on complete data are fixed, raw partial-trimming metadata is exposed, and the pre-window storage point is excluded from the first bucket of tier queries.
- Correct tier selection for sub-resolution windows.
csvjsonarraynow always emits numeric timestamps and valid JSON whenlabel-quotesis passed.
Netdata Cloud: AI Troubleshooting and MCP
[!NOTE] Netdata Cloud ships continuously rather than on the Agent's release cadence. The Cloud sections below cover everything that shipped between v2.10.0 (8 April 2026) and this release. If you use Netdata Cloud, you already have all of it — nothing here requires an upgrade. Items marked Beta are available to everyone; the label reflects how new they are, and means their interface and scope will keep moving over the next few releases.
MCP client capabilities — Beta. An alert tells you what changed. It rarely tells you why — that answer usually lives in the pull request that shipped minutes earlier, or the incident already open in PagerDuty. With MCP Connections, Netdata Cloud acts as an MCP client and reads those systems directly while it investigates.
MCP Connections settings, offering GitHub, PagerDuty, Atlassian Cloud and custom MCP server integrations
Note this is the reverse of the integration you may already use. Connecting Claude or Cursor to Netdata's own MCP server has been possible for a while; here, Netdata reaches out to your servers.
| Capability | Details |
|---|---|
| Predefined Integrations | GitHub, PagerDuty, and Atlassian Cloud for Jira, Confluence and Bitbucket — connected over OAuth, no tokens to paste |
| Custom MCP Servers | Point at any HTTPS MCP endpoint, with encrypted credentials, connection testing, health checks and tool selection |
| Read-Only, Enforced | Netdata enables read-only tools only. Tools that create, modify or delete are discovered but cannot be enabled from the UI |
| Used by Reports and Chats | Connected tools are available to Netdata AI in both AI conversations and generated reports |
| Admin-Gated | Configured per Space under Settings → AI → MCP Connections, behind an admin-only permission |
| On-Premises | AI and Insights features are now enabled on on-prem installations that have them configured |
Why this matters: an investigation that used to stop at "CPU saturation started at 14:02" can now continue into "…which coincides with the deploy in this GitHub PR, and there is already a PagerDuty incident open for it."
[!IMPORTANT] MCP Connections require a Netdata Cloud paid plan and Space admin access to configure.
Alongside MCP, capacity forecasting was rewritten to run several forecasting algorithms and automatically select the best-performing one per metric, rather than applying a single model everywhere. Investigation prompts grew to 10,000 characters, and reports gained dedicated forecasting tooling.
Netdata Cloud: Alerts and Notifications
Silencing rules received the largest single set of changes:
- Timezone-anchored scheduling. A rule is now bound to a timezone, so recurring maintenance windows behave correctly across DST transitions and multi-day windows no longer drift.
- Notification options instead of severities, giving finer control over exactly what a rule suppresses.
- Automatic deletion on expiry, so temporary silences do not accumulate, with a "rule expired" entry in the activity feed.
- Rule authorship is recorded and shown, so you can tell who silenced what.
- Node selection by room and multi-select, instead of picking nodes one at a time.
Notifications now carry host labels — across email, Slack, Mattermost, Rocket.Chat and mobile push (up to 100 labels per email). An alert arrives already carrying the environment, region, cluster or team that the node belongs to, so routing and triage no longer require a lookup. Slack and Mattermost push notifications also render message previews.
Misconfigured alerts are no longer silent. Space administrators are notified when alerts are misconfigured — for example alerts stuck in a raised state — with a direct link to a dedicated tab listing them.
A new Group Email notification integration sends Space-wide alerts to a shared group or mailing-list address, independently of each member's personal email notification settings — so an on-call alias or team distribution list receives alerts without every member having to configure their own. Configure it per Room and per notification type under Space settings → Alerts & Notifications. The address is verified with a token from a test email, which means you need access to that mailbox; the integration requires a paid plan and Space admin access.
