Synthetic and path
ICMP, TCP, UDP, DNS, HTTP, agent-to-agent, voice quality and scripted browser checks, plus ECMP and MPLS-aware hop-by-hop traces with a geographic path view.
From BGP routes crossing the open internet down to packets inside your kernel, probectl gathers five planes of signal and folds them into one correlated incident: synthetic, routing, flow, device and eBPF. Self-hosted, so the signal is yours alone.
The same five-plane core and the same self-hosted promise, pointed at one network or at many.
Stand up one tenant and get a correlated view across synthetic, routing, flow, device and eBPF, with cross-plane root cause and an MCP server for your own AI tools. Self-hosted, so no telemetry leaves your network.
Run it once and serve many hard-isolated tenants: pooled, siloed or hybrid isolation per tenant, with per-tenant metering, and break-glass that is explicit, time-bounded and separately audited. Every tenant sees the probectl product; there is no per-tenant rebranding, by design.
Each plane is gathered by your own agents, with no third-party collector in the path. Routing is the exception by nature: it reads public route-collector feeds, because the subject is the open internet.
ICMP, TCP, UDP, DNS, HTTP, agent-to-agent, voice quality and scripted browser checks, plus ECMP and MPLS-aware hop-by-hop traces with a geographic path view.
Live RIS and RouteViews monitoring for hijacks, leaks and origin changes, RPKI-aware, with ASN and geographic context.
Passive NetFlow, IPFIX and sFlow, plus AWS, Azure and GCP flow logs your own export pipeline already writes. Top talkers, link capacity and egress anomalies, with sampling corrected.
SNMP over standard MIBs plus streaming gNMI and OpenConfig: interface health, errors and capacity. A box that lacks a table yields fewer metrics rather than failing the poll.
A kernel sensor that maps service dependencies from L3 to L7 with no application changes, on Linux 5.8 and newer. It observes and never blocks.
Semantic conventions are pinned and conformance-tested, and OTLP metrics, traces and logs move in both directions: probectl ingests them and re-exports them to your collector.
“Berlin says the app is slow. Network, path, or server?”
Synthetic probes, ECMP and MPLS-aware path discovery and flow analytics show where the latency lives, not just that it exists.
“Is it us, or the user's WiFi?”
The endpoint agent measures WiFi link health, the local gateway and the ISP path, then attributes the slowdown to the closest impaired layer. Access-point identifiers and last-mile hop addresses stay off unless you turn them on.
“Did the 14:03 deploy cause this?”
Change intelligence correlates deployment and configuration events with the symptoms that followed them.
“Why did this prefix go dark, us or the internet?”
Routing intelligence from RouteViews and RIPE RIS, RPKI validity and a collective outage view separate a you-problem from an everyone-problem.
“What breaks if I drain this node?”
The topology graph is versioned, so a what-if removes a node or link at any point in its history and reports which paths break and which reroute, with the coverage behind that answer stated.
“Who is saturating this link, and what does it cost?”
Flow top talkers plus egress attributed to services and teams, priced against list rates. It is an attribution model, not a billing reconciliation.
A flare on the map is not an answer. probectl folds every plane's signal into one tenant-scoped incident, walks the live topology to find the cause, and cites the evidence behind each step.
A route change, a path shift and an egress spike become one story rather than three pages.
Every claim links to the exact signal that supports it. A reading you can audit.
It reads the network and explains it. Remediation is human-gated, and the detection engine emits signals rather than blocking traffic.
Everything on this page is in the free, source-available core. The commercial editions add the FIPS build, bring-your-own-key, governance and support, plus the provider plane and metering for MSPs.
Core Web Vitals from real browsers, consent-gated, with no visitor address ever stored, joined against the synthetic tests watching the same host.
Nine certificate and protocol findings read from traffic probectl already captured, so nothing is re-handshaked and no scanner touches your estate.
Six shipped detectors for beaconing, DNS exfiltration, hostile egress and lateral fan-out. They raise signals; there is no enforcement surface anywhere in the package.
Import and export OpenSLO v1 definitions, with error budgets and multi-window multi-burn-rate alerting.
