User Guide Functional Overview Requirements Architecture System Installation NetEye Additional Components Installation Setup The neteye Command Director NetEye Self Monitoring Tornado Business Service Monitoring IT Operation Analytics - Telemetry Geo Maps NagVis Audit Log Shutdown Manager Reporting ntopng Visual Monitoring with Alyvix Elastic Stack IT Operations (Command Orchestrator) Asset Management Service Level Management Cyber Threat Intelligence - SATAYO NetEye.Cloud Solution Monitoring Asset Management SOC System Administrator SOC Attacker Centric Cyber Threat Intelligence - SATAYO NetEye Update & Upgrade Backup and Restore How To NetEye Extension Packs Troubleshooting Security Policy Glossary
module icon Functional Overview
Introduction to NetEye Monitoring Business Service Monitoring IT Operation Analytics Visualization Network Visibility Log Management & Security Orchestrated Datacenter Shutdown Application Performance Monitoring User Experience Service Management Service Level Management & Reporting
Functional Overview Requirements Architecture System Installation NetEye Additional Components Installation Setup The neteye Command Introduction to NetEye Monitoring Business Service Monitoring IT Operation Analytics Visualization Network Visibility Log Management & Security Orchestrated Datacenter Shutdown Application Performance Monitoring User Experience Service Management Service Level Management & Reporting Requirements for a Node Cluster Requirements and Best Practices NetEye Satellite Requirements TCP and UDP Ports Requirements Additional Software Installation Introduction Single Node Cluster NetEye Master Master-Satellite Architecture Underlying Operating System Acquiring NetEye ISO Image Installing ISO Image Single Nodes and Satellites Cluster Nodes Configuration of Tenants Satellite Nodes Only Nodes behind a Proxy Additional NetEye Components Satellites Nodes only Verify if a module is running correctly Accessing the New Module Cluster Satellite Security Backup and Restore Identity and Access Management External Identity Providers Configure federated LDAP/AD Emergency Reset of Keycloak Configuration Advanced Configuration Roles Single Page Application in NetEye Module Permissions and Single Sign On Within NetEye Importing User Federation Groups inside another Group Importing OIDC IdP Groups inside another Group Resources Tuning Advanced Topics Basic Concepts & Usage Advanced Topics Monitoring Environment Templates Monitored Objects Import Monitored Objects Data Fields Deployment Icinga 2 Agents Configuration Baskets Dashboard Monitoring Status Integration with Elasticsearch VMD Permissions Notifications Jobs API Configuring Icinga Monitoring Retention Policy NetEye Self Monitoring Concepts Collecting Events Add a Filter Node WHERE Conditions Iterating over Event fields Retrieving Payload of an Event Extract Variables Create a Rule Tornado Actions Test your Configuration Export and Import Configuration Example Under the hood Development Retry Strategy Configuration Thread Pool Configuration API Reference Configure a new Business Process Create your first Business Process Node Importing Processes Operators The ITOA Module Configuring User Permissions Telegraf Metrics in NetEye Telegraf Configuration Telegraf on Monitored Hosts Visualizing Dashboards Customizing Grafana The NetEye Geo Map Visualizer Map Viewer Configuring Geo Maps NagVis Audit Log Overview Shutdown Manager user Shutdown Manager GUI Shutdown Commands Advanced Topics Overview User Role Management Cube Use Cases ntopng and NetEye Integration Permissions Retention Advanced Topics Overview User Roles Nodes RDP Client Building Tools Editor: Interface Overview Editor: Script Building Editor: Managing Scripts Designer: Interface Overview Designer: Interface Options Designer: Component Tree Selector: Interface Overview Test Case Management Dashboard Use Cases Overview Architecture Authorization Kibana Elasticsearch Cluster Elasticsearch Configuration Replicas on a Single Node Elasticsearch Performance tuning Overview Enabling El Proxy Sending custom logs to El Proxy Configuration files Commands Elasticsearch Templates and Retentions El Proxy DLQ Blockchain Verification Handling Blockchain Corruptions El Proxy Metrics El Proxy Security El Proxy REST Endpoints Agents Logstash Rsyslog Elastic APM Elastic RUM Elastic XDR Overview Authorization in the Command Orchestrator Module Configuring CLI Commands Executing Commands Overview Permissions Installation Single Tenancy Multitenancy Communication through a Satellite Asset collection methods Display asset information in monitoring host page Overview Customers Availability Event Adjustment Outages Resource Advanced Topics Introduction The Intelligence We Produce Mitre Attack Coverage Getting Started Settings SATAYO Items Intelligence Requirements Managed Service Request Form FAQ Changelog SATAYO Community NetEye.Cloud as a SaaS solution NetEye.Cloud Subscription Authentication via IdP Authentication via Microsoft Entra ID Authorization Monitoring with NetEye.Cloud Monitoring Environment Business Service Monitoring VMD Asset Management in Neteye.Cloud Automatic Inventory Collection Software & License Management Contract & Supplier Management Change & Lifecycle Management SOC System Administrator (AdS) Access to NetEye and Elastic Elastic Dashboards Elastic Discover Elastic Alerts Elastic Rules Introduction to SOC Attacker Centric Service Description NetEye SIEM About SATAYO Threat Intelligence and Security Operations How SATAYO works MITRE ATT&CK Coverage SATAYO Findings SaaS & Managed Mode Before you start Update Procedure Single Node Upgrade from 4.48 to 4.49 Cluster Upgrade from 4.48 to 4.49 Satellite Upgrade from 4.48 to 4.49 DPO machine Upgrade from 4.48 to 4.49 Create a mirror of the RPM repository Sprint Releases Feature Troubleshooting Backup and Restore Tornado Networking Service Management - Incident Response IT Operation Analytics - Telemetry Identity Provider (IdP) Configuration NetEye Cluster on Microsoft Azure NetEye Cluster on AWS Introduction to NEP Getting Started with NEPs Online Resources Obtaining NEP Insights Available Packages Advanced Topics Upgrade to NetEye 4.48 Setup Configure swappiness Restarting Stopped Services Enable stack traces in web UI How to access standard logs Director does not deploy when services assigned to a host have the same name How to enable/disable debug logging Activate Debug Logging for Tornado Modules/Services do not start Sync Rule fails when trying to recreate Icinga object How to disable InfluxDB query logging Managing an Elasticsearch Cluster with a Full Disk Some logs are not indexed in Elasticsearch Elasticsearch is not functioning properly Reporting: Error when opening a report Debugging Logstash file input filter Bugfix Policy Reporting Vulnerabilities Glossary

