Prometheus exporter that reads the current Linux connection tracking table
1.3K
Prometheus exporter that reads the current Linux connection tracking table from /proc/net/nf_conntrack
and exports traffic metrics (packets/bytes) plus aggregated totals.
The exporter periodically takes a snapshot of nf_conntrack and caches the resulting metrics until
the next read.
Source code avaliable on github
/proc/net/nf_conntrack.--collector.interval (seconds).src ip, dst ip, l3protocol, l4protocol, dport, l7protocolsrc/dst/dport but different source ports are summed.You can add grafana dashboard to visualize the exporter data. The dashboard code is in the file.

For the kernel to include packets/bytes counters in /proc/net/nf_conntrack, you must enable:
net.netfilter.nf_conntrack_acct=1If the value is 0, the exporter will still run, but conntrack entries may miss packets/bytes fields
or provide zero values (making traffic metrics incorrect).
Check the current value:
sysctl net.netfilter.nf_conntrack_acct
Enable until reboot:
sudo sysctl -w net.netfilter.nf_conntrack_acct=1
Make it persistent (example):
echo 'net.netfilter.nf_conntrack_acct=1' | sudo tee /etc/sysctl.d/99-conntrack-exporter.conf
sudo sysctl --system
The exporter also supports best-effort auto-configuration on startup:
--configure.nf_conntrack_acctNote: this typically requires root privileges (or equivalent capabilities), otherwise a warning will be logged.
In containers there are two important points:
nf_conntrack from procfs. To read the host conntrack table, you must mount the host /proc
into the container and point --path.procfs to that mount point.Run example (replace the image name with yours):
docker run --rm \
--name conntrack-exporter \
--net=host \
--pid=host \
-v /proc:/host/proc:ro \
conntrack-exporter:latest \
--path.procfs=/host/proc \
--web.listen-address=:9095 \
--web.telemetry-path=/metrics
Content type
Image
Digest
sha256:d47619ed8…
Size
3.3 MB
Last updated
8 months ago
docker pull rickraven/conntrack-exporter