Your link is full and the graph cannot say why. You need to see whose traffic it is and which route it took — Kentik joins router flow to BGP routes, device metrics, four clouds’ flow logs and synthetic tests in one SaaS, from US$2,000 a month — now an Infoblox company, hosted in the US or Frankfurt.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Kentik — network observability, acquired by Infoblox in August 2026. The rest of the Infoblox line:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It joins flow records, routing and device metrics, so you see who used a link and which path the traffic took.
What consolidation actually replaces, dimension by dimension.
| Dimension | SNMP graphs and guesswork | Kentik |
|---|---|---|
| Who used the link | SNMP graphs show it full, not by whom | Flow joined to BGP names the source and route |
| Cloud traffic | A separate console per cloud account | AWS, Google Cloud, Azure and OCI flow logs together |
| Branch slowness | Ping from the data centre and guess | Synthetic path tests from agents in the branch |
| DDoS response | Customers call, then someone checks | Flow-based alert, RTBH or FlowSpec mitigation |
| Asking a question | Write the query by hand | AI Advisor plans and runs the queries |
| What it is NOT | — | APM, India-hosted, or inside the Infoblox Portal yet |
The cheapest test is the free 30-day trial: point two routers at a Universal Agent, replay a past incident, and see what it explains.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Your routers and switches export NetFlow, sFlow or IPFIX and answer SNMP or streaming telemetry; AWS, Google Cloud, Azure and OCI publish VPC flow logs to buckets.
The Universal Agent on a Linux host collects flow and SNMP and encrypts it before it leaves; ksynth agents you place run synthetic tests from your own sites.
Flow is enriched with BGP paths and stored on Kentik’s own equipment, AES-256 at rest, for 45 days at full resolution and 120 days summarised by default.
Data Explorer, Network Explorer, NMS dashboards, Protect alerts and AI Advisor sit in one portal and a full API; Pro allows 50 users and 50 API queries an hour.
Agents on your Linux hosts collect and encrypt flow — Kentik’s SaaS in Virginia or Frankfurt adds routing and answers the query.
Kentik shows whose traffic fills each link, which route it took, and what the devices on that path were doing.
NetFlow, sFlow and IPFIX records are enriched with BGP AS paths and communities, so each flow shows which network it crossed.
The Cloud module reads flow logs from AWS, Google Cloud, Azure and OCI next to on-prem traffic; Pro includes 1,000 cloud flows per second.
Kentik NMS polls SNMP and streaming telemetry; Pro covers 25 devices at up to 250 metrics a second, kept for 13 months.
Tests cover DNS, BGP, network paths, site and cloud meshes, web pages and transactions, paid from a pool of credits; Pro has 2.5 million.
Install the ksynth agent on Linux or Docker in a branch or data centre, and tests run from where your users sit, not only from Kentik’s.
Capacity Planning and Observation Deck show interface utilisation trends, so upgrades are ordered from measured growth, not a guess.
Protect flags attacks from flow and triggers RTBH or FlowSpec mitigation, with RPKI analysis of route validity; it is in Pro.
Ask in plain language; AI Advisor plans the steps, pulls flow, device and test data and suggests a cause. An MCP server exposes it to other agents.
Edge models traffic engineering and peering options and keeps 1,200 cost snapshots on Pro, for teams that buy transit and peer with other networks.
A platform overview across cloud, DDoS and BGP, the AI Advisor agent, AI diagnostics in Kentik NMS, and a Data Explorer walkthrough on NetFlow.
A tour of the platform: cloud traffic, DDoS detection and BGP analysis in one portal.
How the AI Advisor agent turns a plain-language question into a plan of network queries.
AI-assisted diagnosis on device metrics collected by Kentik NMS.
Building a traffic query in Data Explorer from NetFlow records, filters and AI help.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most monitoring tools tell you a link is full. Kentik tells you whose traffic filled it: each flow record is joined to its BGP AS path and community, then sits beside SNMP and streaming-telemetry metrics from the same devices. An engineer can go from a saturated interface to the source network, the destination and the route in one Data Explorer query.
The Cloud module ingests VPC flow logs from AWS, Google Cloud, Azure and OCI into the same store as router flow, and synthetic tests measure the paths between them. For a business whose users sit in Indian branches and whose apps run in a cloud region, that is the view that shows where latency really comes from.
Kentik prints its entry tier: Pro from US$2,000 a month billed annually, with 50 users, 1,000 flows per second, 25 NMS devices and 2.5 million synthetic credits. A free 30-day trial comes first. SSO and audit logs are in Pro, not held back for a higher tier, and Protect’s DDoS detection is included too.
Data lives in Ashburn, Virginia or Frankfurt, with no India region. The list is US pricing; international buyers are asked to contact sales, and contracts are annual only. It sees the network, not application code: it is no APM. AI Advisor sends queries to LLM providers including OpenAI and Google. Infoblox integration is promised over time, not shipped.
List the routers, switches and cloud accounts that will export, and measure peak flows per second so Pro’s 1,000 FPS is tested.
Choose Ashburn or Frankfurt, decide which IP fields to redact before ingest, and record the cross-border flow for your DPDP review.
Install a Universal Agent, point two core routers and one cloud account at it, and enable Kentik AI only if your policy allows it.
Place ksynth agents in two branches, replay a past slowdown or attack, and check Protect’s alert and the path tests against your logs.
