Platform
From raw infrastructure signals to verified answers.
Netlume is a layered system: connectors collect from your existing infrastructure, a live topology model gives that data context, and an investigation engine turns it into explained, verifiable conclusions.
Architecture
Eight layers, one direction of travel.
Data flows upward from your devices into context, reasoning and recommendations. Control flows back down only through approvals.
- Collectors deploy inside your network and connect outbound
- Raw vendor output is preserved alongside the normalized model
- Topology is modelled continuously, not per incident
- Recommendations are gated by approval and verified afterwards
This is a conceptual view of the platform. Specific deployment topologies are agreed with each team based on their environment and security requirements.
Infrastructure
L1Your existing devices, controllers and clouds. Nothing is replaced.
- Routers
- Switches
- Firewalls
- Load balancers
- GPU / compute hosts
- Cloud networks
- Kubernetes
Netlume Connectors / Agents
L2Lightweight collectors deployed close to the infrastructure, using least-privilege credentials you control.
- SSH
- NETCONF
- RESTCONF
- gNMI
- SNMP
- Syslog
- Streaming telemetry
- Vendor & cloud APIs
- Kubernetes API
Telemetry + Logs + State + Configuration
L3Normalized into a common model while keeping the original vendor output as evidence.
Telemetry
- Counters · queues
- Optics · CPU · memory
- ECN · PFC · drops
Logs & alarms
- Syslog
- SNMP traps
- Controller events
Operational state
- RIB / FIB · BGP · EVPN
- MAC · ARP / ND · LLDP
- Interface state
Configuration
- Running / candidate
- Change history
- Drift vs. intent
Topology Context
L4A live model of how everything connects, built before any incident happens.
- Physical / LLDP
- Underlay routing
- Overlay · EVPN / VXLAN
- MPLS · SR paths
- VRFs & tenants
- Service dependencies
Investigation Engine
L5Agents form hypotheses, collect targeted evidence along the topology and correlate it on a single timeline.
- Hypothesis generation
- Targeted collection
- Cross-device correlation
- Change correlation
Root Cause Analysis
L6Ranked candidates with confidence, linked evidence and the alternatives that were ruled out.
Recommendations
L7Proposed actions with blast radius, a verification plan and a rollback — gated by approval.
Verification
L8The same evidence checks run again after any change to confirm the outcome.
Connectivity
Speaks the protocols your infrastructure already uses.
Netlume uses structured, model-driven interfaces where available and falls back to CLI or SNMP where they are not — so older platforms are not left out.
What Netlume can collect
- Configuration
- Operational state
- Logs
- Alarms
- Show command output
- Interface state
- Optics
- Counters
- Queue statistics
- Routing tables
- BGP state
- EVPN state
- MAC tables
- ARP / ND
- LLDP
- Telemetry
- CPU / memory
- Packet drops
- Errors
- Congestion
- Historical changes
Design principles
Built to be trusted on production networks.
Read before anything else
Connectors are read-only by default. Investigation never requires write access to your devices.
Evidence over assertions
Every conclusion links to the command output, telemetry or event that supports it. Nothing is a black box.
Topology before analysis
The relationship model exists before an incident starts, so investigations follow real forwarding paths.
Vendor-neutral model
Vendor output is normalized into common concepts while the original output is kept as evidence.
Runs where your network is
Collectors sit inside your environment and connect outbound. The platform can be deployed privately.
People approve change
Recommendations are proposals. Changes require an authorized operator and are verified afterwards.
Deployment
Deploy where your security model needs it.
Netlume is designed for environments where infrastructure data cannot leave the building, as well as teams that prefer a managed service.
On-premise
The full platform and collectors inside your own facilities.
- Runs entirely in your data center
- Air-gap friendly design
- Your identity provider and vault
Private cloud
Deployed into infrastructure you control in your cloud provider.
- Your cloud account and VPC
- Private connectivity to collectors
- Your keys and retention policy
Managed
Netlume operates the platform; collectors and credentials stay with you.
- Collectors stay in your network
- Outbound-only connectivity
- Scoped, revocable access
Turn infrastructure complexity into clear answers.
See Netlume investigate a real-world failure scenario on a multi-vendor fabric, and talk with the engineers building it about your environment.