You cannot defend a network you cannot see.
XS NMS discovers your topology on its own, watches every node and link in real time, and tells you which incident actually matters — across on-premise hardware, cloud instances and edge sites, in one picture.
- Zero-config discovery
- Vendor agnostic
- Hybrid & multi-cloud
Invisible infrastructure is a liability, not a saving
Most operations teams are not short of data. They are short of a single, current, trustworthy picture — and the noise is what makes outages long.
Stale documentation
The topology diagram is a Visio file from two migrations ago. Nobody trusts it, so every incident begins with an archaeology exercise.
Alert fatigue
One failed link generates hundreds of downstream alerts. Engineers learn to mute the channel, and the alert that mattered goes with it.
Tool fragmentation
SNMP polling in one product, cloud metrics in another, flow data in a third. Correlation happens in a human head at 3am.
Reactive posture
Failures are discovered by customers, not by monitoring. Hardware degrades for weeks before anyone sees the trend.
An intelligence layer over everything you run
Six subsystems, one data model. Discovery feeds the map, the map feeds correlation, correlation feeds the alert you actually receive.
Dynamic topology mapping
Auto-discovers devices, interfaces and the links between them, then keeps the map current as the network changes. No manual diagramming, no drift.
Predictive latency tracking
Packet health is measured continuously across global routes. Trend models flag congestion and route degradation before customers register an impact.
Correlated alerting
Related events are grouped into a single incident with a probable root cause attached, so an engineer opens one ticket instead of triaging two hundred.
Node health analytics
CPU, memory, temperature, interface errors and throughput per device, retained long enough to see the slope. Hardware failures announce themselves weeks early.
Anomaly detection
Behavioural baselines per device and per link surface unusual traffic patterns, rogue devices and unauthorised topology changes as they happen.
Hybrid cloud operations
On-premise hardware, AWS and Azure instances and distributed edge nodes report into the same dashboard, with the same thresholds and the same on-call rota.
How 142 events become one actionable incident
The value of a monitoring platform is not how much it collects. It is how much it removes before a human is woken up.
Discover
Devices, interfaces and dependencies are found and mapped automatically, then re-verified continuously.
Collect
SNMP, ICMP, flow, API and agent telemetry stream into a single time-series store with per-device baselines.
Correlate
Dependency-aware logic collapses the event storm into the one failure that caused it.
Predict
Trend models flag the degradations that have not yet crossed a threshold but will.
Act
Incidents route to the right team with context, runbook and history — and close themselves when the signal clears.
The map is the product
Dashboards tell you a number is bad. A live dependency map tells you what breaks next. NMS builds and maintains that map without asking your team to draw it.
- Auto-discovery. Point NMS at a subnet or seed device; it walks the network and returns a topology, not a device list.
- Blast-radius view. Select any node and see every service, site and subscriber group that depends on it.
- Change detection. A new device, a moved link or an unauthorised port becomes an event, not a surprise at audit time.
- Geographic and logical layers. Switch between physical sites, logical service paths and cloud regions on the same canvas.
EDGE-LAGOS-01 has trended upward for eleven days. NMS raised it as a capacity risk before it became an outage.
Fewer alerts. Better alerts.
Correlation is where monitoring platforms earn their keep. NMS understands the dependency graph, so it knows the difference between a cause and its two hundred consequences.
- Dependency suppression. When an upstream link drops, downstream device-unreachable alerts are attached to the parent incident rather than paged separately.
- Probable root cause. Each incident opens with the most likely origin, the evidence behind it and the last known-good state.
- Maintenance awareness. Planned windows suppress the expected noise so the on-call channel stays meaningful.
- Anywhere delivery. Email, SMS, webhook, Teams or Slack, with severity-based escalation chains and acknowledgement tracking.
Built for networks that cannot go dark
ISPs & carriers
Core, aggregation and access layers on one map, with per-POP SLA reporting and customer-impact visibility during incidents.
Data centres
Rack, switch, power and thermal telemetry with capacity trending and pre-failure hardware alerts.
Multi-site enterprises
Branch, campus and remote-site uptime measured against the same SLA, with WAN path quality per location.
Government & defence
Air-gapped and sovereign deployments, change auditing and topology-integrity monitoring for critical infrastructure.
Cloud & hybrid estates
One operations picture spanning owned hardware and public-cloud workloads, so the hand-off point stops being a blind spot.
Education & healthcare
Campus-wide Wi-Fi and clinical network visibility where downtime has consequences beyond a support ticket.
Agentless where it can be, agent-based where it must be
NMS is designed to be dropped into a heterogeneous estate you did not choose. It speaks the standard protocols first and falls back to agents and APIs only where the standards run out.
- Scales with the estate — distributed pollers for geographically split networks, with a single management plane.
- Retains the history — long-window metric retention so capacity planning is evidence-based, not anecdotal.
- Integrates outward — REST API, webhooks and native hand-off to SmartGuard subscriber data and B.O.S.S. service records.
| Discovery | Seed-based and subnet sweep, L2/L3 neighbour walk, scheduled re-discovery, manual override |
|---|---|
| Collection | SNMP v1/v2c/v3 ICMP NetFlow / sFlow WMI SSH REST Syslog |
| Cloud | AWS and Azure metric APIs, container and edge node agents, hybrid service views |
| Alerting | Threshold, baseline-deviation and predictive rules; dependency suppression; maintenance windows |
| Notification | Email, SMS, webhook, Microsoft Teams, Slack, escalation chains with acknowledgement |
| Visualisation | Live topology canvas, per-device dashboards, NOC wall view, scheduled PDF/Excel reports |
| Deployment | On-premise, private cloud, air-gapped or XS-managed. Distributed poller architecture. |
| Access control | Role-based permissions, tenant separation, full administrative audit trail, SSO |
Monitoring written by people who run networks
Operator heritage
Thirty years of building AAA, billing and access platforms for ISPs means NMS was designed against real carrier estates, not a lab topology.
No per-device tax
Commercial terms are built around your deployment, not a per-sensor meter that punishes you for monitoring more of your own network.
Part of a platform
NMS shares data with SmartGuard and B.O.S.S., so an incident can be expressed in the language your business cares about: affected subscribers and revenue at risk.
Before you talk to sales
No. NMS is agentless by default and uses SNMP, ICMP, flow data, SSH and vendor APIs for the majority of an estate. Agents are used only where deeper host-level visibility is required — typically servers, containers and cloud workloads — and are optional.
A seeded discovery returns first devices and metrics in under a minute, with a full topology assembled over the following minutes to hours depending on estate size and credential coverage. Re-discovery then runs continuously in the background, so the map stays current without manual intervention.
Yes — that is the design goal. AWS and Azure resources are collected through their metric APIs and rendered on the same canvas as physical devices and edge nodes, sharing thresholds, dashboards and escalation rules. The cloud hand-off point stops being the blind spot in your incident timeline.
Most teams do not need more collection; they need correlation and a current topology. If your existing tool tells you a hundred things are down when one link failed, or your diagram is out of date, NMS is solving a different problem. Many customers run NMS alongside an incumbent during a pilot and consolidate once the correlation quality is proven.
Yes. NMS runs fully on-premise with no external dependency, including in air-gapped environments, and supports distributed pollers for networks split across sites or jurisdictions. Deployments for government and defence customers are configured with local data residency and full administrative audit trails.
Point it at your network and watch the map draw itself.
Book a live demo and we will run discovery against a segment of your own estate — you will see your real topology, not a sample dataset.