proc_net_stat_conntrack.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include "plugin_proc.h"
  3. #define RRD_TYPE_NET_STAT_NETFILTER "netfilter"
  4. #define RRD_TYPE_NET_STAT_CONNTRACK "conntrack"
  5. #define PLUGIN_PROC_MODULE_CONNTRACK_NAME "/proc/net/stat/nf_conntrack"
  6. int do_proc_net_stat_conntrack(int update_every, usec_t dt) {
  7. static procfile *ff = NULL;
  8. static int do_sockets = -1, do_new = -1, do_changes = -1, do_expect = -1, do_search = -1, do_errors = -1;
  9. static usec_t get_max_every = 10 * USEC_PER_SEC, usec_since_last_max = 0;
  10. static int read_full = 1;
  11. static char *nf_conntrack_filename, *nf_conntrack_count_filename, *nf_conntrack_max_filename;
  12. static RRDVAR *rrdvar_max = NULL;
  13. unsigned long long aentries = 0, asearched = 0, afound = 0, anew = 0, ainvalid = 0, aignore = 0, adelete = 0, adelete_list = 0,
  14. ainsert = 0, ainsert_failed = 0, adrop = 0, aearly_drop = 0, aicmp_error = 0, aexpect_new = 0, aexpect_create = 0, aexpect_delete = 0, asearch_restart = 0;
  15. if(unlikely(do_sockets == -1)) {
  16. char filename[FILENAME_MAX + 1];
  17. snprintfz(filename, FILENAME_MAX, "%s%s", netdata_configured_host_prefix, "/proc/net/stat/nf_conntrack");
  18. nf_conntrack_filename = config_get("plugin:proc:/proc/net/stat/nf_conntrack", "filename to monitor", filename);
  19. snprintfz(filename, FILENAME_MAX, "%s%s", netdata_configured_host_prefix, "/proc/sys/net/netfilter/nf_conntrack_max");
  20. nf_conntrack_max_filename = config_get("plugin:proc:/proc/sys/net/netfilter/nf_conntrack_max", "filename to monitor", filename);
  21. usec_since_last_max = get_max_every = config_get_number("plugin:proc:/proc/sys/net/netfilter/nf_conntrack_max", "read every seconds", 10) * USEC_PER_SEC;
  22. read_full = 1;
  23. ff = procfile_open(nf_conntrack_filename, " \t:", PROCFILE_FLAG_DEFAULT);
  24. if(!ff) read_full = 0;
  25. do_new = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter new connections", read_full);
  26. do_changes = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter connection changes", read_full);
  27. do_expect = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter connection expectations", read_full);
  28. do_search = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter connection searches", read_full);
  29. do_errors = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter errors", read_full);
  30. do_sockets = 1;
  31. if(!read_full) {
  32. snprintfz(filename, FILENAME_MAX, "%s%s", netdata_configured_host_prefix, "/proc/sys/net/netfilter/nf_conntrack_count");
  33. nf_conntrack_count_filename = config_get("plugin:proc:/proc/sys/net/netfilter/nf_conntrack_count", "filename to monitor", filename);
  34. if(read_single_number_file(nf_conntrack_count_filename, &aentries))
  35. do_sockets = 0;
  36. }
  37. do_sockets = config_get_boolean("plugin:proc:/proc/net/stat/nf_conntrack", "netfilter connections", do_sockets);
  38. if(!do_sockets && !read_full)
  39. return 1;
  40. rrdvar_max = rrdvar_custom_host_variable_create(localhost, "netfilter_conntrack_max");
  41. }
  42. if(likely(read_full)) {
  43. if(unlikely(!ff)) {
  44. ff = procfile_open(nf_conntrack_filename, " \t:", PROCFILE_FLAG_DEFAULT);
  45. if(unlikely(!ff))
  46. return 0; // we return 0, so that we will retry to open it next time
  47. }
  48. ff = procfile_readall(ff);
  49. if(unlikely(!ff))
  50. return 0; // we return 0, so that we will retry to open it next time
  51. size_t lines = procfile_lines(ff), l;
