Independent reviewsWe host no filesNot affiliated with any vendor listed
Scannethub

Comparison · Network Discovery & Troubleshooting

Network discovery and troubleshooting: the tools you reach for before and beside the monitor

A monitor only watches what you told it about, and it only reports what reached the poller. This table covers the tools that fill both gaps.

Illustration for network discovery & troubleshooting

Every monitoring system has two blind spots that no amount of template tuning will fix. The first is the device nobody added: the switch someone racked during a Friday change, the IPMI interface that kept its factory address, the printer VLAN that was never in anyone’s spreadsheet. It fails silently, because as far as the monitor is concerned it does not exist. The second is the check that goes red while everyone insists nothing is wrong: the network team says SNMP is permitted, the server team says the web service is healthy, and the poller keeps logging timeouts. In both cases the monitor is the wrong instrument for the question, and you need something that looks at the network directly.

That is the job of this category. Three of the products here are not monitoring systems at all. Angry IP Scanner sweeps an address range and tells you which hosts answer and which TCP ports they expose, which is exactly the list you want before seeding an inventory or auditing one. Wireshark captures and decodes traffic, so you can see whether an SNMP request left the poller, whether the reply came back, and what an HTTP check actually received. LizardSystems Network Scanner, a closed-source Windows tool that is free for personal use and licensed per machine for business, looks at a different layer: it lists shared folders, FTP and web servers across a range and shows which of them a given account can read or write, which is a quick way to find the file server or NAS that never made it into monitoring. It has not been updated since July 2021, so it sits at the end of the table. None of the three stores history or sends alerts; they are the flashlight and the multimeter on the workbench, not the alarm panel.

Four more rows are monitors whose own discovery features overlap with a manual sweep. LibreNMS follows LLDP, CDP and routing neighbors from a seed device; Zabbix runs scheduled network discovery rules with actions that create hosts automatically; Checkmk’s network scan can create hosts in a folder on a schedule; PRTG runs auto-discovery against IP ranges and proposes sensors. If you already run one of them, the built-in feature may be all you need for inventory. The dedicated tools still earn a place for the moments when you want an independent second opinion, or need to see raw packets. The order of this table is explained on our methodology page and involves no commercial arrangement.

How we score: read our methodology. Table order follows how often we recommend each product for this job, not any commercial arrangement.

The comparison table

7 products side by side

ProductLicenseRuns onKey featureBest for
WiresharkWireshark FoundationFree, open source (GPLv2)Desktop app for Windows, macOS and Linux; tshark and dumpcap on the command linePacket capture with protocol dissectors, including SNMP (and SNMPv3 decryption) and HTTPProving what is on the wire when a check fails and nobody agrees why
Angry IP ScannerAnton KeksFree, open source (GPLv2)Desktop app for Windows, macOS and Linux (Java-based)Fast ping and TCP port sweeps of IP ranges with CSV/TXT/XML exportChecking what actually answers on a subnet before you add it to monitoring
LibreNMSLibreNMS communityGPLv3Linux server (PHP, MariaDB, RRDtool); optional distributed pollersSNMP auto-discovery across a very wide list of device operating systemsNetwork teams with lots of switches, routers and firewalls to graph
ZabbixZabbixAGPLv3 (since 7.0; GPLv2 before)Linux server; agents for Linux, Windows, macOS, BSDLow-level discovery plus proxies for remote sitesMixed estates that want one self-hosted tool for servers and network gear
CheckmkCheckmk GmbHGPLv2 (Raw) + commercial editionsLinux server (Debian, Ubuntu, RHEL, SLES), appliance or containerAgent-driven service discovery with rule-based configurationAdmins who want sensible defaults fast and may pay for scale later
PRTG Network MonitorPaesslerCommercial subscriptionSelf-managed on Windows Server, or PRTG Hosted Monitor (SaaS)Sensor-based monitoring with auto-discovery and ready-made mapsWindows-centric teams that want a supported product and fast onboarding
LizardSystems Network ScannerLizardSystemsFree for personal use; paid business licenseWindowsLists SMB/NetBIOS shares, FTP and web servers across IP ranges and checks read/write access for a chosen userFinding forgotten file shares, NAS boxes and web admin pages on a Windows network you manage

Every name links to our full review. Licensing and platform details reflect vendor documentation at the time of writing; confirm current terms on each vendor’s site.

Before you shortlist

How to choose

Your own network, with permission

Scanning and packet capture are routine administration on infrastructure you are responsible for, and a policy violation almost everywhere else. Use these tools only on networks you own or are authorized in writing to manage, scope sweeps to the ranges you actually administer, and treat capture files as sensitive: they can contain credentials, session cookies and personal data. Delete them when the ticket is closed.

Further reading

Questions we get

FAQ

Do I need a separate scanner if my monitoring system has discovery?

Often not for routine inventory. Zabbix, Checkmk, LibreNMS and PRTG can all discover hosts on their own. A standalone scanner is still handy for a quick independent check, for networks the poller cannot reach, or when you want a list to review before anything is added automatically.

Can a port scanner tell me whether SNMP will work?

Not reliably. SNMP uses UDP, and most general-purpose scanners probe TCP ports. The honest test is an snmpwalk or snmpget run from the poller itself with the real credentials, backed by a packet capture if the result is a timeout.

Is it safe to run Wireshark on the monitoring server?

Capture there, analyze elsewhere. Run dumpcap, tshark or tcpdump on the server with a tight capture filter and a size limit, copy the file to your workstation, and open it in Wireshark. That keeps the GUI and its parsers off a machine that holds credentials for your whole network.

How do I find devices that never made it into monitoring?

Export the host list from your monitor, sweep the same ranges with a scanner or discovery rule, and compare the two lists by IP address. Anything that answers but is not monitored is a candidate; anything monitored that no longer answers is a candidate for removal.

Which of these tools cost money?

Wireshark, Angry IP Scanner and LibreNMS are free and open source, as are Zabbix and the Checkmk Raw edition. PRTG is a commercial subscription licensed by sensor count; check Paessler’s site for current plans. LizardSystems Network Scanner is closed source: free for personal, non-commercial use, with a paid business license per machine; check the vendor’s purchase page for the current price.

Disclosure. Scannethub is independent and hosts no software. Product links go directly to each vendor’s official site, and none of them earns us anything. No vendor pays for table order or verdicts. Details on ouraffiliate disclosure page.