Alert evaluation — testing an alert definition against historical data before deploying it, introduced in v2.10.0 —
now evaluates several definitions in a single request, so tuning a set of related alerts no longer means one
round-trip each. Netdata's AND/OR/NOT expressions are translated correctly, and time-range errors are clearer. The
Alerts view also gained status filters and configurable alert cards.
Finally, the Netdata mobile app is now available to everyone on free plans. It was previously restricted to paid plans.
Netdata Cloud: Fleet Management and Scale
Cloud's node views were rebuilt around getting to the right node quickly in very large infrastructures.
Fleet Management view showing 23,495 servers as status hexagons, grouped by fleet state with per-location cards
- Nodes Fleet Management views, with nodes rendered as group hexagons that reflect status and link straight through to the relevant alerts or the Nodes tab.
- Rebuilt home page, including a geographic map card for distributed fleets.
- Group nodes by alert status, in addition to the existing grouping dimensions.
- SNMP overview tab, surfacing SNMP devices — including per-interface breakdowns on a single node.
- Metric taxonomy kept in step with the Agent, so this release's new collectors are browsable in Cloud from day one — AWS CloudWatch, MSSQL transaction logs, and vSphere clusters, datastores and resource pools all have taxonomy entries.
On scale: the Nodes and Alerts views were rebuilt to stay fluent in rooms of 50,000 nodes, backed by a large query-path overhaul in the charts service — batched per-node and per-context routing, covering indexes, memory-optimized aggregation, and top-N pushdown with distributed top-k across agents. Large spaces load and interact noticeably faster.
On administration: Space settings gained a dedicated User invitations tab, SCIM provisioning was corrected to
match the RFC (case-insensitive matching for filters and sorting, filtered emails[...].value PATCH paths, and inactive
accounts included in user searches), and the Dynamic Configuration UI now masks passwords when configuring collectors
from Cloud.
Netdata Cloud: Dashboards and Charts
New Dashboards — Beta. The custom dashboards experience was rebuilt: a substantially larger card library, ready-made layouts to start from, and the tools to manage dashboards at scale.
| Addition | What It Does |
|---|---|
| State Timeline card | Renders any single context as a state timeline — good for up/down, health and status over time |
| Heatmap charts | Heatmap rendering with caching, pairing with the Agent's new histogram range heatmaps |
| Alert count card | A stat card sourced from live alert counts |
| Node breakdown and inventory cards | Fleet composition and inventory as first-class dashboard components |
| Fleet map card | Geographic distribution, with configurable controls and persisted gauge thresholds |
| Playlists | Rotate through a set of dashboards automatically — for wall displays and NOC screens |
| Import and export | Move dashboards between spaces, or keep them in version control |
| Templates and layouts | Start from a ready-made layout — Infrastructure, Containers, Network, Applications, Operations or Nodes — instead of an empty canvas |
Two new aggregations landed on the query side: percentage-of-group aggregation, which shows each dimension as its
share of the group rather than an absolute value, and latest time aggregation, the Cloud counterpart to the
Agent's new latest time-grouping. Live-tail accuracy was fixed so live charts no longer trim to empty or show partial
tail windows, and the threshold at which dimensions collapse into OTHERS was raised tenfold, so high-cardinality charts
keep showing real dimension names for much longer.