  52. for(l = 1; l < lines ;l++) {
  53. size_t words = procfile_linewords(ff, l);
  54. if(unlikely(words < 17)) {
  55. if(unlikely(words)) error("Cannot read /proc/net/stat/nf_conntrack line. Expected 17 params, read %zu.", words);
  56. continue;
  57. }
  58. unsigned long long tentries = 0, tsearched = 0, tfound = 0, tnew = 0, tinvalid = 0, tignore = 0, tdelete = 0, tdelete_list = 0, tinsert = 0, tinsert_failed = 0, tdrop = 0, tearly_drop = 0, ticmp_error = 0, texpect_new = 0, texpect_create = 0, texpect_delete = 0, tsearch_restart = 0;
  59. tentries = strtoull(procfile_lineword(ff, l, 0), NULL, 16);
  60. tsearched = strtoull(procfile_lineword(ff, l, 1), NULL, 16);
  61. tfound = strtoull(procfile_lineword(ff, l, 2), NULL, 16);
  62. tnew = strtoull(procfile_lineword(ff, l, 3), NULL, 16);
  63. tinvalid = strtoull(procfile_lineword(ff, l, 4), NULL, 16);
  64. tignore = strtoull(procfile_lineword(ff, l, 5), NULL, 16);
  65. tdelete = strtoull(procfile_lineword(ff, l, 6), NULL, 16);
  66. tdelete_list = strtoull(procfile_lineword(ff, l, 7), NULL, 16);
  67. tinsert = strtoull(procfile_lineword(ff, l, 8), NULL, 16);
  68. tinsert_failed = strtoull(procfile_lineword(ff, l, 9), NULL, 16);
  69. tdrop = strtoull(procfile_lineword(ff, l, 10), NULL, 16);
  70. tearly_drop = strtoull(procfile_lineword(ff, l, 11), NULL, 16);
  71. ticmp_error = strtoull(procfile_lineword(ff, l, 12), NULL, 16);
  72. texpect_new = strtoull(procfile_lineword(ff, l, 13), NULL, 16);
  73. texpect_create = strtoull(procfile_lineword(ff, l, 14), NULL, 16);
  74. texpect_delete = strtoull(procfile_lineword(ff, l, 15), NULL, 16);
  75. tsearch_restart = strtoull(procfile_lineword(ff, l, 16), NULL, 16);
  76. if(unlikely(!aentries)) aentries = tentries;
  77. // sum all the cpus together
  78. asearched += tsearched; // conntrack.search
  79. afound += tfound; // conntrack.search
  80. anew += tnew; // conntrack.new
  81. ainvalid += tinvalid; // conntrack.new
  82. aignore += tignore; // conntrack.new
  83. adelete += tdelete; // conntrack.changes
  84. adelete_list += tdelete_list; // conntrack.changes
  85. ainsert += tinsert; // conntrack.changes
  86. ainsert_failed += tinsert_failed; // conntrack.errors
  87. adrop += tdrop; // conntrack.errors
  88. aearly_drop += tearly_drop; // conntrack.errors
  89. aicmp_error += ticmp_error; // conntrack.errors
  90. aexpect_new += texpect_new; // conntrack.expect
  91. aexpect_create += texpect_create; // conntrack.expect
  92. aexpect_delete += texpect_delete; // conntrack.expect
  93. asearch_restart += tsearch_restart; // conntrack.search
  94. }
  95. }
  96. else {
  97. if(unlikely(read_single_number_file(nf_conntrack_count_filename, &aentries)))
  98. return 0; // we return 0, so that we will retry to open it next time
  99. }
  100. usec_since_last_max += dt;
  101. if(unlikely(rrdvar_max && usec_since_last_max >= get_max_every)) {
  102. usec_since_last_max = 0;
  103. unsigned long long max;
  104. if(likely(!read_single_number_file(nf_conntrack_max_filename, &max)))
  105. rrdvar_custom_host_variable_set(localhost, rrdvar_max, max);
  106. }
  107. // --------------------------------------------------------------------
  108. if(do_sockets) {
  109. static RRDSET *st = NULL;
  110. static RRDDIM *rd_connections = NULL;
  111. if(unlikely(!st)) {
  112. st = rrdset_create_localhost(
  113. RRD_TYPE_NET_STAT_NETFILTER
  114. , RRD_TYPE_NET_STAT_CONNTRACK "_sockets"
  115. , NULL
  116. , RRD_TYPE_NET_STAT_CONNTRACK