Introduction to NetEye

Welcome to the NetEye product documentation.

The structure of this user guide follows that of the various modules provided in the NetEye distribution, and contains both conceptual and practical information on how to use the NetEye system for many purposes you’ll find in the Introduction.

Product Overview

NetEye is a comprehensive solution for unified monitoring of your network and infrastructure. Based on Open Source tools, its functionalities allow monitoring of disparate resources: IoT and IIoT devices, remote infrastructure, business services, and company assets.

The entire solution is licensed under open source licenses, with the GPLv3 Open Source License being the most used. Continuous improvements, coming from both the community and from Würth IT Italy, are integrated into NetEye to provide added business value to widely-used open source projects.

Real-time dashboards built with the data collected over time, reporting solutions, a powerful tool for complex event management and log analysis, and network traffic analysis complement NetEye’s monitoring features. A deeper description of the NetEye features can be found in the upcoming sections.

NetEye builds around Icinga and Icinga Web 2. Most concepts and setups valid for the latter are also valid in NetEye. Icinga’s modular architecture allows you to reuse all of its modules within NetEye, while NetEye’s team continuously develops new modules and seamlessly integrates them within the existing infrastructure.

Intended Use

NetEye is a platform designed to perform a wide range of monitoring activities by means of the software natively developed by the NetEye team, or software integrated with the system. A set of modules available within NetEye provides a full spectrum of monitoring services, depending on your business needs.

Below, you will find a list of NetEye’s core functionalities grouped in categories, which will help you construct your monitoring solution with NetEye based on your needs.

You can learn more about the capabilities of NetEye in dedicated chapters of NetEye’s Functional Overview below.

Releases and Latest News

NetEye’s development cycle lasts two months. At the beginning of each even month, a new NetEye release is published and made available for installation. After the release has taken place, it is referred to as the Current NetEye release, i.e. the latest stable release of a product available to be installed by a customer.

In the NetEye Guide, the ‘current’ label indicates the version of the user guide that corresponds to the current NetEye release.

In turn, the Next version corresponds to the upcoming version of NetEye, which is currently in development. The development cycle ends with a feature freeze two weeks prior to the official NetEye release, which gives us the opportunity to test out the scope.

Within this two-week period, the development of an even newer NetEye version starts, which is referred to as Alpha. Hence, the appearance of an ‘Alpha’ version in the user guide indicates that the development cycle for a new NetEye version has started.

A list of all the new and changed functionalities in NetEye is compiled for each new public release; it can be found on NetEye’s blog, in the release notes category.

Moreover, the NetEye blog also features a series of posts about bug fixes, published as soon as a bug has been corrected and the fix has been released. Each post contains an explanation of the bug and, most importantly, the list of package(s) that contain the fix.

NetEye Core & Components

All the functionality provided by NetEye is delivered to the user within NetEye Modules.

The Modules that are shipped with the standard NetEye image constitute the |ne| Core. All other Modules are called |ne| Components and can be installed on demand. More information can be found in the section Additional NetEye Components.

|ne| Core

NetEye is a flexible solution that allows you to build your own monitoring experience based on the preferred functionality from the scope the product has to offer.

Since all NetEye functionality is delivered to the user within NetEye Modules, you can choose between acquiring the standard NetEye image, or customize your experience with extended functionalities.

|ne| Core is the set of most commonly used functionalities offered by the platform, including monitoring, visualization (with dashboards and maps), configuration, reporting, and event handling.

Follow |ne| installation guide to start exploring the NetEye Core functionality. You can also learn more about the modules that build the Core in the Core Modules chapters.

Additional Feature Modules

In order to customize your monitoring experience with NetEye, you can go beyond the feature scope offered by NetEye Core.

NetEye’s modular architecture supports the installation of additional Feature Modules that extend the NetEye Core functionality. This separation allows you to customize NetEye in order to address specific customer needs.

Each NetEye Feature Module can be purchased separately from NetEye Core and adds a specific set of features. In some cases, the Feature Module contains Open Source, GPL-licensed software. In cases like these the software can be used even after the paid subscription has expired or can even be installed independently.

However, the software is considered a customisation and is entirely not supported.

You can learn more about installing additional NetEye Feature Modules in our installation guide.

Support

To get in touch with the NetEye Support Team use either contact:

  • Phone: +39 0471 56 41 01

  • Web: support portal

Note

Please be aware that the support phone number is only available during standard office hours on working weekdays, i.e. Monday through Friday, 09:00 AM–05:00 PM.

All content of this product documentation is © 2017 - 2026 by Würth IT Italy.