Security Hardening
| Change | Impact |
|---|---|
| Dedicated MCP ACL with bearer-token enforcement | MCP endpoints are no longer reachable without a token |
| Anonymous MCP metadata limited | Signed-out callers see a reduced metadata surface |
| WebSocket decompression-bomb guard (CWE-409) | A malicious compressed frame can no longer exhaust memory |
ndsudo privilege-escalation check | Escalation attempts through ndsudo are rejected |
NETDATA_HOST_PREFIX validation | Validated in local_listeners, and format-checked to prevent % injection into printf strings |
/api/v3/settings behind HTTP_ACL_DASHBOARD | Connection allowlists are enforced; anonymous state-changing requests blocked |
| gRPC upgraded for CVE-2026-33186 | Removes a known vulnerability from the Go dependency tree |
kickstart.sh argument sanitization | Installer arguments that could reach a privileged context are validated or sanitized; claiming config is no longer written from user input as root, and uses a secure temporary file |
| CodeQL security-extended suite | Broader static-analysis coverage in CI |
End of Full Support for RHEL 7.x, CentOS 7.x, and Amazon Linux 2
The 2.11.x release series will be the last stable releases of the Netdata Agent to provide pre-built RPM packages for Red Hat Enterprise Linux 7.x, CentOS 7.x, Amazon Linux 2, and other compatible platforms. Officially, per our usual platform support policy, our support for RHEL 7.x and CentOS 7.x should have ended more than two years ago when Red Hat ended the Maintenance Support 2 support phase for the platform. We chose at that time to continue our support to a limited extent as we had a very large number of customers still using the platform and didn’t have a good way for them to switch to a different installation type. Today, however, we have decent support for switching installation types, we have a much lower percentage of users using the platform, and we’re starting to run into technical issues due to continuing support for a platform that is now more than a decade old. Given these factors and the upstream end of life for Amazon Linux 2 (which is causing similar technical issues) earlier this year, we have decided to finally end full support for these platforms.
Native RPM packages for these platforms will not be published for stable releases starting with version 2.12.0 of the Netdata Agent, and are expected to stop being published in nightly builds at some point within the next few weeks after the release of version 2.11.0. Existing packages will continue to be available for the foreseeable future, but will eventually be removed as well. New installs will automatically switch to using static builds at the same time that we stop publishing native RPM packages for nightly builds. Users with existing installs are encouraged to switch those systems to static builds as well, instructions on how to do so can be found here.
Local builds for these platforms should continue to work at least until the release of version 2.12.0, but after that point we will start removing the platform-specific support code for builds on RHEL 7.x, CentOS 7.x, and Amazon Linux 2.
This does not affect users using newer versions of Red Hat Enterprise Linux, CentOS, Amazon Linux, or equivalent platforms.
This does not affect users who are using our static builds or Docker images on these platforms. Those will continue to work as-is without any need for user intervention, and our static builds are the recommended approach for using Netdata on these platforms going forwards.
Acknowledgments
We would like to thank our dedicated, talented contributors that make up this amazing community. The time and expertise that you volunteer is essential to our success.
- @jmestwa-coder for bounding v2 journal header offsets before CRC reads and avoiding an
out-of-bounds read in
url_percent_escape_decode. - @DavidMarec for adding FreeBSD system-call monitoring and fixing a FreeBSD plugin counter size mismatch.
- @Kelpy2004 for fixing the health
sumlookup on incremental dimensions and/proc/interruptsname parsing. - @artem for fixing a stack buffer overflow in the macOS
mach_smicollector. - @arch-yunus for adding
nfdsmonitoring and fixing a file descriptor bug inapps.plugin. - @AJCxZ0 for silencing
curloutput innetdata-updater.sh. - @lavr for allowing
pg_ls_direxecute privilege for replication slot files in the PostgreSQL collector. - @wangtsingx for fixing a misleading error message on PEM decode failure in
x509check. - @Hashim1999164 for fixing the
python.dDEB dependency typo and a duplicatendsudoentry. - @Func86 for reducing the Docker image size by setting permission bits in the builder stage.
- @kkzhsh for fixing a
NetdataYAML.cmakecompilation error. - @Zhao73 for fixing documentation typos.
- OrbisAI Security for reporting and upgrading gRPC to address CVE-2026-33186.
