added libreswan charts.d plugin
Costa Tsaousis (ktsaou) committed
Jan 3, 2018 at 00:26 UTC
cddae4aba5179dbd7c2c635b49eda4e086c08c78
5 files changed
+361
-125
charts.d/Makefile.am
+1
@@ -16,6 +16,7 @@ dist_charts_DATA = \
16
example.chart.sh \
17
exim.chart.sh \
18
hddtemp.chart.sh \
19
+ libreswan.chart.sh \
20
load_average.chart.sh \
21
mem_apps.chart.sh \
22
mysql.chart.sh \
charts.d/README.md
+168
-125
@@ -1,5 +1,76 @@
1
The following charts.d plugins are supported:
2
3
+---
4
+
5
+# hddtemp
6
+
7
+The plugin will collect temperatures from disks
8
+
9
+It will create one chart with all active disks
10
+
11
+1. **temperature in Celsius**
12
+
13
+### configuration
14
+
15
+hddtemp needs to be running in daemonized mode
16
+
17
+```sh
18
+# host with daemonized hddtemp
19
+hddtemp_host="localhost"
20
+
21
+# port on which hddtemp is showing data
22
+hddtemp_port="7634"
23
+
24
+# array of included disks
25
+# the default is to include all
26
+hddtemp_disks=()
27
+```
28
+
29
+---
30
+
31
+# libreswan
32
+
33
+The plugin will collects bytes-in, bytes-out and uptime for all established libreswan IPSEC tunnels.
34
+
35
+The following charts are created, **per tunnel**:
36
+
37
+1. **Uptime**
38
+
39
+ * the uptime of the tunnel
40
+
41
+2. **Traffic**
42
+
43
+ * bytes in
44
+ * bytes out
45
+
46
+### configuration
47
+
48
+Its config file is `/etc/netdata/charts.d/libreswan.conf`.
49
+
50
+The plugin executes 2 commands to collect all the information it needs:
51
+
52
+```sh
53
+ipsec whack --status
54
+ipsec whack --trafficstatus
55
+```
56
+
57
+The first command is used to extract the currently established tunnels, their IDs and their names.
58
+The second command is used to extract the current uptime and traffic.
59
+
60
+Most probably user `netdata` will not be able to query libreswan, so the `ipsec` commands will be denied.
61
+The plugin attempts to run `ipsec` as `sudo ipsec ...`, to get access to libreswan statistics.
62
+
63
+To allow user `netdata` execute `sudo ipsec ...`, create the file `/etc/sudoers.d/netdata` with this content:
64
+
65
+```
66
+netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --status
67
+netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --trafficstatus
68
+```
69
+
70
+Make sure the path `/sbin/ipsec` matches your setup (execute `which ipsec` to find the right path).
71
+
72
+---
73
+
74
# mysql
75
76
The plugin will monitor one or more mysql servers
@@ -76,67 +147,89 @@ The above sets the mysql command only for server2. server1 will use the system d
147
148
If no configuration is given, the plugin will attempt to connect to mysql server at localhost.
149
150
+
151
---
152
81
-# squid
153
+# nut
154
83
-The plugin will monitor a squid server.
155
+The plugin will collect UPS data for all UPSes configured in the system.
156
85
-It will produce 4 charts:
157
+The following charts will be created:
158
87
-1. **Squid Client Bandwidth** in kbps
159
+1. **UPS Charge**
160
89
- * in
90
- * out
91
- * hits
161
+ * percentage changed
162
93
-2. **Squid Client Requests** in requests/sec
163
+2. **UPS Battery Voltage**
164
95
- * requests
96
- * hits
97
- * errors
165
+ * current voltage
166
+ * high voltage
167
+ * low voltage
168
+ * nominal voltage
169
99
-3. **Squid Server Bandwidth** in kbps
170
+3. **UPS Input Voltage**
171
101
- * in
102
- * out
172
+ * current voltage
173
+ * fault voltage
174
+ * nominal voltage
175
104
-4. **Squid Server Requests** in requests/sec
176
+4. **UPS Input Current**
177
106
- * requests
107
- * errors
178
+ * nominal current
179
109
-### autoconfig
180
+5. **UPS Input Frequency**
181
111
-The plugin will by itself detect squid servers running on
112
-localhost, on ports 3128 or 8080.
182
+ * current frequency
183
+ * nominal frequency
184
114
-It will attempt to download URLs in the form:
185
+6. **UPS Output Voltage**
186
116
-- `cache_object://HOST:PORT/counters`
117
-- `/squid-internal-mgr/counters`
187
+ * current voltage
188
+
189
+7. **UPS Load**
190
+
191
+ * current load
192
+
193
+8. **UPS Temperature**
194
+
195
+ * current temperature
196
119
-If any succeeds, it will use this.
