Shortlist · 7 products compared
Discovery and troubleshooting tools to use before, and during, a monitoring purchase
For anyone about to request a monitoring quote or start a trial who wants their own numbers, and their own evidence, before the vendor supplies them.

Every monitoring quote on this site starts from a number you are asked to provide: devices, sensors, endpoints, nodes. Most buyers give it from memory or from an asset spreadsheet last touched two years ago, and then watch a vendor’s auto-discovery find forty per cent more on day one of the trial. The subscription tier gets chosen by the vendor’s count, not yours. The cheapest correction is an independent sweep of your own address ranges, done with a free scanner before anyone sends you a price, so you arrive at the sales call knowing roughly how many things answer on each subnet.
The second free tool earns its keep during the trial. When a probe reports a switch as unreachable, or a latency graph looks nothing like what users describe, someone has to decide whether the product is wrong or the network is. A packet analyzer such as Wireshark settles that with evidence: you can see the SNMP requests the collector actually sends, the replies it gets, and the timing between them. This page compares three desktop tools with the discovery built into four platforms we already review. Two of them, Wireshark and Angry IP Scanner, are free and open source; the third, LizardSystems Network Scanner, is free only for personal, non-commercial use and needs a paid per-machine licence in a business. The table runs from the free tools this page is about, with the packet analyzer first because nearly every network team already relies on it, to LibreNMS as the free platform with persistent discovery, then the paid products in order of how central discovery is to what you pay for, and last the LizardSystems scanner, a narrower Windows tool for listing file shares and web interfaces that has not had a release since July 2021. None of these tools is a monitoring system on its own; they are what you use to buy one well. Use every one of them only on networks you own or are authorized to manage.
Verdict labels are editorial judgements against six buyer questions, not scores or user ratings. Read how we assess products before relying on them.
Side by side
The comparison table
Pricing is described as a model, not a figure: most vendors quote by estate size, and published prices change. Check each vendor’s pricing page before budgeting.
| Product | Licence | Pricing model | Deployment | Key feature | Best for | Verdict |
|---|---|---|---|---|---|---|
| WiresharkWireshark Foundation | Free, open source (GPLv2) | No licence fee | Desktop application plus the TShark command line | Protocol-level decoding with display filters and conversation statistics | Settling “is it the network or the application?” with evidence | DIY baselineThe referee you call when a trial result looks wrong. A diagnostic tool, not a monitor. |
| Angry IP ScannerAnton Keks | Free, open source (GPLv2) | No licence fee | Desktop application, runs on demand | Fast ping sweep of a range with hostnames, open ports and CSV export | Counting what is on your network before you ask a vendor for a quote | DIY baselineAnswers “how many devices do we really have?” in minutes. It counts; it does not watch. |
| LibreNMSLibreNMS community | GPLv3 | No licence fee; community support | Self-hosted (Linux) | SNMP auto-discovery with wide network vendor coverage | Network-heavy estates that need port graphs more than server checks | DIY baselineSuperb SNMP coverage for nothing; support is a forum, not a contract. |
| AuvikAuvik Networks | Commercial subscription (SaaS) | Subscription per billable network device; quote-based | Cloud (SaaS) with an on-site collector | Automatic topology maps and config backup | Lean IT teams and MSPs looking after several sites | ShortlistFastest route to a useful network map; costs follow your switch and firewall count. |
| PRTG Network MonitorPaessler | Commercial subscription | Subscription tiered by sensor count | Self-hosted (Windows Server) or vendor-hosted | One console for SNMP, flow, WMI and ping checks with ready-made maps | Small IT teams that want a single tool and a predictable annual bill | ShortlistEasy to budget once you know your sensor count; the counting is the hard part. |
| ManageEngine OpManagerManageEngine (Zoho) | Commercial (subscription or perpetual) | Per monitored device, by edition | Self-hosted (Windows or Linux) | Broad device templates plus built-in workflow automation | Mid-size teams that want per-device pricing they can forecast | ShortlistStrong value per device; expect to spend time tidying defaults and alert rules. |
| LizardSystems Network ScannerLizardSystems | Free for personal use; paid business licence | Perpetual licence per machine for business use; free for personal, non-commercial use | Windows desktop application, runs on demand | Inventory of SMB/NetBIOS shares, FTP and web resources with read/write access checks | A quick inventory of Windows file servers and shares before you scope a monitoring purchase | SituationalUseful for mapping shares and access rights on Windows networks; no release since July 2021, so weigh its age. |
Scale changes the answer
What buying looks like at three sizes
Usually one or two /24 subnets. A ping sweep with hostname lookup finishes in a few minutes and gives you a list worth reconciling line by line against DHCP leases. At this size the count decides whether you sit in an entry tier or one step above it.