Contributions
Collectors
- Added NetFlow/IPFIX/sFlow flow-analysis plugin with a four-tier local journal, Cisco ASA NSEL accounting, enrichment from cloud-provider IP ranges and BGP/RIPE RIS data, faceted search, and accounting charts (netflow.plugin). (#22111, #23201, #22665, #22703, #22719, #22925, #23241, #23246, #23313, @ktsaou)
- Added AWS CloudWatch collector with 47 service profiles, automatic resource discovery, multi-account support, resource tag filtering and labels, explicit targets and collection rules, exact metric selection, per-rule and per-selection query policies, declarative opt-in metrics, stock health alerts, and collector activity metrics (go.d/cloudwatch). (#22874, #22944, #22948, #22949, #23004, #23011, #23024, #23028, #23031, #23086, #23090, #23092, #23094, #23110, #23113, #23119, #23122, #23123, #23125, #23338, #23340, @ilyam8)
- Added SNMP L2/L3 topology engine and collector, discovering Layer 2 adjacencies from LLDP/FDB/STP, L3 subnet segments and adjacency, and OSPF and BGP adjacency links, with MAC OUI vendor lookup and reverse DNS enrichment (go.d/snmp_topology). (#22109, #22215, #22780, #22783, #22790, #22822, #22988, @ktsaou, @ilyam8)
- Added SNMP trap listener with profile-based trap ingestion, 800+ vendor trap profiles, enrichment, SIEM forwarding, and dynamic configuration support (go.d/snmp_traps). (#22652, #22693, #22702, #22849, @ktsaou)
- Added network-viewer and streaming topology functions with a documented topology v1 payload contract, container grouping in connection topology, and a role field on presentation actor types (topology). (#22110, #22217, #22496, #22601, @ktsaou)
- Added Cato Networks collector for SASE site, tunnel and traffic monitoring (go.d/cato_networks). (#22373, @ktsaou)
- Added Palo Alto PAN-OS collector (go.d/panos). (#22389, @ktsaou)
- Added Linux audit subsystem monitoring (debugfs.plugin). (#22077, @ktsaou)
- Added Active Directory monitoring to the Windows plugin (windows.plugin). (#22093, @thiagoftsm)
- Added SMB protocol monitoring to the Windows plugin (windows.plugin). (#22236, @thiagoftsm)
- Added system-call monitoring on FreeBSD (freebsd.plugin). (#23082, @DavidMarec)
- Added macOS hardware sensor and log collectors: GPU power, clock and temperatures, SMC and IOHID sensors and fans, power sources and thermal pressure, NVMe SMART, and macOS logs, with a
powermetricsfallback viandsudo, a cross-OSsensorsfunction, a shared temperature-histogram context, and bounded-cardinality process grouping forapps.pluginon hosts with high process churn (macos.plugin, macos-logs.plugin). Backported to 2.10.4. (#22475, #23085, @ktsaou) - Added the basis of a new eBPF Go plugin (ebpfgo.plugin). (#22469, @thiagoftsm)
- Overhauled the Prometheus collector: migrated to the V2 framework, added a relabeling engine with job-level and profile-owned metric relabeling, a promprofiles catalog, profile-driven app detection for chart contexts, profile-owned fallback types, a profile autogen selector, and a unified single-pass stream parser; also fixed summaries without quantiles and preserved typed counters whose names end in
info(go.d/prometheus). (#22640, #22651, #22660, #22664, #22668, #22682, #22694, #23016, #23255, #23405, #23410, #23419, #23441, @ilyam8) - Expanded SNMP device coverage from 229 to 273 profiles, with improvements for Cisco Catalyst, Cisco Nexus, Fortinet FortiGate and Check Point, plus BGP session monitoring and network-device licence monitoring (go.d/snmp). (#22122, #22170, #22190, #22191, #22192, #22193, @ktsaou)
- Added SNMPv3 context name support, structured mapping config with bitmask value mappings, a