197
198
### configuration
199
123
-If you need to configure it by hand, create the file
124
-`/etc/netdata/squid.conf` with the following variables:
200
+This is the internal default for `/etc/netdata/nut.conf`
201
126
-- `squid_host=IP` the IP of the squid host
127
-- `squid_port=PORT` the port the squid is listening
128
-- `squid_url="URL"` the URL with the statistics to be fetched from squid
129
-- `squid_timeout=SECONDS` how much time we should wait for squid to respond
130
-- `squid_update_every=SECONDS` the frequency of the data collection
202
+```sh
203
+# a space separated list of UPS names
204
+# if empty, the list returned by 'upsc -l' will be used
205
+nut_ups=
206
132
-Example `/etc/netdata/squid.conf`:
207
+# how frequently to collect UPS data
208
+nut_update_every=2
209
+```
210
+
211
+---
212
+
213
+# postfix
214
+
215
+The plugin will collect the postfix queue size.
216
+
217
+It will create two charts:
218
+
219
+1. **queue size in emails**
220
+2. **queue size in KB**
221
+
222
+### configuration
223
+
224
+This is the internal default for `/etc/netdata/postfix.conf`
225
226
```sh
135
-squid_host=127.0.0.1
136
-squid_port=3128
137
-squid_url="cache_object://127.0.0.1:3128/counters"
138
-squid_timeout=2
139
-squid_update_every=5
227
+# the postqueue command
228
+# if empty, it will use the one found in the system path
229
+postfix_postqueue=
230
+
231
+# how frequently to collect queue size
232
+postfix_update_every=15
233
```
234
235
---
@@ -189,113 +282,63 @@ sensors_excluded=()
282
283
---
284
192
-# hddtemp
193
-
194
-The plugin will collect temperatures from disks
195
-
196
-It will create one chart with all active disks
197
-
198
-1. **temperature in Celsius**
199
-
200
-### configuration
201
-
202
-hddtemp needs to be running in daemonized mode
203
-
204
-```sh
205
-# host with daemonized hddtemp
206
-hddtemp_host="localhost"
207
-
208
-# port on which hddtemp is showing data
209
-hddtemp_port="7634"
210
-
211
-# array of included disks
212
-# the default is to include all
213
-hddtemp_disks=()
214
-```
215
-
216
----
217
-
218
-# postfix
219
-
220
-The plugin will collect the postfix queue size.
221
-
222
-It will create two charts:
223
-
224
-1. **queue size in emails**
225
-2. **queue size in KB**
226
-
227
-### configuration
228
-
229
-This is the internal default for `/etc/netdata/postfix.conf`
230
-
231
-```sh
232
-# the postqueue command
233
-# if empty, it will use the one found in the system path
234
-postfix_postqueue=
235
-
236
-# how frequently to collect queue size
237
-postfix_update_every=15
238
-```
239
-
240
----
241
-
242
-# nut
243
-
244
-The plugin will collect UPS data for all UPSes configured in the system.
245
-
246
-The following charts will be created:
285
+# squid
286
248
-1. **UPS Charge**
287
+The plugin will monitor a squid server.
288
250
- * percentage changed
289
+It will produce 4 charts:
290
252
-2. **UPS Battery Voltage**
291
+1. **Squid Client Bandwidth** in kbps
292
254
- * current voltage
255
- * high voltage
256
- * low voltage
257
- * nominal voltage
293
+ * in
294
+ * out
295
+ * hits
296
259
-3. **UPS Input Voltage**
297
+2. **Squid Client Requests** in requests/sec
298
261
- * current voltage
262
- * fault voltage
263
- * nominal voltage
299
+ * requests
300
+ * hits
301
+ * errors
302
265
-4. **UPS Input Current**
303
+3. **Squid Server Bandwidth** in kbps
304
267
- * nominal current
305
+ * in
306
+ * out
307
269
-5. **UPS Input Frequency**
308
+4. **Squid Server Requests** in requests/sec
309
271
- * current frequency
272
- * nominal frequency
310
+ * requests
311
+ * errors
312
274
-6. **UPS Output Voltage**
313
+### autoconfig
314
276
- * current voltage
315
+The plugin will by itself detect squid servers running on
316
+localhost, on ports 3128 or 8080.
317
278
-7. **UPS Load**
318
+It will attempt to download URLs in the form:
319
280
- * current load
320
+- `cache_object://HOST:PORT/counters`
321
+- `/squid-internal-mgr/counters`
322
282
-8. **UPS Temperature**
323
+If any succeeds, it will use this.
