Platform · Deep Collection
Up/down tells you a light went off. Phantom tells you why. It collects protocol-level state from every multi-vendor device over SNMP and SSH, and keeps it as time-series history you can rewind.
Coverage
Advertised/received prefixes with AS-path, local-pref, MED, communities and next-hop — see not just what was chosen, but why.
Groups, members, (S,G) trees, RPF, PIM and outgoing-interface lists, with source→receiver path discovery.
Per-tenant tables with route distinguishers and import/export targets — every route attributed to the right customer.
Labels, FECs, MPLS interfaces and LDP neighbors — the invisible label plane, made auditable.
Full RIB per device with next-hop, protocol, admin distance and metric — snapshotted to detect path changes.
Latency, packet loss and jitter against contracted thresholds, for objective SLA evidence.
Status, traffic, errors and utilization per port, with per-interface monitoring controls.
Neighbor adjacencies for topology, plus IP↔MAC↔port mapping for endpoint tracking.
Detect flapping and profile it — duty cycle, period and confidence — to separate a one-off from an oscillation.
Time-series by design
Each snapshot is stamped first_seen / last_seen, so "what changed, and when" is a query — not a war room. Diff any two points in time across routing, BGP, multicast, VRF and more.