ping_onlyoption, and reusable profile engine helpers (go.d/snmp). (#22175, #22177, #22180, #22181, #22200, @ktsaou, @ilyam8) - Added OpenTelemetry logs ingestion and query subsystem, enabled the otel-plugin on macOS, and added optional OTLP log export of accepted agent events (otel.plugin). (#22720, #23172, #23184, #23185, #23250, @vkalintiris)
- Extended the Network Viewer to Windows connections with SMB data and to FreeBSD, stabilized topology around self-listeners, and integrated the eBPF plugin with the network viewer (network-viewer, ebpf.plugin). (#22253, #22470, #22585, #22608, #22632, #22715, @thiagoftsm, @ktsaou)
- Added HTTP service discovery and single-instance collector framework support, with operational tests for HTTP, DynCfg and secretstore configurations (go.d). (#22256, #22752, #23317, #23324, #23327, #23333, #23349, @ilyam8)
- Added histogram buckets charted as range heatmaps, chart series aggregation, mutable chart labels, optional instance labels, and
context_namespacesupport for autogenerated chart contexts; fixed unlabeled contributor intersection and algorithm resolution from runtime metric kinds (go.d/chartengine). (#22642, #23013, #23087, #23341, #23414, #23424, #23425, @ilyam8, @ktsaou) - Migrated the vSphere collector to framework v2 and expanded its coverage, with topology overlay helpers (go.d/vsphere). (#22458, #22625, @ktsaou, @ilyam8)
- Added SQL Agent job execution metrics and transaction log monitoring to the MSSQL collector (go.d/mssql). (#22319, #22730, @ilyam8)
- Added an opt-in
uriencmodifier to percent-encode secret references, for credentials containing URI-reserved characters (go.d). (#22750, @ilyam8) - Added vnode-scoped metrics for Azure Monitor workloads (go.d/azure_monitor). (#22402, @ilyam8)
- Reworked and improved perflib on Windows, and added missing memory metrics and path translation (windows.plugin). (#22164, #22194, #23189, #23205, @thiagoftsm)
- Replaced the cgroups-eBPF shared-memory transport with netipc IPC, and added a cgroup-name Go helper (cgroups.plugin, ebpf.plugin). (#22221, #22685, @ktsaou)
- Made stock alert overrides removable without a restart (dyncfg/health). (#22511, @stelfrag)
- Added a
FUNCTION_DELprotocol command to plugins.d (plugins.d). (#21685, @ktsaou) - Added offline Function test modes for NetFlow and systemd journal (netflow.plugin, systemd-journal.plugin). (#22638, @ktsaou)
- Reconciled instance function availability and withdrew unavailable shared functions, so the dashboard no longer offers functions that cannot run (go.d). (#22870, #22871, #22853, @ilyam8)
- Ran collector dyncfg commands concurrently on per-key lanes and moved jobmgr dyncfg domains onto a claimed executor, reducing configuration latency (go.d). (#22964, #22966, #23299, @ilyam8)
- Added a collector taxonomy framework POC for integrations (integrations). (#22489, @ilyam8)
- Fixed SNMP topology reverse DNS warming, index-derived endpoints, a snapshot data race on device labels, capability actor type preservation, and Netgear switch topology discovery via LLDP/FDB/STP (go.d/snmp_topology). (#22366, #22371, #22714, #22826, #22839, @ktsaou, @ilyam8)
- Fixed streaming topology graph output and namespace-relative cgroup lookup for topology (topology). (#22432, #22727, @ktsaou)
- Fixed jobmgr lifecycle and configuration reconciliation, pre-activation retirement races, and stopping-rejection classification (go.d/jobmgr). (#23238, #23279, #23362, @ilyam8)
- Fixed the CloudWatch collector not being configurable from the dyncfg UI (go.d/cloudwatch). (#23314, @ilyam8)
- Fixed a scale factor for
arubaWiredTempSensorTemperatureand tolerance for invalid optional typed row values (go.d/snmp). (#22846, #23376, @ilyam8) - Fixed macOS
