Comparison · Network Discovery & Troubleshooting
Network discovery and troubleshooting: the tools you reach for before and beside the monitor
A monitor only watches what you told it about, and it only reports what reached the poller. This table covers the tools that fill both gaps.

Every monitoring system has two blind spots that no amount of template tuning will fix. The first is the device nobody added: the switch someone racked during a Friday change, the IPMI interface that kept its factory address, the printer VLAN that was never in anyone’s spreadsheet. It fails silently, because as far as the monitor is concerned it does not exist. The second is the check that goes red while everyone insists nothing is wrong: the network team says SNMP is permitted, the server team says the web service is healthy, and the poller keeps logging timeouts. In both cases the monitor is the wrong instrument for the question, and you need something that looks at the network directly.
That is the job of this category. Three of the products here are not monitoring systems at all. Angry IP Scanner sweeps an address range and tells you which hosts answer and which TCP ports they expose, which is exactly the list you want before seeding an inventory or auditing one. Wireshark captures and decodes traffic, so you can see whether an SNMP request left the poller, whether the reply came back, and what an HTTP check actually received. LizardSystems Network Scanner, a closed-source Windows tool that is free for personal use and licensed per machine for business, looks at a different layer: it lists shared folders, FTP and web servers across a range and shows which of them a given account can read or write, which is a quick way to find the file server or NAS that never made it into monitoring. It has not been updated since July 2021, so it sits at the end of the table. None of the three stores history or sends alerts; they are the flashlight and the multimeter on the workbench, not the alarm panel.
Four more rows are monitors whose own discovery features overlap with a manual sweep. LibreNMS follows LLDP, CDP and routing neighbors from a seed device; Zabbix runs scheduled network discovery rules with actions that create hosts automatically; Checkmk’s network scan can create hosts in a folder on a schedule; PRTG runs auto-discovery against IP ranges and proposes sensors. If you already run one of them, the built-in feature may be all you need for inventory. The dedicated tools still earn a place for the moments when you want an independent second opinion, or need to see raw packets. The order of this table is explained on our methodology page and involves no commercial arrangement.
How we score: read our methodology. Table order follows how often we recommend each product for this job, not any commercial arrangement.
The comparison table
7 products side by side
| Product | License | Runs on | Key feature | Best for |
|---|---|---|---|---|
| WiresharkWireshark Foundation | Free, open source (GPLv2) | Desktop app for Windows, macOS and Linux; tshark and dumpcap on the command line | Packet capture with protocol dissectors, including SNMP (and SNMPv3 decryption) and HTTP | Proving what is on the wire when a check fails and nobody agrees why |
| Angry IP ScannerAnton Keks | Free, open source (GPLv2) | Desktop app for Windows, macOS and Linux (Java-based) | Fast ping and TCP port sweeps of IP ranges with CSV/TXT/XML export | Checking what actually answers on a subnet before you add it to monitoring |
| LibreNMSLibreNMS community | GPLv3 | Linux server (PHP, MariaDB, RRDtool); optional distributed pollers | SNMP auto-discovery across a very wide list of device operating systems | Network teams with lots of switches, routers and firewalls to graph |
| ZabbixZabbix | AGPLv3 (since 7.0; GPLv2 before) | Linux server; agents for Linux, Windows, macOS, BSD | Low-level discovery plus proxies for remote sites | Mixed estates that want one self-hosted tool for servers and network gear |
| CheckmkCheckmk GmbH | GPLv2 (Raw) + commercial editions | Linux server (Debian, Ubuntu, RHEL, SLES), appliance or container | Agent-driven service discovery with rule-based configuration | Admins who want sensible defaults fast and may pay for scale later |
| PRTG Network MonitorPaessler | Commercial subscription | Self-managed on Windows Server, or PRTG Hosted Monitor (SaaS) | Sensor-based monitoring with auto-discovery and ready-made maps | Windows-centric teams that want a supported product and fast onboarding |
| LizardSystems Network ScannerLizardSystems | Free for personal use; paid business license | Windows | Lists SMB/NetBIOS shares, FTP and web servers across IP ranges and checks read/write access for a chosen user | Finding forgotten file shares, NAS boxes and web admin pages on a Windows network you manage |
Every name links to our full review. Licensing and platform details reflect vendor documentation at the time of writing; confirm current terms on each vendor’s site.
Before you shortlist
How to choose
- Authorization first. Only sweep or capture on networks you own or administer under a written agreement. Discovery traffic and packet captures can trip intrusion detection, breach policy and expose other people’s data. Tell the security team before you scan, and keep captures on encrypted storage.
- One-off answer or recurring job. A desktop sweep answers “what is on this subnet right now”. If you need that answer every night, with new devices added to monitoring automatically, use the discovery rules built into Zabbix, Checkmk, LibreNMS or PRTG instead of scheduling a GUI tool.
- Which protocols you need to see. Ping and TCP port probes find most hosts, but SNMP runs over UDP 161 and traps arrive on UDP 162. Confirming those paths needs either an SNMP query from the poller itself or a packet capture on it; a TCP port scan cannot tell you.
- Where the evidence has to be collected. Monitoring servers are usually headless. Plan to capture with tcpdump, dumpcap or tshark on the poller and open the file in Wireshark on your workstation, rather than installing a desktop environment on a production box.
- Export formats that feed your inventory. A sweep is only useful if its output can be compared with what the monitor already knows. Look for CSV or XML export and an API or bulk import on the monitoring side, so the diff takes minutes rather than an afternoon of copy and paste.
Your own network, with permission
Scanning and packet capture are routine administration on infrastructure you are responsible for, and a policy violation almost everywhere else. Use these tools only on networks you own or are authorized in writing to manage, scope sweeps to the ranges you actually administer, and treat capture files as sensitive: they can contain credentials, session cookies and personal data. Delete them when the ticket is closed.
Further reading
Head-to-head comparisons
Questions we get
FAQ
Do I need a separate scanner if my monitoring system has discovery?
Often not for routine inventory. Zabbix, Checkmk, LibreNMS and PRTG can all discover hosts on their own. A standalone scanner is still handy for a quick independent check, for networks the poller cannot reach, or when you want a list to review before anything is added automatically.
Can a port scanner tell me whether SNMP will work?
Not reliably. SNMP uses UDP, and most general-purpose scanners probe TCP ports. The honest test is an snmpwalk or snmpget run from the poller itself with the real credentials, backed by a packet capture if the result is a timeout.
Is it safe to run Wireshark on the monitoring server?
Capture there, analyze elsewhere. Run dumpcap, tshark or tcpdump on the server with a tight capture filter and a size limit, copy the file to your workstation, and open it in Wireshark. That keeps the GUI and its parsers off a machine that holds credentials for your whole network.
How do I find devices that never made it into monitoring?
Export the host list from your monitor, sweep the same ranges with a scanner or discovery rule, and compare the two lists by IP address. Anything that answers but is not monitored is a candidate; anything monitored that no longer answers is a candidate for removal.
Which of these tools cost money?
Wireshark, Angry IP Scanner and LibreNMS are free and open source, as are Zabbix and the Checkmk Raw edition. PRTG is a commercial subscription licensed by sensor count; check Paessler’s site for current plans. LizardSystems Network Scanner is closed source: free for personal, non-commercial use, with a paid business license per machine; check the vendor’s purchase page for the current price.
Disclosure. Scannethub is independent and hosts no software. Product links go directly to each vendor’s official site, and none of them earns us anything. No vendor pays for table order or verdicts. Details on ouraffiliate disclosure page.