324
284
- * current temperature
325
+### configuration
326
327
+If you need to configure it by hand, create the file
328
+`/etc/netdata/squid.conf` with the following variables:
329
287
-### configuration
330
+- `squid_host=IP` the IP of the squid host
331
+- `squid_port=PORT` the port the squid is listening
332
+- `squid_url="URL"` the URL with the statistics to be fetched from squid
333
+- `squid_timeout=SECONDS` how much time we should wait for squid to respond
334
+- `squid_update_every=SECONDS` the frequency of the data collection
335
289
-This is the internal default for `/etc/netdata/nut.conf`
336
+Example `/etc/netdata/squid.conf`:
337
338
```sh
292
-# a space separated list of UPS names
293
-# if empty, the list returned by 'upsc -l' will be used
294
-nut_ups=
295
-
296
-# how frequently to collect UPS data
297
-nut_update_every=2
339
+squid_host=127.0.0.1
340
+squid_port=3128
341
+squid_url="cache_object://127.0.0.1:3128/counters"
342
+squid_timeout=2
343
+squid_update_every=5
344
```
299
-
300
----
301
-
charts.d/libreswan.chart.sh
new
+166
@@ -0,0 +1,166 @@
1
+# no need for shebang - this file is loaded from charts.d.plugin
2
+
3
+# netdata
4
+# real-time performance and health monitoring, done right!
5
+# (C) 2018 Costa Tsaousis <costa@tsaousis.gr>
6
+# GPL v3+
7
+#
8
+
9
+# _update_every is a special variable - it holds the number of seconds
10
+# between the calls of the _update() function
11
+libreswan_update_every=1
12
+
13
+# the priority is used to sort the charts on the dashboard
14
+# 1 = the first chart
15
+libreswan_priority=90000
16
+
17
+# set to 1, to run ipsec with sudo
18
+libreswan_sudo=1
19
+
20
+# global variables to store our collected data
21
+
22
+# [TUNNELID] = TUNNELNAME
23
+# here we track the *latest* established tunnels
24
+# as detected by: ipsec whack --status
25
+declare -A libreswan_connected_tunnels=()
26
+
27
+# [TUNNELID] = VALUE
28
+# here we track values of all established tunnels (not only the latest)
29
+# as detected by: ipsec whack --trafficstatus
30
+declare -A libreswan_traffic_in=()
31
+declare -A libreswan_traffic_out=()
32
+declare -A libreswan_established_add_time=()
33
+
34
+# [TUNNELNAME] = CHARTID
35
+# here we remember CHARTIDs of all tunnels
36
+# we need this to avoid converting tunnel names to chart IDs on every iteration
37
+declare -A libreswan_tunnel_charts=()
38
+
39
+# run the ipsec command
40
+libreswan_ipsec() {
41
+ if [ ${libreswan_sudo} -ne 0 ]
42
+ then
43
+ sudo -n "${IPSEC_CMD}" "${@}"
44
+ return $?
45
+ else
46
+ "${IPSEC_CMD}" "${@}"
47
+ return $?
48
+ fi
49
+}
50
+
51
+# fetch latest values - fill the arrays
52
+libreswan_get() {
53
+ # do all the work to collect / calculate the values
54
+ # for each dimension
55
+
56
+ # empty the variables
57
+ libreswan_traffic_in=()
58
+ libreswan_traffic_out=()
59
+ libreswan_established_add_time=()
60
+ libreswan_connected_tunnels=()
61
+
62
+ # convert the ipsec command output to a shell script
63
+ # and source it to get the values
64
+ source <(
65
+ {
66
+ libreswan_ipsec whack --status;
67
+ libreswan_ipsec whack --trafficstatus;
68
+ } | sed -n \
69
+ -e "s|[0-9]\+ #\([0-9]\+\): \"\(.*\)\".*IPsec SA established.*newest IPSEC.*|libreswan_connected_tunnels[\"\1\"]=\"\2\"|p" \
70
+ -e "s|[0-9]\+ #\([0-9]\+\): \"\(.*\)\",.* add_time=\([0-9]\+\),.* inBytes=\([0-9]\+\),.* outBytes=\([0-9]\+\).*|libreswan_traffic_in[\"\1\"]=\"\4\"; libreswan_traffic_out[\"\1\"]=\"\5\"; libreswan_established_add_time[\"\1\"]=\"\3\";|p"
71
+ ) || return 1
72
+
73
+ # check we got some data
74
+ [ ${#libreswan_connected_tunnels[@]} -eq 0 ] && return 1
75
+
76
+ return 0
77
+}
78
+
79
+# _check is called once, to find out if this chart should be enabled or not
80
+libreswan_check() {
81