  117. , NULL
  118. , "Connection Tracker Connections"
  119. , "active connections"
  120. , PLUGIN_PROC_NAME
  121. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  122. , NETDATA_CHART_PRIO_NETFILTER_SOCKETS
  123. , update_every
  124. , RRDSET_TYPE_LINE
  125. );
  126. rd_connections = rrddim_add(st, "connections", NULL, 1, 1, RRD_ALGORITHM_ABSOLUTE);
  127. }
  128. else rrdset_next(st);
  129. rrddim_set_by_pointer(st, rd_connections, aentries);
  130. rrdset_done(st);
  131. }
  132. // --------------------------------------------------------------------
  133. if(do_new) {
  134. static RRDSET *st = NULL;
  135. static RRDDIM
  136. *rd_new = NULL,
  137. *rd_ignore = NULL,
  138. *rd_invalid = NULL;
  139. if(unlikely(!st)) {
  140. st = rrdset_create_localhost(
  141. RRD_TYPE_NET_STAT_NETFILTER
  142. , RRD_TYPE_NET_STAT_CONNTRACK "_new"
  143. , NULL
  144. , RRD_TYPE_NET_STAT_CONNTRACK
  145. , NULL
  146. , "Connection Tracker New Connections"
  147. , "connections/s"
  148. , PLUGIN_PROC_NAME
  149. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  150. , NETDATA_CHART_PRIO_NETFILTER_NEW
  151. , update_every
  152. , RRDSET_TYPE_LINE
  153. );
  154. rd_new = rrddim_add(st, "new", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  155. rd_ignore = rrddim_add(st, "ignore", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  156. rd_invalid = rrddim_add(st, "invalid", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  157. }
  158. else rrdset_next(st);
  159. rrddim_set_by_pointer(st, rd_new, anew);
  160. rrddim_set_by_pointer(st, rd_ignore, aignore);
  161. rrddim_set_by_pointer(st, rd_invalid, ainvalid);
  162. rrdset_done(st);
  163. }
  164. // --------------------------------------------------------------------
  165. if(do_changes) {
  166. static RRDSET *st = NULL;
  167. static RRDDIM
  168. *rd_inserted = NULL,
  169. *rd_deleted = NULL,
  170. *rd_delete_list = NULL;
  171. if(unlikely(!st)) {
  172. st = rrdset_create_localhost(
  173. RRD_TYPE_NET_STAT_NETFILTER
  174. , RRD_TYPE_NET_STAT_CONNTRACK "_changes"
  175. , NULL
  176. , RRD_TYPE_NET_STAT_CONNTRACK
  177. , NULL
  178. , "Connection Tracker Changes"
  179. , "changes/s"
  180. , PLUGIN_PROC_NAME
  181. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  182. , NETDATA_CHART_PRIO_NETFILTER_CHANGES
  183. , update_every
  184. , RRDSET_TYPE_LINE
  185. );
  186. rrdset_flag_set(st, RRDSET_FLAG_DETAIL);
  187. rd_inserted = rrddim_add(st, "inserted", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  188. rd_deleted = rrddim_add(st, "deleted", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  189. rd_delete_list = rrddim_add(st, "delete_list", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  190. }
  191. else rrdset_next(st);
  192. rrddim_set_by_pointer(st, rd_inserted, ainsert);
  193. rrddim_set_by_pointer(st, rd_deleted, adelete);
  194. rrddim_set_by_pointer(st, rd_delete_list, adelete_list);
  195. rrdset_done(st);
  196. }
  197. // --------------------------------------------------------------------
  198. if(do_expect) {
  199. static RRDSET *st = NULL;
  200. static RRDDIM *rd_created = NULL,
  201. *rd_deleted = NULL,
  202. *rd_new = NULL;
  203. if(unlikely(!st)) {
  204. st = rrdset_create_localhost(
  205. RRD_TYPE_NET_STAT_NETFILTER
  206. , RRD_TYPE_NET_STAT_CONNTRACK "_expect"
  207. , NULL
  208. , RRD_TYPE_NET_STAT_CONNTRACK
  209. , NULL
  210. , "Connection Tracker Expectations"
  211. , "expectations/s"
