[GH-ISSUE #3935] Add Traffic Events Logging in Open-Source Version #8121

Open
opened 2026-08-05 01:16:05 -04:00 by saavagebueno · 20 comments
Owner

Originally created by @kkatiyar-jrni on GitHub (Jun 5, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/3935

Is your feature request related to a problem? Please describe.
In self-hosted environments, there's often a strong need to track user activity for audit and compliance purposes — such as when a user connects to a peer, initiates traffic, or accesses specific internal services. Currently, there is no built-in support for traffic event logging in the open-source version of NetBird, making it difficult to maintain an audit trail.

Describe the solution you'd like
I would like to request that traffic events logging (including source peer, destination peer, timestamp, direction, and volume or protocol if possible) be included in the open-source version. This would help operators monitor user access patterns, maintain security posture, and generate audit reports for compliance.

Describe alternatives you've considered

Enterprise version may support this, but it's not viable for community or internal teams with budget or policy constraints.

Additional context
Audit logs are a standard requirement in many organizations, even for internal tools. Making basic activity logging available to the open-source community would significantly improve NetBird’s value in privacy-conscious and regulated environments.

Originally created by @kkatiyar-jrni on GitHub (Jun 5, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/3935 Is your feature request related to a problem? Please describe. In self-hosted environments, there's often a strong need to track user activity for audit and compliance purposes — such as when a user connects to a peer, initiates traffic, or accesses specific internal services. Currently, there is no built-in support for traffic event logging in the open-source version of NetBird, making it difficult to maintain an audit trail. Describe the solution you'd like I would like to request that traffic events logging (including source peer, destination peer, timestamp, direction, and volume or protocol if possible) be included in the open-source version. This would help operators monitor user access patterns, maintain security posture, and generate audit reports for compliance. Describe alternatives you've considered Enterprise version may support this, but it's not viable for community or internal teams with budget or policy constraints. Additional context Audit logs are a standard requirement in many organizations, even for internal tools. Making basic activity logging available to the open-source community would significantly improve NetBird’s value in privacy-conscious and regulated environments.
saavagebueno added the feature-requestself-hosting labels 2026-08-05 01:16:05 -04:00
Author
Owner

@M0nk3yOo commented on GitHub (Aug 21, 2025):

Dear NetBird team,

I would also realy realy appreciate that! Would love to see the traffic events and flow information on self hosted as well.
This would helps lot for troubleshooting and to see whats going on.

Best
M0nk3y

<!-- gh-comment-id:3209532075 --> @M0nk3yOo commented on GitHub (Aug 21, 2025): Dear NetBird team, I would also realy realy appreciate that! Would love to see the traffic events and flow information on self hosted as well. This would helps lot for troubleshooting and to see whats going on. Best M0nk3y
Author
Owner

@jvdk-synto commented on GitHub (Aug 22, 2025):

Hi NetBird team,

This would be amazing to have in the self-hosted version.

Many thanks

<!-- gh-comment-id:3213914893 --> @jvdk-synto commented on GitHub (Aug 22, 2025): Hi NetBird team, This would be amazing to have in the self-hosted version. Many thanks
Author
Owner

@i-am-ez76 commented on GitHub (Aug 26, 2025):

YES!! that would be amazing.

<!-- gh-comment-id:3223904351 --> @i-am-ez76 commented on GitHub (Aug 26, 2025): YES!! that would be amazing.
Author
Owner

@Br00dkast commented on GitHub (Sep 18, 2025):

I strongly support this feature request. Simply providing the ability to forward traffic event logs to a syslog server would already be sufficient.

<!-- gh-comment-id:3307321315 --> @Br00dkast commented on GitHub (Sep 18, 2025): I strongly support this feature request. Simply providing the ability to forward traffic event logs to a syslog server would already be sufficient.
Author
Owner

@gata-bbs commented on GitHub (Sep 24, 2025):

+1

<!-- gh-comment-id:3330541037 --> @gata-bbs commented on GitHub (Sep 24, 2025): +1
Author
Owner

@ramyhhh commented on GitHub (Nov 7, 2025):

+1

<!-- gh-comment-id:3501350935 --> @ramyhhh commented on GitHub (Nov 7, 2025): +1
Author
Owner

@sevensolutions commented on GitHub (Nov 21, 2025):

In my case i especially want to know the amount of traffic flowing somewhere and through "which" routing peer.
It would be really cool if this could be integrated in the new control center with some kind of animation, like in the Unifi controller.

Image

Here is the animation:
https://www.4gon.co.uk/gb/wp-content/uploads/2023/09/unifi-blog01.gif

<!-- gh-comment-id:3563848113 --> @sevensolutions commented on GitHub (Nov 21, 2025): In my case i especially want to know the amount of traffic flowing somewhere and through "which" routing peer. It would be really cool if this could be integrated in the new control center with some kind of animation, like in the Unifi controller. <img width="860" height="464" alt="Image" src="https://github.com/user-attachments/assets/93176240-bb77-4e14-b11c-6daedaa2b11f" /> Here is the animation: https://www.4gon.co.uk/gb/wp-content/uploads/2023/09/unifi-blog01.gif
Author
Owner

@WHOOHAA commented on GitHub (Dec 31, 2025):

This would be amazing and would help with problem-solving network issues caused by devices authorized on the network. Like an accidental self DOS of my webserver due to a reverse proxy and DNS misconfiguration(might have happened once or twice).

