v3.0 in progress
IPMG
Network monitoring from the command line
Python tool that finds which hosts on your network are up and what changed since last time: parallel ping sweeps, reverse DNS, scan history and diffs, Excel/CSV/JSON/Markdown reports and a local web UI.
- Python
- Networking
- CLI
01 problem
Ping sweeps tell you what's up right now. The question people who look after a network actually have is "what changed since yesterday?": which host went offline, which address moved, whose latency jumped. Tools like nmap -sn and fping don't keep history or tell you what changed.
02 approach
- 01 Store every scan in a local SQLite history, shared by the CLI and the web UI, so any two scans can be compared.
- 02 Classify every change by severity: a host going offline is
critical; a new host, moved IP or changed status iswarning; recovery, a renamed host or a latency shift isinfo. - 03 Report latency changes only when they clear both an absolute (5 ms) and a relative (25%) threshold, which keeps normal jitter out of reports.
- 04 Make it automatable: exit codes for cron and CI, and notifications to Slack, Teams, a webhook or email filtered by severity.
- 05 Expose results to existing observability: an optional Prometheus
/metricsendpoint with bounded cardinality (host series carry onlysourceandip).
03 architecture
-
01 · targets
-
02 · scan
-
03 · store
-
04 · compare
-
05 · deliver
trigger · file · CIDR · --discover
targets
IPs, CIDR blocks and ranges from a file or the command line, or --discover to scan the network you're on. IPv4 and IPv6 are supported.
All steps as text
-
1. targets
- targets: IPs, CIDR blocks and ranges from a file or the command line, or --discover to scan the network you're on. IPv4 and IPv6 are supported.
-
2. scan
- parallel ping sweep: One system ping per host, run in parallel with a bounded thread pool, plus reverse DNS for hostnames. Optional TCP connect checks on common ports.
-
3. store
- scan history: Every scan is stored locally and shared by the CLI and IPMG Web, so any two scans can be compared later. By default, comparisons only use scans of the same target source.
-
4. compare
- ipmg diff: Compares two scans and classifies every change by severity. Latency changes must clear both an absolute and a relative threshold to count.
-
5. deliver
- reports: Scan reports and change summaries in Excel, CSV, JSON and Markdown that you can hand to someone.
- alerts & metrics: Notifications for changes at or above --notify-severity, and an optional Prometheus endpoint so results land in existing dashboards and alert rules.
In practice
pip install ipmg
ipmg --discover # scan the network you are on, right now
ipmg --discover --compare # later: scan again and see what changed
Compare any two stored scans. --fail-on-change turns it into a CI or cron gate:
ipmg --input targets.txt --compare # compare with the previous scan
ipmg diff 12 14 # compare two specific scans
ipmg diff --fail-on-change # exit 2 when anything changed (CI)
Only send the changes that matter:
ipmg --input targets.txt --interval 15 --notify-slack
ipmg diff --notify-webhook https://ops.example.com/ipmg --notify-severity critical
Results can feed the Prometheus and alerting setup you already have:
# an alert rule: a host that stopped answering
groups:
- name: ipmg
rules:
- alert: HostDown
expr: ipmg_host_up == 0
for: 10m
annotations:
summary: "{{ $labels.ip }} ({{ $labels.source }}) is not answering ping"
05 outcome
- Published on PyPI as
ipmg. Parallel ping sweeps over IPs, CIDR blocks and ranges (IPv4 and IPv6), with reverse DNS. - Change reports with severities, exportable as Markdown, JSON or CSV, plus Excel/CSV/JSON/Markdown scan reports.
- IPMG Web: a local dashboard that works offline, with a Changes view comparing any two scans.
- v3.0 is in progress.