Two philosophies for seeing what your network is doing — and the real trade-offs between them.
The short version
- Every network monitoring tool makes a fundamental choice before it even starts collecting data: does it install something on each host, or does it…
- Agentless monitoring draws on sources the network produces naturally — SNMP counters from routers and switches, NetFlow/IPFIX or sFlow records from flow-capable devices, proxy…
- Agent-based tools install a small process on each host.
01The Fork in the Road
Every network monitoring tool makes a fundamental choice before it even starts collecting data: does it install something on each host, or does it read what the infrastructure already emits? The first approach is agent-based; the second is agentless.
Agentless monitoring draws on sources the network produces naturally — SNMP counters from routers and switches, NetFlow/IPFIX or sFlow records from flow-capable devices, proxy and firewall logs, and DNS query logs. Nothing touches the endpoints. Internet Access Monitor, Red Line Software's proxy-log analyser, was agentless by design: point it at the logs your proxy was already writing and it told you who was visiting what, how often, and how much bandwidth they consumed. The same principle drives most of today's flow-based tools — ntopng, ElastiFlow, PRTG's flow receiver — and DNS-layer monitors like Pi-hole or Cisco Umbrella. The infrastructure does the talking; the monitor just listens.
Agent-based tools install a small process on each host. That process can see things no passive listener can: per-application bandwidth broken down by process name, local DNS activity before it even leaves the machine, or exact user identity without relying on proxy-authentication headers. Tools like Zabbix with its agent, Datadog's agent, or endpoint-aware CASB clients work this way. The trade-off is real: you have software to deploy, maintain, update and trust on every machine in scope.
The practical split usually looks like this. Agentless wins on deployment speed and breadth — a single NetFlow source or a central DNS resolver gives you visibility across every device on the segment, including IoT kit and guest Wi-Fi, without touching any of them. Agents win on precision: if you need to know that it was the Chrome browser, not a background updater, consuming the link, a host-side process tells you what a flow record cannot. Privacy falls similarly. Agentless techniques — flows, DNS, proxy logs — deal in metadata and volumes, not content. An agent could be written to capture more, so scrutinise what any agent actually collects and ensure it stays at the metadata layer.
For most small and mid-size environments the agentless stack is sufficient and far easier to justify to users and management alike. Reserve agents for specific gaps — endpoint attribution, per-app reporting — where the deployment cost and governance overhead genuinely earn their keep.

