Why did nobody know? Which alarm is the real one? Who is going to fix it, and how fast? A monitor, a ticket queue and a terminal that never talk to each other leave you to answer all three by hand. IRIS was built so the answers are already on the screen.
Because a poll every few minutes misses a short outage, and five-minute traffic averages flatten a spike into nothing. IRIS looks every ten seconds, at every host, so you hear it from the system, not from a user.
See what ten seconds changes Which alarm is real?One failed closet lights up every device behind it. Most tools page you for all of them. IRIS folds the pile into one incident, names the frame that failed, and ranks it by how much of the building it took down.
See how incidents are built Who fixes it, and how fast?Every other monitor stops at the alert and sends you to a terminal. IRIS opens a live SSH session on the affected switches from the incident itself, with the last known-good config one click away.
See the fix in one tabMost tools check reachability every one to five minutes and collect bandwidth every five. That is long enough for a closet to drop, reboot and come back without anyone seeing it, and long enough to average a thirty-second saturation event into a flat line. IRIS pings every host every ten seconds and reads bandwidth at the same rate on the ports that matter, so a flap is a flap and a spike is a spike.
ACME-HQ accounts for 63% of site incidents this week.
In most tools ping is a green or red dot. IRIS probes every host every ten seconds and keeps the loss and jitter of every window, then lays the fleet out as a heat table: the deeper the red, the worse the loss; amber for jitter; green for hosts that are simply fine. One glance says which site is in trouble and whether it is one closet or all of them.
Most tools give you a five-minute average and a date picker. IRIS gives you a live chart that scrolls with the clock, zooms under your cursor and fetches finer data as you go, all the way down to the raw ten-second readings. Drag across a spike and you land on a page that already knows which incidents, which conversations and which hosts were involved in that exact window.
"Can this closet take twelve more cameras?" is usually answered by walking to the switch. Most monitors do not track PoE at all; the ones that do show a per-switch total. IRIS reads the real budget from each switch, shows the fleet as a wall of dials, and drills from site to frame to a breaker-panel view of every port with its live draw.
Finding out the state of a UPS usually means a truck roll and a web console per device. IRIS scans every UPS on the network from one place and keeps charge, load, voltage, alarms and battery age for each one, so you know which closet is on battery and which battery is due before anyone leaves the office. Ageing against a two-year warning and a three-year expiry turns replacements into a planned trip with a parts list, not a surprise.
Packet capture usually means a laptop, a span port and someone remembering to press start after the problem is over. IRIS captures continuously at the points you choose, turns the stream into flows and conversations you can search, and keeps the raw segments so you can open any single packet in full. When a user says "it was slow around two", the evidence is already there.
Every packet in every flow opens like this, straight from the stored segments. No export, no laptop, no second tool.
When a distribution frame fails, every switch behind it goes dark, and a traditional NMS pages you for each one. The on-call engineer then reads forty alerts to find the one that matters. IRIS knows how your closets connect, so it files one incident, names the frame that failed, and lists everything behind it as a consequence rather than a separate emergency.
Knowing which frame failed is half the answer. The other half is why, and that usually takes a senior engineer an afternoon of pulling logs. IRIS runs the evidence it already has, sensor history, UPS events, PoE draw, CPU and memory, interface errors and recent config changes, through seven cause categories and gives each a verdict with the evidence attached. What you get is a ranked explanation and a to-do list, not a pile of graphs.
Monitoring tools tell you something is wrong and then leave you to open a terminal, find the addresses and log in one switch at a time. IRIS ships its own browser terminal, Terminus. Launch it from the incident and the affected devices are already connected. Type a command once and every switch answers; click any one of them to read its output alone.
Cloud-managed monitoring means your switch inventory, credentials and traffic patterns live on someone else's servers, on a per-device subscription that climbs every renewal. IRIS runs on one box inside your network. No agents on your switches, no telemetry to us, and no procurement call to add a closet.
See pricingNetwork monitoring is usually priced per device, per feature module and per year, behind a sales call. IRIS is $1 per host per year with every feature included, in two sizes. A host is anything IRIS watches: a switch, an access point, a UPS, a server. Pick the size that covers your count and you are done.
A campus, a hospital wing, a district office. Every closet and every UPS, watched.
Dozens of sites, hundreds of frames, one watchboard for the NOC.
The per-host licence is the same either way. These add the people.
You provide the Linux box inside your network. We install IRIS, keep it patched and upgraded, watch the queues and pollers, and fix it before you notice. Your data still never leaves the building.
Everything in Managed, plus we host the server. Includes up to $500 a month of server cost. If your fleet needs more than that, the difference is billed at actual usage, itemised, no markup surprise.
More than 10,000 hosts? Same dollar, same rules. Talk to us about a multi-site rollout.
Bring a host count and the incident that hurt most last quarter. We will walk through when IRIS would have noticed, what it would have called the root cause, and how many alarms you would not have read.