Skip to content

Nyxtrace documentation

Nyxtrace watches the traffic on your own network, keeps an inventory of every device, and explains what it sees in plain language. It runs as your own appliance, and your network data stays on it.

Getting started

What the product is, what the appliance is made of, what hardware it needs, and how to get from a blank Debian 13 machine to a first login.

Read the introduction

Data sources

Firewall NetFlow, Suricata EVE, resolver query logs, a Proxmox mirror and Zeek — what each source can see, and what it cannot.

See the sources

Connectors

One shape for every integration with a foreign system: configuration, secrets, health, rate limits, and the ndr connectors command.

Read the framework

Dashboard

The globe, the network map, devices, incidents, replay, search, response proposals, and the system view.

Take the tour

Detection

Rarity, beaconing, robust hourly baselines, scans and peer-group outliers — and the learning phase that has to pass before any of them alert.

See the models

Operations

Health checks, backup and restore, upgrades and rollback, the GeoIP databases, and where the logs are.

Read the runbook

API reference

The v1 REST surface: authentication, tenancy, wire rules, the resource endpoints, and the internal ingest listener.

Read the contract

Editions & licensing

What the free core contains, what Pro adds, and how the online licence check, its entitlement tokens and the 72-hour grace period work.

Compare the editions

Security & privacy

What is collected and where it stays, tenant isolation, and the daily heartbeat written out field by field — including how to switch it off.

Read the privacy model

It is not a cloud service, not an inline firewall, and not an agent on your laptops. Your network data lives on your appliance; what the installation does send is one daily heartbeat of version and bucketed counts, and — on Pro — the licence check. Sensors observe passively; nothing in the free core can change a firewall rule. Response actions are recorded, reviewed and approved by a person before anything is executed, and execution itself is a separate, separately gated module.

It is also not instant. Every behavioural model needs a baseline, so a fresh installation spends its learning phase collecting evidence and deliberately raising no alerts.