disk.utilpercent scaling, and stopped logging an error every cycle for macOS zombies (macos.plugin, apps.plugin). (#23292, #23297, @ktsaou, @vkalintiris) - Fixed macOS NVMe SMART collection: corrected the IOKit object lifecycle so interfaces and registry entries are released on every path, bounded discovery before device reads, admitted replacement devices after pruning, kept samples collected before a teardown error, and allowed the
IOService:/device paths thatsmartctlneeds throughndsudovia a purpose-built validator.ndsudois now also installed with native macOS builds, so SMART collection works when the Go and script plugins are disabled (macos.plugin, daemon). (#23445, #23447, @ktsaou) - Fixed the Cato collector to support Cato SDK v0.3.2 snapshots (go.d/cato_networks). (#23280, @ilyam8)
- Fixed function timeouts over the limit being clamped instead of returning 400 (go.d/functions). (#23258, @ilyam8)
- Prevented plugins from overwriting reserved dyncfg functions (plugins.d). (#23224, @stelfrag)
- Unified histogram bucket dimension names (go.d). (#23021, @ilyam8)
- Fixed a DBEngine retention accounting underflow (netflow.plugin). (#22914, @ktsaou)
- Fixed the debugfs audit capability service limit (debugfs.plugin). (#22831, @ktsaou)
- Fixed static journal facet filters and journal file access error handling and validation (systemd-journal.plugin). (#22310, #22456, @stelfrag, @ktsaou)
- Excluded
ND_REMAPPINGbookkeeping entries from the journal index, avoidedValueGuardInUsewhen indexing otel journals, and required absolute journal directory paths (journal-index, journal-log-writer). (#22513, #22621, #22771, @vkalintiris) - Fixed eBPF and cgroup shutdown handling, exit paths and log messages (ebpf.plugin, cgroups.plugin). (#22242, #22414, #22574, @stelfrag, @Copilot, @thiagoftsm)
- Fixed a cgroup-name timeout environment race (cgroups.plugin). (#23156, @ktsaou)
- Fixed ZFS bugs in the diskspace plugin (diskspace.plugin). (#22188, @thiagoftsm)
- Fixed non-Hard-drive entries being parsed as physical disks (go.d/adaptecraid). (#22355, @ilyam8)
- Fixed handling of SSIDs containing whitespace (go.d/ap). (#22472, @Copilot)
- Fixed
/proc/interruptsname parsing (proc.plugin). (#22556, @Kelpy2004) - Allowed
pg_ls_direxecute privilege for replication slot files (go.d/postgres). (#22488, @lavr) - Fixed a misleading error message on PEM decode failure (go.d/x509check). (#23134, @wangtsingx)
- Fixed agent compilation on FreeBSD (freebsd.plugin). (#23221, @stelfrag)
- Fixed the systemd journal plugin OTEL log directory discovery, then removed OTel journal discovery from it entirely now that the otel-plugin owns that path (systemd-journal.plugin). (#22569, #22572, @stelfrag)
- Also fixed in the 2.10.x patch line and included here:
nvidia_smitemperature and power collection with driver 580 XML variants, macOSmach_smistack buffer overflow,apps.pluginfile-descriptor accounting with newnfdsmonitoring, FreeBSD counter size mismatches andfreebsd_ipfw/claim off-by-one,freeipmi.pluginwatchdog underflow at low uptime,systemd-journal.pluginmemory retention after queries, eBPF PID accounting shared-memory pool leak and 100% CPU spin, eBPF FD PID map iteration, pluginsd cleanup race and slot bounds check, diskspace mountpoint initialization, SNMPsnmpEngineTimeuptime source andMaxOIDsdefault, dyncfg transient 503s and handoff behavior,powerstoreextra_details, v2 journal header offset bounds before CRC reads, and thefail2bansocket path move intondsudo. (#22179, #22183, #22201, #22203, #22207, #22231, #22232, #22291, #22298, #22436, #22447, #22490, #22553, #22598, #22710, #22666, #22745, #23044, #23047, #23089)