  212. , PLUGIN_PROC_NAME
  213. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  214. , NETDATA_CHART_PRIO_NETFILTER_EXPECT
  215. , update_every
  216. , RRDSET_TYPE_LINE
  217. );
  218. rrdset_flag_set(st, RRDSET_FLAG_DETAIL);
  219. rd_created = rrddim_add(st, "created", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  220. rd_deleted = rrddim_add(st, "deleted", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  221. rd_new = rrddim_add(st, "new", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  222. }
  223. else rrdset_next(st);
  224. rrddim_set_by_pointer(st, rd_created, aexpect_create);
  225. rrddim_set_by_pointer(st, rd_deleted, aexpect_delete);
  226. rrddim_set_by_pointer(st, rd_new, aexpect_new);
  227. rrdset_done(st);
  228. }
  229. // --------------------------------------------------------------------
  230. if(do_search) {
  231. static RRDSET *st = NULL;
  232. static RRDDIM *rd_searched = NULL,
  233. *rd_restarted = NULL,
  234. *rd_found = NULL;
  235. if(unlikely(!st)) {
  236. st = rrdset_create_localhost(
  237. RRD_TYPE_NET_STAT_NETFILTER
  238. , RRD_TYPE_NET_STAT_CONNTRACK "_search"
  239. , NULL
  240. , RRD_TYPE_NET_STAT_CONNTRACK
  241. , NULL
  242. , "Connection Tracker Searches"
  243. , "searches/s"
  244. , PLUGIN_PROC_NAME
  245. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  246. , NETDATA_CHART_PRIO_NETFILTER_SEARCH
  247. , update_every
  248. , RRDSET_TYPE_LINE
  249. );
  250. rrdset_flag_set(st, RRDSET_FLAG_DETAIL);
  251. rd_searched = rrddim_add(st, "searched", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  252. rd_restarted = rrddim_add(st, "restarted", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  253. rd_found = rrddim_add(st, "found", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  254. }
  255. else rrdset_next(st);
  256. rrddim_set_by_pointer(st, rd_searched, asearched);
  257. rrddim_set_by_pointer(st, rd_restarted, asearch_restart);
  258. rrddim_set_by_pointer(st, rd_found, afound);
  259. rrdset_done(st);
  260. }
  261. // --------------------------------------------------------------------
  262. if(do_errors) {
  263. static RRDSET *st = NULL;
  264. static RRDDIM *rd_icmp_error = NULL,
  265. *rd_insert_failed = NULL,
  266. *rd_drop = NULL,
  267. *rd_early_drop = NULL;
  268. if(unlikely(!st)) {
  269. st = rrdset_create_localhost(
  270. RRD_TYPE_NET_STAT_NETFILTER
  271. , RRD_TYPE_NET_STAT_CONNTRACK "_errors"
  272. , NULL
  273. , RRD_TYPE_NET_STAT_CONNTRACK
  274. , NULL
  275. , "Connection Tracker Errors"
  276. , "events/s"
  277. , PLUGIN_PROC_NAME
  278. , PLUGIN_PROC_MODULE_CONNTRACK_NAME
  279. , NETDATA_CHART_PRIO_NETFILTER_ERRORS
  280. , update_every
  281. , RRDSET_TYPE_LINE
  282. );
  283. rrdset_flag_set(st, RRDSET_FLAG_DETAIL);
  284. rd_icmp_error = rrddim_add(st, "icmp_error", NULL, 1, 1, RRD_ALGORITHM_INCREMENTAL);
  285. rd_insert_failed = rrddim_add(st, "insert_failed", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  286. rd_drop = rrddim_add(st, "drop", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  287. rd_early_drop = rrddim_add(st, "early_drop", NULL, -1, 1, RRD_ALGORITHM_INCREMENTAL);
  288. }
  289. else rrdset_next(st);
  290. rrddim_set_by_pointer(st, rd_icmp_error, aicmp_error);
  291. rrddim_set_by_pointer(st, rd_insert_failed, ainsert_failed);
  292. rrddim_set_by_pointer(st, rd_drop, adrop);
  293. rrddim_set_by_pointer(st, rd_early_drop, aearly_drop);
  294. rrdset_done(st);
  295. }
  296. return 0;
  297. }