pmacct

C
C tier on Bandwidth Monitoring SoftwareScore 6.2 · #19 of 31
Android app
Not listed
Free plan
No
Runs on
Linux, self-hosted

Summary

pmacct is a free, self-hosted suite of passive network monitoring tools for Linux. It collects NetFlow, IPFIX, and sFlow traffic, while separate daemons handle BGP, BMP, and Streaming Telemetry. The tools can replicate and export network information, then filter, sample, tag, classify, renormalize, and aggregate traffic, including at layer 7. Data can be kept in memory, relational or NoSQL databases, or flat files, and can also be sent to AMQP or Kafka brokers. Documented options include MySQL/MariaDB, PostgreSQL, SQLite, MongoDB, Elasticsearch, InfluxDB, Druid, and ClickHouse. Output formats include text, CSV, JSON, and Apache Avro, and a command-line client can query memory-table data. Official Docker images cover seven daemons; images are built for linux/amd64 and linux/arm64, with arm64 support marked experimental. SQL, AMQP, and Kafka plugins are disabled by default and need compile-time support enabled. The project advises planning for CPU, memory, and disk needs when retaining every flow.

Who it is for

pmacct suits Linux operators who need to collect and process network traffic data with configurable filtering, classification, and aggregation. Its documented deployment options include self-hosting with Docker, Docker Compose, or Kubernetes.

What is good

  • Free plan with self-hosted Linux deployment.
  • Processes NetFlow, IPFIX, and sFlow traffic.
  • Supports filtering, sampling, tagging, and aggregation.
  • Offers text, CSV, JSON, and Avro output.
  • Official images cover seven daemons.

What to know first

  • arm64 container support is experimental.
  • SQL, AMQP, and Kafka plugins are disabled by default.
  • Storing every flow can increase CPU, memory, and disk use.
  • Memory plugin is intended for smaller or prototype environments.

Verdict

pmacct offers broad traffic collection and processing options for teams prepared to configure and operate a self-hosted toolset. Check plugin build requirements and storage capacity needs before choosing it.

Compared on bandwidth monitoring software

Free plan
Yespmacct.net

Facts

Product
pmacct is a set of passive network monitoring tools for NetFlow, IPFIX, sFlow, libpcap, BGP, BMP, RPKI, IGP and Streaming Telemetry.github.com · 3 Oct 2026
Collection and processing
It can collect, replicate and export network information, and aggregate, filter, sample, renormalize, tag and classify traffic at layer 7.github.com · 3 Oct 2026
Storage and output
Traffic data can be stored in memory, relational or NoSQL databases, and flat files, or published to AMQP and Kafka brokers.github.com · 3 Oct 2026
Integrations
The documentation names MySQL/MariaDB, PostgreSQL, SQLite, BerkeleyDB, MongoDB, RabbitMQ, Kafka, Elasticsearch, InfluxDB, Druid and ClickHouse among supported storage or consumer options.github.com · 3 Oct 2026
Protocols
Its tools collect or export traffic using NetFlow, IPFIX and sFlow; separate daemons collect BGP, BMP and Streaming Telemetry data.github.com · 3 Oct 2026
Deployment
The project provides official Docker images for seven daemons and documents use with Docker Compose and Kubernetes.github.com · 3 Oct 2026
Container platforms
Official Docker images are built for linux/amd64 and linux/arm64, with arm64 support marked experimental.github.com · 3 Oct 2026
Build requirements
The quickstart says libpcap and its headers are the package’s only dependency, while SQL, AMQP and Kafka plugins are disabled by default.github.com · 3 Oct 2026
Scaling
The FAQ says deployments can scale through aggregation, filtering, sampling and tagging, or by distributing input across multiple pmacct instances.github.com · 3 Oct 2026
Resource considerations
The FAQ cautions that storing every flow can increase CPU, memory and disk use and recommends planning resources for that level of detail.github.com · 3 Oct 2026
Documentation
The repository links to a wiki and includes a quickstart, FAQ, configuration key reference, examples and SQL documentation.github.com · 3 Oct 2026
Support and troubleshooting
The Docker documentation provides troubleshooting guidance and says bug reporters may be asked to provide debugging information.github.com · 3 Oct 2026
Purpose
pmacct is a set of passive network monitoring tools for accounting, classifying, aggregating, and exporting network traffic.github.com · 4 Oct 2026
Traffic processing
Traffic data can be filtered, sampled, tagged, classified, and aggregated using configurable primitives.github.com · 4 Oct 2026
Data destinations
The project documents output to MySQL, PostgreSQL, SQLite, flat files, AMQP, and Kafka.github.com · 4 Oct 2026
Message consumers
The documentation names Elasticsearch, InfluxDB, Druid, and ClickHouse as examples of systems that can consume data through messaging brokers.github.com · 4 Oct 2026
Output formats
The print plugin supports tab-spaced, CSV, and JSON output, and the documentation also describes Apache Avro output.github.com · 4 Oct 2026
Command line client
The pmacct client can query memory-table data and format output as text, CSV, or JSON.github.com · 4 Oct 2026
Configuration limit
SQL, AMQP, and Kafka plugins are disabled by default and require their support to be enabled at compile time.github.com · 4 Oct 2026
Scale guidance
The documentation says the memory plugin is intended for prototyping, lab use without mass traffic generation, and smaller or home production environments.github.com · 4 Oct 2026
Support and documentation
The project points users to online GitHub wiki pages and documentation included in the distribution, including a quickstart and FAQ.github.com · 4 Oct 2026
Security information
The opened project pages describe collection and output capabilities but do not state security certifications or compliance attestations.github.com · 4 Oct 2026

Best pmacct alternatives

See all 20

Where it ranks on Everything Xiaomi

Is pmacct yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources