Four Bundles, Fourteen Probes
A bundle is the licensing unit: it sets how many monitors (unique targets) its probes may watch at the Starter, Growth or Pro tier. The free tier enables every bundle with 15 Web, 20 Reachability, 10 Performance and 5 Routing monitors. Backends, agents and alerting are never metered. Prices are on the pricing page.
| Bundle | Probe types | Monitor unit | Starter / Growth / Pro caps |
|---|---|---|---|
| Web | HTTP/HTTPS, SSL expiry, DNS | URL or hostname | 50 / 200 / 1,000 monitors |
| Reachability | ICMP ping, batch ping, TCP connect, traceroute, liveness sweep, NTP, path MTU | IP or hostname | 100 / 500 / 2,500 monitors |
| Performance | Native throughput, DNS propagation, SNMP | Agent pair, record or device | 25 / 100 / 500 monitors |
| Routing | BGP | Session | 10 / 50 / 250 sessions |
Services, Certificates and Names
| Probe | What it does | Metrics recorded |
|---|---|---|
HTTP/HTTPS http | Makes a full request with the method, headers, body, basic auth or API key you configure, follows redirects, and checks the status against an expected list and the body against validation rules. A transport failure records status 0 so dashboards show the outage, not a gap. | status_code, dns_ms, connect_ms, tls_ms, ttfb_ms, transfer_ms, total_ms, body_bytes, body_sha256, redirect_count, final_url, curated response headers |
SSL expiry ssl_expiry | Completes a TLS handshake (SNI configurable), then validates the chain separately against the system roots or your own CA bundle, so a broken or expired certificate still yields a full result instead of an error. | cert_days_remaining, cert_not_before, cert_not_after, cert_chain_valid, issuer, subject, serial, signature algorithm, key type and size, cert_san, tls_version, tls_cipher_suite, handshake_ms |
DNS dns | Queries the system resolver (A, AAAA, CNAME, MX, TXT, NS) or named resolvers (adds SOA, PTR, SRV) and compares the answer with an expected value. Detects resolver failures, slow answers and wrong records. | resolution_ms, resolver_used, rcode, answer_count, ttl_seconds, answers |
Latency, Loss, Paths and Plumbing
| Probe | What it does | Metrics recorded |
|---|---|---|
ICMP ping ping | Sends ICMP echo requests and measures round-trip time and loss. Uses unprivileged datagram ICMP first and a raw socket only as a fallback. Intervals down to 1 second; count capped at 100 per run. | min_rtt_ms, avg_rtt_ms, max_rtt_ms, mdev_rtt_ms, loss_pct, packets_sent, packets_received, packets_lost |
Batch ping batch_ping | Pings many targets in parallel from a single configuration entry, so a sweep of thousands of hosts finishes in seconds. One summary row plus a per-target breakdown. | total_targets, targets_succeeded, targets_failed, aggregate_loss_pct, per_target (RTT and loss per host) |
TCP connect tcp | Times a TCP connection to a port and optionally reads the banner. The reachability check for services that are not HTTP. | connect_success, handshake_ms, bytes_read |
Traceroute traceroute | Sends UDP probes with rising TTL; ICMP Time Exceeded replies identify each hop. Hashes the path, compares it with the previous run, enriches every hop with its autonomous system, and keeps the old path when a change is detected. | total_hops, timeout_hops, path_changed, previous_path_hash, hops (address and RTT per hop), as_path, as_path_changed, distinct_as_count |
Liveness sweep alive | One ICMP echo (or a TCP connect) per device across a whole fleet: answers "is it up", without RTT statistics, as a replacement for fping. Emits a sweep summary and one row per device, with coordinates for map dashboards. | mode, total_devices, alive_count, dead_count, sweep_duration_ms, per-device connect_ms, lat, lon |
NTP ntp | Sends SNTP queries to each server in a pool and derives offset, delay and jitter from the four NTP timestamps. Reports the best server and whether a quorum answered. Catches the clock drift that breaks TLS and log correlation. | offset_ms, jitter_ms, delay_ms, stratum, servers_total, servers_reachable, quorum_met |
Path MTU mtu | Sends ICMP echoes with the DF bit set and binary-searches for the largest packet that gets a reply, between 576 and 1500 bytes by default. Finds MTU black holes on VPN and overlay tunnels that plain ping misses. | discovered_mtu, failure_mode, probes_sent, min_mtu, max_mtu |
Bandwidth, Propagation and Devices
| Probe | What it does | Metrics recorded |
|---|---|---|
Native throughput throughput | An in-process iperf3 replacement. One agent dials another agent's throughput server (port 5202 by default) over mTLS with the certificates the master issued and streams TCP for a bounded duration or byte count, up to 60 seconds per test. | bandwidth_bps, bytes_sent, bytes_received, connect_ms, throughput_duration_ms, tcp_retransmits (Linux) |
DNS propagation dns_propagation | Asks up to 32 resolvers (your list, or Cloudflare, Google, Quad9, OpenDNS, Verisign and Level3) for the same record, eight at a time, and reports whether they agree. The check to run after a DNS change. | resolvers_total, resolvers_succeeded, resolvers_consistent, consistency, per_resolver (answer and latency per resolver) |
SNMP snmp | SNMPv3 only. Bulk-walks ifTable and ifXTable and emits one result per interface, one per device and one per sensor. Credentials come from environment variables or sealed secrets. Points at the specific link behind an end-to-end loss figure. | Per interface: in_bps, out_bps, in_util_pct, out_util_pct, error and discard rates, oper_status, admin_status, flapped. Per device: interface census, cpu_load_pct, mem_used_pct, health_alarms. Per sensor: sensor_value, alarm |
Prefixes and Origins
| Probe | What it does | Metrics recorded |
|---|---|---|
BGP bgp | Verifies that each configured prefix is announced by the expected origin AS and records announced and withdrawn prefixes, path changes and flaps. AS-path changes on the forwarding path are detected by the traceroute probe, so the two together show both what is announced and what traffic actually does. | session_state, session_up, announced, withdrawn, path_changes, flap_count, uptime_seconds, prefixes (per-prefix detail) |
One Envelope, Any Backend
Every probe result carries the same envelope: the probe name and type, the target, the agent that ran it, a success flag and error class, the labels you attached, optional coordinates for map dashboards, and the timestamp. The metrics above sit inside it. In PostgreSQL each probe type gets its own typed table, partitioned by month; in InfluxDB each becomes a measurement; in Elasticsearch a document; in Prometheus a set of gauges. The probe reference in the documentation has every configuration field.
Standards and references
The protocols these probes speak, and the backends they write to:
- RFC 792, Internet Control Message Protocol (ping, traceroute, liveness sweep, path MTU)
- RFC 1191, Path MTU Discovery
- RFC 1035, Domain Names (DNS and DNS propagation)
- RFC 9110, HTTP Semantics, and RFC 8446, TLS 1.3 (HTTP and SSL expiry probes; TRCR's own master/agent transport)
- RFC 4330, SNTP, and RFC 5905, NTPv4 (NTP probe)
- RFC 3414, SNMPv3 User-based Security Model (SNMP probe)
- RFC 4271, BGP-4 (BGP probe)
- PostgreSQL table partitioning, InfluxDB v2 write API, Elasticsearch bulk API, Prometheus remote write
Every probe type, free to try
Every Bundle on the Free Tier, Forever
5 agents and 50 monitors across all four bundles.
Install in a minute, no credit card.