Take measured FPS, device count and users into Pro or Premier, list add-ons such as Protect Advanced, and get an international quote.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our Mumbai uplink kept hitting 95%. Kentik showed one video CDN behind most of it, and we fixed it with a peering change.”
“A volumetric attack hit our hosting range at night; Protect raised it from flow and the RTBH route went out within minutes.”
“We placed ksynth agents in six branches. Path tests proved the slowness was the ISP’s hop, not our SD-WAN policy.”
“Cloud flow logs from AWS and Azure beside our router flow ended a long argument about inter-region transfer charges.”
“Legal asked where the flow data lives. Frankfurt or Virginia was the answer, so we turned on IP redaction before signing.”
“Strong on flow, but we sized the FPS too low in the trial and the annual quote went up. Measure peak exports first.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the network observability market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Pro from US$2,000 a month, billed annually; now owned by Infoblox.
The grid nobody publishes — how many kinds of network data a tool reads vs whether its data can stay in India.
Flow with BGP, SNMP, cloud logs, synthetics, DDoS; hosted in the US or Frankfurt.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Datadog Network Monitoring, Cisco ThousandEyes, SolarWinds Observability SaaS and Self-Hosted, and Dynatrace — on data covered, price, retention, DDoS, SSO and India.
| Dimension | Kentik | Datadog Network Monitoring | Cisco ThousandEyes | SolarWinds Observability SaaS | SolarWinds Observability Self-Hosted | Dynatrace Application & Infrastructure Observability |
|---|---|---|---|---|---|---|
| What it is | Network analytics SaaS | Datadog network lines | Path and test monitoring | Modular SaaS suite | Self-run network suite | Full-stack APM platform |
| Deployment | SaaS + Linux agents | SaaS + Datadog Agent | SaaS + three agent types | SaaS; on-site collector | Your servers or cloud | SaaS + ActiveGate |
| Network data covered | Flow, BGP, SNMP, clouds | Hosts, devices, flow | Tests and BGP, no flow | Devices and SD-WAN | NPM, flow, NCM, IPAM | Host traffic + SNMP |
| Pricing model | Annual tiers by FPS | Per host, device, record | Monthly units by test | Per node, per module | Per node, multi-year | Per host, from a DPS |
| Published entry price | $2,000/month, annual | $5/host, $7/device | Not published | $15.75/node/month | $8/node/month | $29/host/month |
| Included vs add-on | Most modules in Pro | Every product separate | Units for agent tests | Each module apart | Tiers bundle modules | Logs priced apart |
| Retention and scale | 45 days full flow | Flow 15 to 90 days | Scales with test rate | Logs kept 1–60 days | Enterprise from 500 | Priced by host memory |
| Routing and DDoS security | DDoS, RTBH, RPKI | No mitigation listed | BGP route monitoring | Not in the modules | Flow, but you patch | Not on its rate card |
| Cloud and integrations | 4 clouds, API, MCP | 1,000+ integrations | Agents on Cisco gear | OTel-native APM | DPA, ServiceNow | OneAgent, Hub extensions |
| Governance and SSO | SSO and audit log in Pro | SAML SSO | SAML JIT and SCIM | SAML 2.0 SSO | SAML 2.0 sign-in | SAML and SCIM 2.0 |
| India data location | Virginia or Frankfurt | No India site | US1, US2 or EU1 | US, Frankfurt, Australia | Your servers, in India | AWS Mumbai region |
| Support | RapidStart, paid help | USD billing, terms apart | Ask Cisco for targets | Portal; SLA unpublished | Training included | Ask for targets |
| Lock-in and exit | Annual only, open inputs | On-demand rates exist | History stays put | Multi-year, OTel exit | Polling stops at expiry | Annual subscription |
| Best fit | BGP-running networks | Datadog shops | Internet path problems | Hybrid IT, one bill | Data must stay in-house | App-first, India region |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Kentik is one of 23 observability & APM products TechBag carries. The Observability & APM guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (network devices exporting flow or SNMP; engineer-hour cost). Estimates model engineering time spent tracing congestion, slow branches and traffic spikes by hand at an assumed 1.5 hours per device a year, with 70% of it removed by flow joined to routing and device data. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Kentik Pro is from US$2,000 a month, billed annually ($24,000 a year), with 50 users, 1,000 flows per second, 25 NMS devices and 2.5 million synthetic credits; SSO, audit logs and Protect DDoS detection are included. Premier is on quote. Contracts are annual only, after a free 30-day trial, and the list is US pricing. TechBag measures your flow first, then quotes in INR with GST.
Best for one network team and a few sites
Best for a broader rollout
Best for large and provider networks
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your peak flows per second across routers and cloud logs? Pro includes 1,000 of each; overage changes the tier.
How many devices need NMS polling? Pro covers 25 at up to 250 metrics a second; count switches and firewalls too.
Is US or Frankfurt hosting acceptable under your DPDP and sector rules, given that no India region exists?
Which IP address fields should be redacted before ingest, and does that still leave the analysis you need?
May queries and context go to LLM providers such as OpenAI and Google? Kentik AI is a setting you can leave off.
Are any sites still on kproxy? It reaches end-of-life on 1 May 2027, so plan the Universal Agent move now.
Do you run BGP with upstreams that accept RTBH or FlowSpec? Protect’s mitigation depends on that being in place.
Will the quote be in INR with GST, list add-ons and onboarding, and state retention if you need more than 45 days?
Measure your peak flows and device count first, or let a TechBag advisor scope a 30-day trial on two core routers and one cloud account.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.