Doing more with less remains an ongoing challenge for IT execs. Making sure everything keeps humming along to meet service-level agreements can be challenging for resource-stretched IT departments. For all but the smallest shops, effective monitoring requires tools that provide a meta view of the entire infrastructure with drill-down capabilities.
provides an attractive alternative to more costly commercial products, but can open source products deliver enterprise-grade results?
To answer this question we tested four open source products: OpenNMS, Pandora FMS, NetXMS and Zabbix. All four have solid user bases and recent updates. Our focus was on ease of installation, management tools and interface and, of course, the monitoring capabilities of each product, agent vs. agent-less, auto-discovery, etc.
We tested two products, OpenNMS and NetXMS, on Windows, and the other two, Pandora FMS and Zabbix, on Linux.
It is worth noting that each time we review a new batch of network monitoring tools we see major improvements across the board. Vendors are beginning to tap in to customers’ monitoring needs in a more management-focused way. GUIs are finally becoming the norm. Coders don’t like them, but they usually aren’t in the ranks of IT management staff that needs to make rapid decisions to meet SLAs.
+ MORE PRODUCT REVIEWS: What IT admins love/hate about 8 top network monitoring tools +
All four products were surprisingly good. Overall we liked Pandora FMS for its ease of installation and modern user interface, with easy to read information, a plus when using a smaller device like a tablet. In general, configuration was easier and more intuitive with Pandora than the other contenders, something that is sure to appeal to busy system administrators.
NetXMS came in a close second with similar positives as the winner; a nice user interface, easy to configure rules and a solid user manual. It was not the winner because some of the navigation was less than logical and the ‘save’ feature needs improvement.
So, are these products enterprise-ready? Overall, we found all four products suitable for enterprise use in small-to-midsize environments. However, this limitation is expressed only because we didn’t perform high capacity or geographically distributed tests.
Each of the four products tested offers commercial options, but these vary widely. For example, NetXMS and Zabbix are available only in one open source version with optional paid support plans. OpenNMS is distributed in two different versions, both based on the same open source code, with the commercial version offering LTS (long term support).
PandoraFMS offers several commercial versions that contain additional features and support for higher capacity environments. To determine suitability for large organizations or highly complex environments, it’s best to consult the vendor and request a commercial evaluation. (See .)
Here are the individual reviews:
Net results
| Product | NetXMS | OpenNMS | Zabbix | Pandora FMS |
|---|---|---|---|---|
| Pros | Easy installation, excellent reporting, lightweight agents | Cross-platform capable, lots of available monitoring plugins, scalability | Clean user interface, good granularity in setting up rules | Intuitive interface, easy to configure with excellent granularity, solid notification functionality |
| Cons | Some of the navigation was not intuitive, such as the save feature | User interface could use improvement, graph functionality can be slow to render | Some of the detailed configuration cumbersome, including setting up agents | Reporting features and navigation leave room for some improvement |
NetXMS
NetXMS is a network monitoring and management tool that runs on Windows and Linux. We installed version 2.06 in a Windows server environment. This turned out to be an easy install, using a step-by-step wizard with just a few user inputs needed. Once installed, the NetXMS server runs as a service and provides a desktop management console, which the vendor calls the Workbench.
The Workbench is logically organized with a Windows Explorer type layout; a navigation tree to the left and detailed information in a larger right-hand panel. It also has a comprehensive top menu with more than 50 choices. It can be organized into different tabbed views or dashboards, providing an excellent level of customization.
Network monitoring with NetXMS requires SNMP or NetXMS proprietary agents. First we ran auto-discovery of our test network without agents and this worked fairly well, although it took quite a while to pick up nodes and some nodes were not discovered. However, we were able to add these manually from the Workbench.
With our network nodes all added to the Workbench, we set out to add a few data collection points. The first one was a simple network interface monitor to see how much traffic was passing through. Then we set a CPU alarm on one of our servers to notify us when utilization exceeded a certain threshold. Both of these were straightforward to configure using the administrator’s guide. By using the MIB explorer, you can ‘walk through’ the MIB (management information base) to locate various object identifiers that can be used to create data collection items.