+ # this should return:
82
+ # - 0 to enable the chart
83
+ # - 1 to disable the chart
84
+
85
+ require_cmd ipsec || return 1
86
+
87
+ # check that we can collect data
88
+ libreswan_get || return 1
89
+
90
+ return 0
91
+}
92
+
93
+# create the charts for an ipsec tunnel
94
+libreswan_create_one() {
95
+ local n="${1}" name
96
+
97
+ name="${libreswan_connected_tunnels[${n}]}"
98
+
99
+ [ ! -z "${libreswan_tunnel_charts[${name}]}" ] && return 0
100
+
101
+ libreswan_tunnel_charts[${name}]="$(fixid "${name}")"
102
+
103
+ cat <<EOF
104
+CHART libreswan.${libreswan_tunnel_charts[${name}]}_net '${name}_net' "LibreSWAN Tunnel ${name} Traffic" "kilobits/s" "${name}" libreswan.net area $((libreswan_priority)) $libreswan_update_every
105
+DIMENSION in '' incremental 8 1000
106
+DIMENSION out '' incremental -8 1000
107
+CHART libreswan.${libreswan_tunnel_charts[${name}]}_uptime '${name}_uptime' "LibreSWAN Tunnel ${name} Uptime" "seconds" "${name}" libreswan.uptime line $((libreswan_priority + 1)) $libreswan_update_every
108
+DIMENSION uptime '' absolute 1 1
109
+EOF
110
+
111
+ return 0
112
+
113
+}
114
+
115
+# _create is called once, to create the charts
116
+libreswan_create() {
117
+ local n
118
+ for n in "${!libreswan_connected_tunnels[@]}"
119
+ do
120
+ libreswan_create_one "${n}"
121
+ done
122
+ return 0
123
+}
124
+
125
+libreswan_now=$(date +%s)
126
+
127
+# send the values to netdata for an ipsec tunnel
128
+libreswan_update_one() {
129
+ local n="${1}" microseconds="${2}" name id uptime
130
+
131
+ name="${libreswan_connected_tunnels[${n}]}"
132
+ id="${libreswan_tunnel_charts[${name}]}"
133
+
134
+ [ -z "${id}" ] && libreswan_create_one "${name}"
135
+
136
+ uptime=$(( ${libreswan_now} - ${libreswan_established_add_time[${n}]} ))
137
+ [ ${uptime} -lt 0 ] && uptime=0
138
+
139
+ # write the result of the work.
140
+ cat <<VALUESEOF
141
+BEGIN libreswan.${id}_net ${microseconds}
142
+SET in = ${libreswan_traffic_in[${n}]}
143
+SET out = ${libreswan_traffic_out[${n}]}
144
+END
145
+BEGIN libreswan.${id}_uptime ${microseconds}
146
+SET uptime = ${uptime}
147
+END
148
+VALUESEOF
149
+}
150
+
151
+# _update is called continiously, to collect the values
152
+libreswan_update() {
153
+ # the first argument to this function is the microseconds since last update
154
+ # pass this parameter to the BEGIN statement (see bellow).
155
+
156
+ libreswan_get || return 1
157
+ libreswan_now=$(date +%s)
158
+
159
+ local n
160
+ for n in "${!libreswan_connected_tunnels[@]}"
161
+ do
162
+ libreswan_update_one "${n}" "${@}"
163
+ done
164
+
165
+ return 0
166
+}
conf.d/Makefile.am
+1
@@ -122,6 +122,7 @@ dist_chartsconfig_DATA = \
122
charts.d/apcupsd.conf \
123
charts.d/cpufreq.conf \
124
charts.d/exim.conf \
125
+ charts.d/libreswan.conf \
126
charts.d/load_average.conf \
127
charts.d/mysql.conf \
128
charts.d/nut.conf \
conf.d/charts.d/libreswan.conf
new
+25
@@ -0,0 +1,25 @@
1
+# no need for shebang - this file is loaded from charts.d.plugin
2
+
3
+# netdata
4
+# real-time performance and health monitoring, done right!
5
+# (C) 2018 Costa Tsaousis <costa@tsaousis.gr>
6
+# GPL v3+
7
+#
8
+
9
+# the data collection frequency
10
+# if unset, will inherit the netdata update frequency
11
+#libreswan_update_every=1
12
+
13
+# the charts priority on the dashboard
14
+#libreswan_priority=90000
15
+
16
+# set to 1, to run ipsec with sudo (the default)
17
+# set to 0, to run ipsec without sudo
18
+#libreswan_sudo=1
19
+
20
+# TO ALLOW NETDATA RUN ipsec AS ROOT
21
+# CREATE THE FILE: /etc/sudoers.d/netdata
22
+# WITH THESE 2 LINES (uncommented of course):
23
+#
24
+# netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --status
25
+# netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --trafficstatus