Sign inSign up

rickraven/conntrack-exporter

By rickraven

•Updated 8 months ago

Prometheus exporter that reads the current Linux connection tracking table

Image
Monitoring & observability
0

1.3K

rickraven/conntrack-exporter repository overview

⁠conntrack-exporter

Prometheus exporter that reads the current Linux connection tracking table from /proc/net/nf_conntrack and exports traffic metrics (packets/bytes) plus aggregated totals.

The exporter periodically takes a snapshot of nf_conntrack and caches the resulting metrics until the next read.

Source code avaliable on github⁠

⁠How it works

  • Data source: /proc/net/nf_conntrack.
  • Polling interval is controlled by --collector.interval (seconds).
  • On each refresh the exporter recreates the per-connection metric set (old label pairs are deleted).
  • Connections are aggregated by the key:
    • src ip, dst ip, l3protocol, l4protocol, dport, l7protocol
    • source port is NOT part of the key, so entries with the same src/dst/dport but different source ports are summed.

⁠Grafana dashboard

You can add grafana dashboard to visualize the exporter data. The dashboard code is in the file⁠.

dashboard

⁠Required system configuration (sysctl)

For the kernel to include packets/bytes counters in /proc/net/nf_conntrack, you must enable:

  • net.netfilter.nf_conntrack_acct=1

If the value is 0, the exporter will still run, but conntrack entries may miss packets/bytes fields or provide zero values (making traffic metrics incorrect).

Check the current value:

sysctl net.netfilter.nf_conntrack_acct

Enable until reboot:

sudo sysctl -w net.netfilter.nf_conntrack_acct=1

Make it persistent (example):

echo 'net.netfilter.nf_conntrack_acct=1' | sudo tee /etc/sysctl.d/99-conntrack-exporter.conf
sudo sysctl --system

The exporter also supports best-effort auto-configuration on startup:

  • --configure.nf_conntrack_acct

Note: this typically requires root privileges (or equivalent capabilities), otherwise a warning will be logged.

⁠Running in Docker

In containers there are two important points:

  • The exporter reads nf_conntrack from procfs. To read the host conntrack table, you must mount the host /proc into the container and point --path.procfs to that mount point.
  • If the container runs in its own network namespace, you will see container conntrack, not the host's. For host metrics, use the host network namespace.

Run example (replace the image name with yours):

docker run --rm \
  --name conntrack-exporter \
  --net=host \
  --pid=host \
  -v /proc:/host/proc:ro \
  conntrack-exporter:latest \
  --path.procfs=/host/proc \
  --web.listen-address=:9095 \
  --web.telemetry-path=/metrics

Tag summary

Content type

Image

Digest

sha256:d47619ed8…

Size

3.3 MB

Last updated

8 months ago

docker pull rickraven/conntrack-exporter