Several VLANs and probably a couple of sites. Sweep each subnet from a machine that can route to it, note which ranges block ICMP, and record printers, phones and access points separately: vendors disagree most about whether those count as billable devices.
A desktop sweep still helps as a sanity check, but at this scale compare it with the discovery results of a trial collector and with your IPAM. Packet capture becomes more useful here, because distributed polling problems are harder to see from a console alone.
Before you request a quote
A five-point buyer’s checklist
- Get written permission first
Sweep and capture only on networks you are responsible for, and put the scope in writing if a manager, client or provider could reasonably ask. Tell the security team: a scan can trip intrusion alerts, and that is not a trial result you want to explain.
- Sweep every subnet, not just the one you sit on
List your VLANs and ranges from the router or firewall configuration, then scan each. A count from a single office subnet will understate the estate and the quote alike.
- Classify before you count
Export the results and add a column for device type. Switches, firewalls and servers are almost always billable; phones, printers and wireless clients vary by vendor. Ask each vendor how they count the same list.
- Re-run the sweep during the trial
Compare the vendor’s discovered inventory with your own list in the first week. Devices it missed will be unmonitored after purchase; devices it added may be inflating the licence.
- Capture before you blame
When a trial alert looks wrong, take a short packet capture on the collector’s interface. If requests leave and replies never return, the problem is the path or the credentials, and the product deserves a fair second look.
Why paid products appear on a page about free tools
Auvik, PRTG and OpManager all discover devices on their own, and LibreNMS does so for free, so it is reasonable to ask why a desktop scanner is needed at all. The answer is independence. A vendor’s discovery is part of the product you are evaluating, and it is also the tool that decides your licence count. Checking it against a sweep you ran yourself is basic procurement hygiene, in the same way you would not let a contractor measure the room they are quoting to paint. Once the purchase is made, the platform’s discovery takes over and the desktop tools go back to occasional troubleshooting.
Where to go next
Vendor sites and deeper reading
- Wireshark reviewDownload
- Angry IP Scanner reviewDownload
- LibreNMS reviewDownload
- Auvik reviewDownload
- PRTG Network Monitor reviewDownload
- ManageEngine OpManager reviewDownload
- LizardSystems Network Scanner reviewDownload
Every “Official site” link goes directly to the vendor’s own website. None is an affiliate link and no vendor pays for its position — see our affiliate disclosure.
- ComparisonAuvik vs PRTG: cloud network management or all-round monitoring?
- ComparisonPRTG vs ManageEngine OpManager: sensor tiers or per-device licensing?
- ComparisonPRTG vs SolarWinds NPM: which monitoring platform fits your budget and team?
- GuideHow to estimate how many PRTG sensors you need
- GuidePer sensor, per device, per node: network monitoring pricing explained
- GuideNetwork monitoring requirements checklist for buyers (RFP-ready)
- GuideA 14-day plan for trialling network monitoring software
Questions buyers ask
FAQ
Why count devices myself if the vendor’s trial discovers them automatically?
Because the trial count becomes the licence count, and auto-discovery tends to include things you would never pay to watch. A quick independent sweep gives you a baseline to argue from, and it shows whether the vendor’s discovery missed anything on subnets its collector could not reach.
Is it legal to scan my own network with an IP scanner?
Scanning networks you own or administer is routine IT work, but check your organisation’s policy and any contracts with managed providers or landlords who share infrastructure. Never scan address ranges you are not authorized to manage, and let your security team know before a sweep so alerts are expected.
Does a ping sweep find every device?
No. Hosts with local firewalls that drop ICMP, devices asleep at the time, and anything on a subnet your machine cannot route to will be missed. Treat a sweep as a floor, add port checks for silent hosts, and reconcile the result with DHCP leases and switch MAC tables.
How does packet capture help during a monitoring trial?
It lets you see exactly what the monitoring collector sends and receives. If SNMP requests go out with the wrong community or version, or replies arrive after the product’s timeout, the capture shows it within minutes, which stops you rejecting a product for a problem in your own configuration.
Is LizardSystems Network Scanner free for business use?
No. The vendor offers it free for personal, non-commercial use only; using it at work needs a business licence, sold per machine as a perpetual licence. Its pages describe the evaluation period inconsistently, so read the current licence terms on lizardsystems.com before running it on a company network.
Can Wireshark, Angry IP Scanner or LizardSystems Network Scanner replace a monitoring platform?
No. None of them stores history, sends alerts or runs unattended as a monitor. They are point-in-time tools for counting and diagnosing. For continuous monitoring without a licence fee, look at LibreNMS or Zabbix; for a supported commercial product, see the other shortlists.
Other shortlists: Network Monitoring for Small Business · Enterprise Network Monitoring · Cloud-Managed Network Monitoring. Starting a trial? Read how to start one safely from the vendor’s site.