After creating and testing a couple of basic rules, we decided to deploy NetXMS agents to a couple of nodes on our network. The agents are available for most platforms, including generic x86 and 64-bit versions for both Linux and Windows. There are some benefits to using the NetXMS agents, one is that traffic between agents and the server can be encrypted. Other benefits include centralized configuration and also the ability to execute commands on managed systems. Adding SNMP and NetXMS agents upped our game considerably and we got a more in-depth look at each node, plus we were able to quickly add multiple pre-defined data collection parameters.
When an alarm threshold is reached, NetXMS provides multiple courses of action. For instance, an email or text message can be sent to one or several recipients. You can also automatically have a command or script executed on the node or the management server, providing unattended failover options.
NetXMS provides a mobile console for administrators on the go. The mobile app is currently only available for Android and the features are mostly limited to read-only tasks. However, it does provide alarm notification with the ability to acknowledge and resolve. There is also a mobile agent for Android devices that allows for reporting static information about make and model in addition to monitoring of a few dynamic parameters, such as battery life and last data activity.
In addition to solid on-screen reporting features, including various types of graphs and geo maps, NetXMS integrates with the Jasper reporting engine that provides PDF report exports. There is a user guide in addition to a more comprehensive (more than 300 page) administrator’s guide.
There is lot to like about NetXMS, ease of installation is always important in our book. Configuration is mostly straightforward, but it is somewhat easy to get lost in some of the menus, especially when trying to navigate the aforementioned MIB explorer. On a few occasions we encountered issues with our changes not being saved. It is not readily apparent when something is automatically saved or when you need to click the tiny ‘disk icon’. The user interface is intuitive, the footprint of the server and the agents is relatively lightweight, and we measured about 2MB of memory use on average for the agents.
OpenNMS
We installed OpenNMS 18.0.1 on Windows Server 2012. OpenNMS runs on Java (version 1.8 or higher) but can also be installed on Linux and OS X systems. Although the vendor warned that the Windows install was a bit tricky compared to Linux, we actually found the opposite to be true. The Windows install consisted of 1) installing the latest Java SDK; 2) setting the JAVA_HOME path (important); 3) installing PostgreSQL), and running the OpenNMS installation script.
We then started the service with a vendor-provided batch file, which worked flawlessly. After the service was started we connected via web interface and right away began finding and monitoring network nodes. No errors, no problems. The CentOS 7 Linux install, on the other hand, was eventually abandoned after we got entangled in a maze of database and other configuration dead ends, even after carefully following the installation instructions.
Up and running on Windows, we found the management interface layout clean and logical with the home screen showing a meta summary of network availability along with notifications about outages and other pending issues. No client agents are needed to run basic monitoring tasks on discovered or manually-added nodes. To get started you need to either manually add one or multiple ‘nodes’ to monitor or you can use the auto-discovery feature to find ‘nodes’ on the network. We started by configuring the auto-discovery to find servers on our local test network and a subnet at a remote location.
OpenNMS is event-driven and events are displayed on an easy to read dashboard-type page. The dashboard provides a summary overview of the state of the infrastructure by categories such as Web, database and DNS servers. At a glance you can see active outages together with availability percentages. The dashboard allows you to drill down to the detail level to see current or recent outages, depending on the type of service along with the type of monitoring performed. This makes for easier troubleshooting and the ability to identify bottlenecks, persistent issues vs. one-offs.
On our local-area test network it did not take too long to discover the nodes, but at our remote data center location we needed to make some firewall tweaks in order to allow traffic to and from OpenNMS. Several of our servers run services that were automatically discovered, for instance DNS and HTTP services were detected and added to the monitoring. The auto-discovery is very granular so nodes on a network can easily be included or excluded from discovery. This flexibility provides for easy addition or removal of nodes as well.
Data collection and monitoring can range from simple ping commands to more advanced methods, such as SNMP traps, JMX, WMI and Syslog events. A lot of the configuration is stored in XML files, some of which can be rather lengthy. Remote ‘pollers’ (agents) can also be deployed to offsite locations to keep track of infrastructure availability.
The ‘poller’ can be installed from a URL on the OpenNMS server using a short wizard with a few prompts for basic information such as the OpenNMS server IP and user information. The topology map was useful, although a bit sluggish. To be fair, this might have been due to our somewhat memory-constrained test server. The geographical map is faster and for organizations with a distributed infrastructure, this feature is definitely helpful.