I believe others including myself will donate when we have funds available in the future just due to all of the futures you have moved from enterprise to open-source. It means alot to the community and is why I chose NetBird over TailScale to be honest.
:)

Between you guys and proxmox I am a happy camper :)

<!-- gh-comment-id:3701533360 --> @WHOOHAA commented on GitHub (Dec 31, 2025): This would be amazing and would help with problem-solving network issues caused by devices authorized on the network. Like an accidental self DOS of my webserver due to a reverse proxy and DNS misconfiguration(might have happened once or twice). I believe others including myself will donate when we have funds available in the future just due to all of the futures you have moved from enterprise to open-source. It means alot to the community and is why I chose NetBird over TailScale to be honest. :) Between you guys and proxmox I am a happy camper :)
Author
Owner

@killmasta93 commented on GitHub (Jan 14, 2026):

+1

<!-- gh-comment-id:3751005606 --> @killmasta93 commented on GitHub (Jan 14, 2026): +1
Author
Owner

@mfuezesi commented on GitHub (Jan 24, 2026):

+1
That would be amazing!

<!-- gh-comment-id:3794140896 --> @mfuezesi commented on GitHub (Jan 24, 2026): +1 That would be amazing!
Author
Owner

@filipem-dev commented on GitHub (Mar 11, 2026):

+1

<!-- gh-comment-id:4039579640 --> @filipem-dev commented on GitHub (Mar 11, 2026): +1
Author
Owner

@fuomag9 commented on GitHub (Mar 12, 2026):

Agreed, this would be awesome

<!-- gh-comment-id:4048729855 --> @fuomag9 commented on GitHub (Mar 12, 2026): Agreed, this would be awesome
Author
Owner

@dipakchaulagain commented on GitHub (Mar 25, 2026):

Agreed, being able to log basic events would be the cherry on top for this tool. I recently found this and tried it myself. It provides a simple but important migration from traditional VPN solutions like OpenVPN to a solution with better compliance and security focus. However, the lack of traffic event logging is a bottleneck for production deployment.

<!-- gh-comment-id:4128373639 --> @dipakchaulagain commented on GitHub (Mar 25, 2026): Agreed, being able to log basic events would be the cherry on top for this tool. I recently found this and tried it myself. It provides a simple but important migration from traditional VPN solutions like OpenVPN to a solution with better compliance and security focus. However, the lack of traffic event logging is a bottleneck for production deployment.
Author
Owner

@klinkeye commented on GitHub (May 1, 2026):

This is a basic system functionality and troubleshooting feature that should be integral to the core product, both paid and community self hosted version.

Like has already been suggested, forwarding of events at a minimum should be considered. The event hooks would already be there.

<!-- gh-comment-id:4362375969 --> @klinkeye commented on GitHub (May 1, 2026): This is a basic system functionality and troubleshooting feature that should be integral to the core product, both paid and community self hosted version. Like has already been suggested, forwarding of events at a minimum should be considered. The event hooks would already be there.
Author
Owner

@Flaxarn commented on GitHub (May 15, 2026):

I would really like this feature with the integrations futures for extrnal siem like wazuh or security onion, both uses elastic agents and online version supports wazuh.
I would also in normal dashboard interafce have some logging visualtiy in to usage of relay/routing/exit/proxy nodes and their performance metrics

<!-- gh-comment-id:4459456709 --> @Flaxarn commented on GitHub (May 15, 2026): I would really like this feature with the integrations futures for extrnal siem like wazuh or security onion, both uses elastic agents and online version supports wazuh. I would also in normal dashboard interafce have some logging visualtiy in to usage of relay/routing/exit/proxy nodes and their performance metrics
Author
Owner

@fuad00 commented on GitHub (May 19, 2026):

+1

<!-- gh-comment-id:4493429313 --> @fuad00 commented on GitHub (May 19, 2026): +1
Author
Owner

@patsevanton commented on GitHub (May 19, 2026):

+2

<!-- gh-comment-id:4493515738 --> @patsevanton commented on GitHub (May 19, 2026): +2
Author
Owner

@Brainpitcher commented on GitHub (May 20, 2026):

+3

<!-- gh-comment-id:4502088101 --> @Brainpitcher commented on GitHub (May 20, 2026): +3
Author
Owner

@st4rburn commented on GitHub (May 30, 2026):

This is also a feature I’d find really valuable. I host a small setup in my homelab which is going to open up to external users soon as a gateway to a private internet. As I don’t know everyone who’ll be using it personally, the logging is important to detect misuse. It’s a small hobby project so there’s no way I could justify using the cloud version, logging is really just a core security feature that’s missing in the open source version.

<!-- gh-comment-id:4585401074 --> @st4rburn commented on GitHub (May 30, 2026): This is also a feature I’d find really valuable. I host a small setup in my homelab which is going to open up to external users soon as a gateway to a private internet. As I don’t know everyone who’ll be using it personally, the logging is important to detect misuse. It’s a small hobby project so there’s no way I could justify using the cloud version, logging is really just a core security feature that’s missing in the open source version.
Author
Owner

@ChillarAnand commented on GitHub (Jun 21, 2026):

https://netbird.io/knowledge-hub/enhancing-network-visibility-with-traffic-events-logging

Any plans on pushing this feature to self hosted version?

<!-- gh-comment-id:4762604992 --> @ChillarAnand commented on GitHub (Jun 21, 2026): https://netbird.io/knowledge-hub/enhancing-network-visibility-with-traffic-events-logging Any plans on pushing this feature to self hosted version?
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#8121