- Rebuilt the go.d job manager around a single-owner command kernel, routing scheduling and commands through an executor seam, running blocking collector work as supervised effects, moving effect lifecycle routing into a transition kernel, and pulling vnode snapshots at runtime boundaries (go.d/jobmgr). (#22951, #22952, #22979, #22986, #22990, #23203, @ilyam8)
- Restructured the SNMP topology collector: extracted the graph model, shape package, v1 renderer, enrichment and Function packages, typed internal details, migrated it to V2 single-instance, and removed dead code paths (go.d/snmp_topology). (#22611, #22614, #22753, #22762, #22773, #22774, #22775, #22776, #22791, #22792, #22795, #22796, #22797, #22798, #22801, #22802, #22803, #22804, #22806, #22807, #22827, #22829, #22832, #22833, #22834, @ilyam8)
- Restructured the SNMP traps collector to establish ownership boundaries: internalized the receiver, profile catalog, profile metric runtime and output backends, isolated the job runtime and trap dedup/telemetry, and reduced the profile surface (go.d/snmp_traps). (#23358, #23359, #23360, #23361, #23363, #23375, #23377, #23387, #23389, @ilyam8)
- Reworked the metrix metric layer with a transactional, bounded descriptor lifecycle, split source layout by ownership, and eliminated repeated multiscope flattening and structured flatten allocations (go.d/metrix). (#23053, #23075, #23242, #23278, @ilyam8, @ktsaou)
- Reworked go.d function declaration and publication: split the declaration API, replaced
AgentWidewithMethodScope, funnelled reconcile through the job manager, and bound single-instance functions to the runtime job (go.d). (#22767, #22856, #22857, #22868, #22869, @ilyam8) - Shared reverse DNS and SNMP state across SNMP collectors, and shared ping probing between the ping and snmp collectors (go.d/snmp). (#22189, #22770, #23385, @ilyam8)
- Skipped disabled lifecycle cap work in the chart engine (go.d/chartengine). (#23282, @ktsaou)
- Migrated the MongoDB Go driver to v2 and Docker API usage to Moby modules (go.d/mongodb, go.d). (#22738, #22742, @ilyam8)
- Updated the vendored systemd journal SDK through 0.7.8 and the vendored NetIPC library (netflow.plugin, libnetdata). (#22649, #22680, #22713, #22729, #22731, #22785, #22859, #22936, #22993, #23033, #23093, @ktsaou)
- Added test coverage for the job manager, dyncfg, SNMP topology scenarios, Prometheus V1 compatibility manifests, Azure Monitor schema behavior, and chart series (go.d). (#22641, #22794, #22843, #22851, #22950, #22991, #23316, #23319, #23320, #23328, #23346, @ilyam8)
- Removed the Go
sensorscollector, superseded since v2.2.0 by the C libsensors module indebugfs.plugin(go.d/sensors). (#23237, @ilyam8) - Rendered non-finite summary quantile values as a gap, and let template dimensions inherit float from the series metric meta (go.d/framework). (#22643, #22681, @ilyam8)
- Adjusted vnodes dyncfg availability and split dyncfg job-name validation per domain (go.d). (#22247, #22415, @ilyam8, @stelfrag)
- Improved service rules description position in service discovery (go.d/sd). (#22413, @ilyam8)
- Added
charttplGroup.Clone()andSpec.MarshalTemplate()(go.d). (#22882, @ilyam8) - Improved journal file handling and logging in DBENGINE (dbengine). (#22152, @stelfrag)
- Prepared the groundwork for virtual logs functions (systemd-journal.plugin). (#22584, @ktsaou)
Packaging/Installation
- Migrated RPM package builds from
netdata.spec.into CPack, and built RPM packages through CPack in CI (packaging). (#23194, #23290, @vkalintiris) - Enabled the netflow plugin and the scripts.d plugin in static and Docker builds (build). (#22852, #22892, @ilyam8)
- Replaced the vendored SQLite amalgamation with build-time generation, and bumped SQLite to 3.53.3 (build). (#21779, #23218, @vkalintiris, @stelfrag)