In addition to on-screen alerts, OpenNMS can be configured to send notices via SMS or email along with integration with existing third-party trouble-ticket systems or custom solutions. We liked the robust reporting feature using Jasper Reports that provides both pre-built and custom reporting options, with the ability to export to common formats such as PDF and CSV.
The built-in search feature makes it easy to search on a variety of parameters such as name, IP, MAC and our favorite, the ability to search by ‘service provided’, such as ‘HTTP’ or ‘DNS’. There is also an asset search feature that allows you to seek out items such as ‘laptop’, ‘server’ or ‘telephony’. We also found it helpful that several of the pages have a quick explanation of terms and features on the page itself. For instance, a short narrative on the reporting page explains each of the report types.
Support is available through several resources (discussion groups, Wiki online documentation and IRC). There is also commercial support options available, at either $19,995 for ‘prime’ support and $49,995 for ‘ultra’ support.
Pandora FMS
We installed Version 6.0 SP3 on a CentOS Linux server. This was an easy install from a live image (note to vendors: live images should be the industry standard). After loading the web-based interface, we were greeted by ‘Pandorin, the annoying assistant’, (the vendor’s description, not ours). Since the days of the old MS Office assistant we’ve not been too keen on such ‘helpers’, so we decided to go it alone and sent Pandorin packing.
Overall the Web interface was modern and uncluttered, with easy to read information. The welcome screen provides a quick overview of the status of the network with lists of any open alarms, the number of agents deployed and a list of recent tasks performed in the console.
To start out, we wanted Pandora FMS to map out our test network. After consulting the user manual, we found out that creating a monitoring template was the best starting point. You can create custom templates with your own monitoring choices and decide which template to apply. With a basic template in hand, we created what they call a ‘recon task’.
As the name implies, it scouts the network for devices that fit a certain set of criteria, this can be, for instance, all Linux servers running on a certain subnet. Once these devices are found, it will apply the monitoring template for those devices, in our case a small group of Windows servers.
Our first template was configured to report some basic SNMP information along with static information like BIOS and Windows version. Pandora FMS can collect information by using basic TCP probes, SNMP, WMI or by deploying its own agents, which are available for most Linux and Windows operating systems.
The recon tasks are supposed to run automatically, but since ours did not appear at first to cooperate, we ran it manually against our modest-size test network. This completed in just a minute or two. The default network view is a tactical dashboard view which was well organized with green, orange and red color codes to indicate the level of severity of any problems.
Other views include a group view and a tree view that both show operation by type of node (server, workstation, router etc). From most of the top-level displays you can drill down to view more detailed information about a node.
Custom agents are available for Linux, Android and Windows. These are installed with an executable for Windows and the appropriate install files for various flavors of Linux. We installed both a workstation and a server agent, which were quick to install. Except for adding the Pandora FMS server IP address, there were no other setup options.
Once installed, we added the two nodes to the console and applied various modules to start collecting data. As soon as these were saved, we could see the agent reporting in, alerting us to potential problems, such as the HTTP service not running on one of our servers. At this point the agent also started collecting performance data such as CPU, memory and network usage statistics.
Next we created a couple of alerts that would send us an email when certain thresholds were met. For testing purposes we created an alert that would tell us if our workstation CPU load exceeded 50%, this was easily triggered and we received an email with detail about the alert. In addition to sending emails, the alert feature can take actions such as restarting the agent and logging the events to the database. Custom alert scripts can also be created using a built-in wizard. Remote configuration via agent is not available in the open source version.
The on-screen reporting was generally adequate, although we wish there were some additional external reporting options. The on-screen HTML reports can be printed and there is an XML export that provides some raw data that could be processed using third-party tools. We did like the custom reporting feature with thresholds for SLAs. We note that the commercial version of Pandora FMS has additional reporting features, including a more powerful report builder and the ability to export to PDF.
For mobile monitoring there is a FMS console app available for both Android and iOS. The search feature is nice. Has some nice network tools built-in like traceroute and we especially liked the ability to check to see if SNMP for a certain community was available on a node. The online documentation is good, and we liked how it is organized into compact quick guides where you don’t have to wade through 500 pages just to figure out how to configure one basic feature.