Declare zones and forbidden flows; probectl validates them against observed traffic and answers violation, clean, or not observed. It never claims you are compliant.
A Grafana datasource, a federation endpoint, and remote-write ingest, so probectl fits the dashboards you already run.
Observed egress attributed to services and teams, and a carbon estimate from published coefficients that reports itself as an estimate rather than a measurement.
SCIM 2.0 provisioning, read-only ServiceNow and NetBox correlation, five SIEM presets, and seven on-call and ITSM connectors that carry acknowledgement and resolution back onto the incident.
A Terraform provider with four resources and six data sources, Helm charts, ArgoCD and Flux manifests, and signed packages.
Most AI-powered observability sends your telemetry to someone else's model and returns prose. probectl's assistant is built the other way around: it answers only with citations to signals you are allowed to see, and runs air-gapped by default.
Every claim links to a real incident or change event. Ungrounded model output is rejected before you see it, and not knowing is a first-class answer.
A deterministic built-in engine with no model at all, then a model on your own hardware through the OpenAI-compatible adapter, which is how Ollama and vLLM are used. A hosted model requires an explicit written opt-in, and every call is audited.
An MCP server hands the live network to Claude or any MCP client as eight tenant-scoped tools: read-only queries, analysis, and one proposal-only remediation. The AI sees exactly what its token's user may see.
probectl is self-hosted by design. Your telemetry stays inside your perimeter, and there is no phone-home, down to licence checks, which are offline signature math. Point the assistant at a local model and the whole observatory runs air-gapped.
No vendor endpoint appears in the source, every optional external feed ships disabled, and a documentation gate binds that promise to the code and fails the build if it drifts.
Run root-cause analysis against a model on your own hardware. Nothing crosses the perimeter.
Every agent-to-control-plane channel is mutually authenticated and encrypted, with SPIFFE-style agent identity, and every listener requires TLS.
Builds can link the FIPS 140-3 validated Go cryptographic module. probectl itself holds no product-level certificate.
probectl is not another hosted agent fleet. The difference is where the data lives, and how many planes it correlates for you.
Both are excellent, and both send your telemetry to someone else's cloud. probectl keeps every signal inside your perimeter and folds routing, flow, device and eBPF into one correlated incident.
A great dashboard layer, but you assemble and correlate the planes yourself. probectl ships them already folded into one tenant-scoped incident, and still speaks to Grafana as a datasource and exports OTLP.
Most stop at flow or device. probectl spans synthetic, routing, flow, device and eBPF, with cross-plane root cause and an answer that cites its evidence.
Source-available and self-hosted. The evaluation stack on the left is real: sample data, loopback only, one command to a live service map. Production is the same idea grown up, with one static binary per agent, Docker or Helm, and HTTPS by default. Single-tenant for one team, or multi-tenant for a provider.
The five-plane core is free. Enterprise adds the FIPS build, bring-your-own-key, governance and guarded remediation; Provider adds the management plane and metering. See editions.
Every image, binary, checksum file and bill of materials is keyless-signed with cosign and verified inside the same job that produced it.
Images carry build provenance and SBOM attestations, and each release ships an SPDX bill of materials for the source tree.
Tenant isolation is enforced by the database with forced row-level security, checked at boot, and a cross-tenant suite runs on every change: a query crossing a tenant line fails the build, not the customer.
Provider operators get no implicit access to tenant telemetry. Break-glass is explicit, time-bounded and separately audited, and the security policy puts that bypass in scope for reports.
The console holds a WCAG 2.2 AA baseline checked against a real browser in continuous integration.
The product's documentation is bound to its source by a gate that fails the build when a sentence outruns what the code does. This page is governed the same way.
probectl is pre-1.0 and in active development. Scale and multi-region figures in the documentation are labelled provisional until reference-hardware runs are recorded, and the docs keep a standing list of what is served, what is built but not yet served, and what is a deliberate non-goal.
Source-available and self-hosted. Clone it, run the eval stack, and you are on a live service map in minutes. No waitlist, no sales call.