Skip to content
Netlume

Platform

From raw infrastructure signals to verified answers.

Netlume is a layered system: connectors collect from your existing infrastructure, a live topology model gives that data context, and an investigation engine turns it into explained, verifiable conclusions.

Architecture

Eight layers, one direction of travel.

Data flows upward from your devices into context, reasoning and recommendations. Control flows back down only through approvals.

  • Collectors deploy inside your network and connect outbound
  • Raw vendor output is preserved alongside the normalized model
  • Topology is modelled continuously, not per incident
  • Recommendations are gated by approval and verified afterwards

This is a conceptual view of the platform. Specific deployment topologies are agreed with each team based on their environment and security requirements.

  1. Infrastructure

    L1

    Your existing devices, controllers and clouds. Nothing is replaced.

    • Routers
    • Switches
    • Firewalls
    • Load balancers
    • GPU / compute hosts
    • Cloud networks
    • Kubernetes
  2. Netlume Connectors / Agents

    L2

    Lightweight collectors deployed close to the infrastructure, using least-privilege credentials you control.

    • SSH
    • NETCONF
    • RESTCONF
    • gNMI
    • SNMP
    • Syslog
    • Streaming telemetry
    • Vendor & cloud APIs
    • Kubernetes API
  3. Telemetry + Logs + State + Configuration

    L3

    Normalized into a common model while keeping the original vendor output as evidence.

    Telemetry

    • Counters · queues
    • Optics · CPU · memory
    • ECN · PFC · drops

    Logs & alarms

    • Syslog
    • SNMP traps
    • Controller events

    Operational state

    • RIB / FIB · BGP · EVPN
    • MAC · ARP / ND · LLDP
    • Interface state

    Configuration

    • Running / candidate
    • Change history
    • Drift vs. intent
  4. Topology Context

    L4

    A live model of how everything connects, built before any incident happens.

    • Physical / LLDP
    • Underlay routing
    • Overlay · EVPN / VXLAN
    • MPLS · SR paths
    • VRFs & tenants
    • Service dependencies
  5. Investigation Engine

    L5

    Agents form hypotheses, collect targeted evidence along the topology and correlate it on a single timeline.

    • Hypothesis generation
    • Targeted collection
    • Cross-device correlation
    • Change correlation
  6. Root Cause Analysis

    L6

    Ranked candidates with confidence, linked evidence and the alternatives that were ruled out.

  7. Recommendations

    L7

    Proposed actions with blast radius, a verification plan and a rollback — gated by approval.

  8. Verification

    L8

    The same evidence checks run again after any change to confirm the outcome.

Connectivity

Speaks the protocols your infrastructure already uses.

Netlume uses structured, model-driven interfaces where available and falls back to CLI or SNMP where they are not — so older platforms are not left out.

Connectivity methods and the data collected through them
InterfaceUsed forTypical data
SSHCLI show commands where no structured interface existsOperational state, show output, logs
NETCONF / RESTCONFStructured configuration and state using YANG modelsRunning config, interfaces, routing
gNMIStreaming telemetry subscriptions and on-demand GetCounters, queues, optics, BGP, EVPN
SNMPPolling and traps for platforms without streaming telemetryInterface counters, environment, traps
SyslogEvent and alarm ingestionLink, protocol and system events
REST / vendor APIsControllers, firewalls, load balancers, fabric managersPolicies, sessions, health
Cloud APIsVirtual networks, gateways and interconnectsRoute tables, attachments, flow logs
Kubernetes APICluster networking context for workloadsNodes, pods, services, policies

What Netlume can collect

  • Configuration
  • Operational state
  • Logs
  • Alarms
  • Show command output
  • Interface state
  • Optics
  • Counters
  • Queue statistics
  • Routing tables
  • BGP state
  • EVPN state
  • MAC tables
  • ARP / ND
  • LLDP
  • Telemetry
  • CPU / memory
  • Packet drops
  • Errors
  • Congestion
  • Historical changes

Design principles

Built to be trusted on production networks.

Read before anything else

Connectors are read-only by default. Investigation never requires write access to your devices.

Evidence over assertions

Every conclusion links to the command output, telemetry or event that supports it. Nothing is a black box.

Topology before analysis

The relationship model exists before an incident starts, so investigations follow real forwarding paths.

Vendor-neutral model

Vendor output is normalized into common concepts while the original output is kept as evidence.

Runs where your network is

Collectors sit inside your environment and connect outbound. The platform can be deployed privately.

People approve change

Recommendations are proposals. Changes require an authorized operator and are verified afterwards.

Deployment

Deploy where your security model needs it.

Netlume is designed for environments where infrastructure data cannot leave the building, as well as teams that prefer a managed service.

On-premise

The full platform and collectors inside your own facilities.

  • Runs entirely in your data center
  • Air-gap friendly design
  • Your identity provider and vault

Private cloud

Deployed into infrastructure you control in your cloud provider.

  • Your cloud account and VPC
  • Private connectivity to collectors
  • Your keys and retention policy

Managed

Netlume operates the platform; collectors and credentials stay with you.

  • Collectors stay in your network
  • Outbound-only connectivity
  • Scoped, revocable access

Turn infrastructure complexity into clear answers.

See Netlume investigate a real-world failure scenario on a multi-vendor fabric, and talk with the engineers building it about your environment.