We found Pandora FMS to be a mature product with a lot of nice features. From a capacity standpoint, the vendor claims to have customers who monitor upwards of 10,000 nodes, although we did not put this claim to the test. The granularity of what can be monitored is very good. After a few days of use we found the search feature to be helpful in navigating. One minor gripe we have is that the left navigation bar only shows icons and not a mouse over tip tool, which is used extensively elsewhere. Right-clicking does provide additional dropdowns.
For additional features and support, there are several commercial versions and offerings available with starting prices around $2,750.
Zabbix
We installed Zabbix Version 3.2 on an Ubuntu server with a MySQL backend database. The server is available for several Linux flavors, Mac OS X, but not Windows. Agents are available for most versions of common operating systems, e.g. Linux, Windows and Mac OS X.
In addition to providing its own data collection agents, Zabbix employs traditional monitoring methods such as SNMP and availability checking using TCP/IP and other protocols such as JMX and IPMI.
+ MORE: +
Although Zabbix can be managed at the command prompt, we predictably chose the browser-based front end. After logging in, a dashboard displays some of the common items you would expect — overall system status, open alarms, pending tasks and graphs. To customize the dashboard you can drag and drop the various sections around on the screen and also add/remove other sections depending on what is monitored. The layout was efficient with most of the navigation at the top and the rest of the screen available for monitoring details.
To get things rolling we decided to manually add a ‘host’ as Zabbix refers to network entities that are monitored. This is accomplished from a configuration page where only a bare minimum is needed to get started. You basically just add the IP address or name of the host, the group you wish to add the host to (this is required) and you’re set. You can also configure the method to use; agent, SNMP, JMX or IPMI, all with pre-defined fields for entering the information applicable to each. With our host set up for SNMP, we needed to create an ‘item’.
An item is essentially a single metric, such as CPU load, to be monitored. Items are added from a separate configuration page that provides detailed information to be entered, depending on the type of item being added. Our first item was just a simple ICMP ping to see if one of our servers was responding (it was).
In order to get more granularity in our data collection, we decided to install a couple of agents. As previously mentioned, agents are available for both Linux and Windows. Similar to agents for the other products in the test, the Zabbix agent runs like a service. A configuration file is needed to launch the agent, but our installation package did not include one (even if the user manual says it is supposed to).
We eventually located one online. It should also be mentioned that there are third-party installers available that create the needed configuration file. The configuration file includes a number of parameters that can be tweaked. To get started only a few of these need to be modified, such as the Zabbix server IP address and the name of the host to be monitored.
Finally, we ran a network discovery to see which hosts it would discover. In order to run a discovery, we needed to specify what to check for, such as SNMP or Zabbix agents broadly or specific services such as FTP, HTTP and SMTP. The server was able to locate almost 100 different hosts and services running on our test network. There is good granularity in setting up rules, regardless of method.
Zabbix has good built-in reporting capabilities for on-screen reporting. The reporting views are customizable and flexible, but we did not find any way to print reports to a PDF or export data to view in a third-party viewer. In addition to displaying any network issues on-screen, Zabbix can send problem notifications via several predefined methods such as email or text message. Administrators can also create custom scripts or use third-party methods such as Jabber for notification.
Zabbix is a solid network monitoring product with several features we like, including the detailed configuration templates and customizable dashboards. The agents have a small footprint; we measured about 1MB of memory usage and less than 1% of CPU utilization. One item of particular interest for VMware environments is that Zabbix provides a variety of VMware parameters like cluster status and hypervisor performance metrics.
We liked the online user manual, which can be saved as a PDF for offline use. Paid technical support options are available, ranging from a basic option to an all-inclusive 24/7 coverage plan.
Summary
The suitability of one product over another is dependent upon many variables (such as platform and resources) that vary widely between organizations. With open source, good management practices are a must. It is important to do a little background research on the vendor. If you have a crack coder or two, ask them to review the source code, and if possible compile the source code yourself. This is the safest approach. If the vendor warns against this, it is probably a red flag.
The judicious use of open source products can save thousands of dollars, but open source offerings typically lack vendor support and may be prone to frequent upgrades which could disrupt operations. Community support may be patchy or slow to respond. Some organizations will be better served by opting for a paid subscription with ready access to reliable customer service.
Perschke is a web and database developer with 15+ years of industry experience. You can reach her atsusan@arcseven.com.




