Platform

One sensor. Performance metrics and security signal from the same feed.

Most stacks run a poller for uptime and a separate collector for threat detection, then stitch the two together by hand during an incident. Linivo's sensor collects once and feeds both, so the correlation already exists before you need it.

Unified telemetry

Native support for the protocols your network already speaks.

No proprietary agents required on most devices. Linivo polls, listens and collects using open, standard protocols, then routes the same records to both the monitoring and detection engines.

SNMP v1/v2c/v3

UDP/161

Polls device metrics, including interface counters, CPU, memory and temperature, from routers, switches and almost anything with a management port.

Used for: device health, interface state

NetFlow v5/v9

UDP/2055

Full-flow accounting exported by routers and firewalls: every conversation's source, destination, ports and byte counts.

Used for: traffic analysis, lateral-movement detection

IPFIX

UDP/4739

The IETF-standardized, vendor-neutral evolution of NetFlow v9, with extensible template-based records.

Used for: multi-vendor flow collection

sFlow

UDP/6343

Sampled packet export built for low overhead on high-speed links, ideal for data center and core switching.

Used for: high-speed link visibility

Syslog

RFC 5424

Centralizes device and system logs over UDP or TLS-encrypted TCP, parsed for both operational events and indicators of compromise.

Used for: event logging, forensics

ICMP

echo/reply

Reachability and round-trip latency checks for any IP-addressable device, with configurable loss thresholds.

Used for: reachability, latency

SSH / Telnet

TCP/22, 23

CLI-based polling and scheduled configuration backups for devices without a usable API or MIB.

Used for: config backup, CLI metrics

WMI

TCP/135

Native Windows host and service monitoring without installing a third-party agent on every machine.

Used for: Windows server metrics

BGP

TCP/179

Peering session state and route-change monitoring for edge routers and multi-homed connections.

Used for: peering health, route churn

NTP

UDP/123

Clock drift and time-source monitoring, since accurate timestamps underpin every alert, log entry and detection.

Used for: time sync integrity

REST API

HTTPS

Cloud, virtualization and SaaS platform metrics pulled through vendor APIs where SNMP isn't available.

Used for: cloud & virtualization

Webhooks

HTTPS out

Pushes alerts, detections and state changes out to your own systems: ticketing, ChatOps, or a custom automation pipeline.

Used for: outbound automation
Alert correlation

One incident, not forty pages.

When an upstream link drops, every downstream device reports it at once. Linivo groups related symptoms into a single incident instead of paging on each one.

Topology-aware grouping

Correlation uses your real network topology, so a core-switch outage is recognized as the cause, not just another symptom in the pile.

Baseline-driven thresholds

Alerts trigger on deviation from a device's own learned baseline, not a single static number that's wrong for half your fleet.

Severity that reflects blast radius

An incident's severity accounts for how many services and users are downstream, not just which single device tripped a threshold.

Maintenance windows that actually suppress

Scheduled maintenance suppresses the alerts it should and nothing else, so a planned reboot doesn't page the whole rotation.

Threat & anomaly detection

The same flow data, read for a second signal.

Nothing extra to deploy. The NetFlow, SNMP and syslog records already collected for performance are also scored for the patterns that indicate compromise.

Lateral-movement detection

Flags east-west traffic patterns between hosts that don't normally talk to each other, a common signature of an attacker moving through a network.

Port-scan & recon detection

Sequential or unusual connection attempts across a range of ports and hosts are surfaced as a detection, not lost in normal traffic noise.

Rogue & shadow device detection

New devices joining the network are checked against your provisioned inventory, so an unauthorized access point doesn't sit unnoticed.

Unified incident timeline

When a performance event and a security event are plausibly related, they merge into one timeline instead of living in two different tools.

See how detections map to your compliance evidence →

Integrations

Fits into the stack you already run.

Alerting & incident response

  • Slack
  • Microsoft Teams
  • PagerDuty
  • Opsgenie

Ticketing & workflow

  • Jira
  • ServiceNow
  • Webhooks, for anything else

Data & infrastructure

  • Grafana
  • Splunk
  • Terraform
  • REST API
  • SAML SSO