Skip to content
A dark data-centre corridor between rows of cabinets
Monitoring

Reads what you already collect.

Your monitoring platform already collects interface counters. Riopex reads its hourly and daily aggregates through its own API on a read-level key.

Request a pilot
Dark perforated rack panels with a single cable
What we read
Your network monitoring system (NMS) holds interface inventory and historic utilisation series. We read those series aggregated hourly and daily, together with the platform's own coverage figure for each bucket.
What stays yours
Your devices, your polling and your write access. We read your platform's own aggregates through its API on a read-level key, and everything else stays exactly as it is.
The key
Read level only. Held as an opaque reference into a secrets manager, resolved at job time, never stored in the database or the repository.
The load
A deliberate request budget with one request in flight per server. Over-driving a monitoring core would degrade your own monitoring, so the budget is set conservatively and the first import is allowed to be slow.
The binding
An interface binds to a service automatically only on an exact identifier match. Everything else opens a review item with ranked candidates.
Cabled server equipment under green light

Connectors

One connector interface, one normalisation path. Every connector declares whether its values are rates, counter deltas or volumes, and that declaration is asserted in a test.

  • PRTG — The first connector, in progress, tested against recorded fixtures captured from a real installation. Reads the inventory and historic-data endpoints, uses the platform's native coverage figure, and asserts the units in a fixture test.In progress
  • SolarWinds — The best interface-matching surface of any platform we surveyed: a real interface index, alias and speed, with series already averaged in bits per second.Planned
  • ManageEngine OpManager — Surveyed. Its API exposes interface inventory and historic series, which is the shape the connector interface expects.Planned
  • Zabbix — Surveyed. Item history and trends give hourly and daily aggregates directly, so the connector reads trends rather than raw items.Planned
  • LibreNMS — Surveyed. Open source, which makes it the likeliest candidate for a live end-to-end test.Planned
  • Cisco Meraki — Surveyed. Its cloud API reports uplink usage per appliance, which suits a branch estate better than a per-interface read.Planned
  • Fortinet FortiAnalyzer — Surveyed. Its figures derive from session logs rather than interface counters, so coverage from this source will be capped by connector policy and can never alone clear the bar for a waste finding.Planned
Rooftop chimneys and antennas with a tower beyond

How we connect

Four properties of the connection, decided deliberately and written down so a network team can check them before a security review starts. Each label says how far the code that enforces the property has come.

  • One read-level API key — The whole ask. It is held as an opaque reference into a secrets manager and resolved only when a job runs, so your device credentials stay with your devices. Polling infrastructure inside your networks would cost, in our estimate, six to twelve months of infosec review, penetration testing and data-processing agreements per customer, so it stays off the plan.In progress
  • Hourly and daily aggregates — A cost question is answered by hourly and daily aggregates, so that is what we read. Real-time polling would add load and latency to your monitoring core, and traps carry events rather than a rate over a window.In progress
  • Outbound reads only — Every request leaves us and lands on your platform's own API. Your firewall keeps its inbound rules, your devices keep their credentials, and your SNMP stays between your devices and the platform that already polls them.In progress
  • The platform's own coverage figure — Native coverage where the platform reports it, derived from the scan interval where it does not. Zero coverage means missing, and a gap suppresses a finding rather than creating one.In progress
What a connector has to declare before it may report a number
PropertyWhy it matters
UnitSome platforms store bytes per second and display kilobits. A missed conversion is a factor-of-eight error in cost per megabit delivered, so the unit is declared and asserted in a fixture test.
Source kindRate, counter delta or volume. A rate source that returns counters raises an error rather than silently producing a wrong number.
CoverageNative where the platform reports it, derived from the scan interval where it does not. Zero coverage means missing, never zero bits per second.
DirectionNormalised per connector so that in always means carrier to site, never passed through as the platform labelled it.
Counter width32-bit counters wrap in seconds on a fast link. Where a platform exposes them, they are refused rather than trusted.

How the key works

Your network team creates an API key at read level in your monitoring platform and gives it to us once. We store an opaque reference to it; the secret itself lives in a secrets manager and is resolved only when a job runs.

Read level is a design decision, and it is what keeps the ask small. Write access on a customer's monitoring system would turn a two-week integration into a two-quarter security review, and it would buy nothing a cost question needs.

Binding an interface to a service

Some platforms expose no stable interface index, so the practical key is the device host plus the sensor name. That is a reconciliation problem rather than an algorithm, and treating it as one is how utilisation ends up attached to the wrong service.

We auto-bind on an exact match between a confirmed service identifier and the interface description. Everything else opens a review item with ranked candidates. Bindings are dated, so a rebind starts a new period and leaves reported history intact.

A woman at a crossing in warm evening glow

Send three invoices. A person replies with what they show.

Request a pilot