- Raised the minimum Go version to 1.26.2 and updated the Go toolchain (build). (#23204, #23210, #23215, @ilyam8, @thiagoftsm)
- Moved the Rust workspace to edition 2024 with MSRV 1.91, centralized workspace dependencies, and kept line tables instead of full debuginfo (build). (#22907, #23148, @ilyam8, @vkalintiris)
- Added an
ENABLE_ND_MCPcmake flag to build nd-mcp independently of go.d.plugin (build). (#22313, @Copilot) - Stopped static packages shipping builder runtime state, repaired otel directory ownership, and removed obsolete otel-signal-viewer artifacts on static upgrade (packaging). (#23251, #23440, @vkalintiris)
- Removed Fedora 42 and openSUSE Leap 15.6 from CI and package builds, and synced CI with the officially supported Alpine versions (CI). (#22211, #22239, #22240, @Ferroin)
- Correctly handled EPEL on RHEL 7, and preserved
PWDwhile ensuring the temporary directory is set inkickstart.sh(packaging). (#23222, #23235, @Ferroin) - Explicitly triggered
systemctl daemon-reloadfrom RPM packages when needed, since some RPM-based systems have no file watcher to queue it (packaging). (#23300, @Ferroin) - Hardened
kickstart.sh: arguments that could be evaluated in a privileged context are now strictly validated where possible and sanitized otherwise, claiming configuration is no longer written from user input while running as root, and it is written through a secure temporary file (packaging). (#23223, @Ferroin) - Improved error handling in the kickstart script when fetching files, and bumped the repository config package version it uses (packaging). (#22420, #22424, @Ferroin)
- Made warnings and fatal errors more visible during installation (packaging). (#23252, @Ferroin)
- Added a Markdown copy of the Windows package EULA (packaging). (#22421, @Ferroin)
- Updated the bundled static curl to 8.20.0 (build). (#22473, @Copilot)
- Made libnetdata standalone-linkable (libnetdata). (#22528, @vkalintiris)
- Fixed the IBM MQ FetchContent check breaking incremental rebuilds, and assorted CI fixes for IBM MQ library handling (build, CI). (#22223, #22491, @ktsaou, @Ferroin)
- Fixed the
python.dDEB dependency typo and a duplicatendsudoentry (packaging). (#23289, @Hashim1999164) - Fixed a
NetdataYAML.cmakecompilation error (build). (#21295, @kkzhsh) - Reduced the Docker image size by setting permission bits in the builder stage (packaging). (#21902, @Func86)
- Corrected the Rust macro name in the spec
_have_rustgate (packaging). (#22515, @vkalintiris) - Excluded
go.modandgo.sumfrom the packaging workflow, disabled compression for GHA artifact uploads of already-compressed files, forced the updater to actually update in CI checks, and added ago fixcheck plus a reworked SNMP fixture workflow covering topology engine tests and assorted CI updates and fixes (CI). (#22172, #22426, #22427, #22441, #22661, #22816, #23272, #23422, @ilyam8, @Ferroin, @stelfrag) - Enabled the CodeQL security-extended suite, aligned its ignore paths, and filtered build results out of CodeQL analysis (CI). (#22245, #23336, @ktsaou, @stelfrag)
- Added the SQLite version to build details and the startup log message (daemon). (#22208, @stelfrag)
- Also fixed in the 2.10.x patch line and included here: Windows MSI installer issues, claiming only when both token and rooms are provided, the search for Visual Studio tooling across multiple versions,
netdata-updaterfetch error handling, and silencedcurloutput. (#22422, #22639, #22723, #22751, #22754)
Documentation
- Added a Network Performance Monitoring documentation section with an SNMP integration catalog, capability overviews, an Integrations submenu, screenshots, and corrected catalog brand icons and SNMP-trap tiles (docs/npm). (#22840, #22854, #22860, #22863, @ktsaou, @shyamvalsan)
…