@cryptotaxi247 / netdata-1 / commits / cddae4aba

added libreswan charts.d plugin

Costa Tsaousis (ktsaou) committed Jan 3, 2018 at 00:26 UTC cddae4aba5179dbd7c2c635b49eda4e086c08c78
5 files changed +361 -125
charts.d/Makefile.am
+1
@@ -16,6 +16,7 @@ dist_charts_DATA = \
16 example.chart.sh \
17 exim.chart.sh \
18 hddtemp.chart.sh \
19 + libreswan.chart.sh \
20 load_average.chart.sh \
21 mem_apps.chart.sh \
22 mysql.chart.sh \
charts.d/README.md
+168 -125
@@ -1,5 +1,76 @@
1 The following charts.d plugins are supported:
2
3 +---
4 +
5 +# hddtemp
6 +
7 +The plugin will collect temperatures from disks
8 +
9 +It will create one chart with all active disks
10 +
11 +1. **temperature in Celsius**
12 +
13 +### configuration
14 +
15 +hddtemp needs to be running in daemonized mode
16 +
17 +```sh
18 +# host with daemonized hddtemp
19 +hddtemp_host="localhost"
20 +
21 +# port on which hddtemp is showing data
22 +hddtemp_port="7634"
23 +
24 +# array of included disks
25 +# the default is to include all
26 +hddtemp_disks=()
27 +```
28 +
29 +---
30 +
31 +# libreswan
32 +
33 +The plugin will collects bytes-in, bytes-out and uptime for all established libreswan IPSEC tunnels.
34 +
35 +The following charts are created, **per tunnel**:
36 +
37 +1. **Uptime**
38 +
39 + * the uptime of the tunnel
40 +
41 +2. **Traffic**
42 +
43 + * bytes in
44 + * bytes out
45 +
46 +### configuration
47 +
48 +Its config file is `/etc/netdata/charts.d/libreswan.conf`.
49 +
50 +The plugin executes 2 commands to collect all the information it needs:
51 +
52 +```sh
53 +ipsec whack --status
54 +ipsec whack --trafficstatus
55 +```
56 +
57 +The first command is used to extract the currently established tunnels, their IDs and their names.
58 +The second command is used to extract the current uptime and traffic.
59 +
60 +Most probably user `netdata` will not be able to query libreswan, so the `ipsec` commands will be denied.
61 +The plugin attempts to run `ipsec` as `sudo ipsec ...`, to get access to libreswan statistics.
62 +
63 +To allow user `netdata` execute `sudo ipsec ...`, create the file `/etc/sudoers.d/netdata` with this content:
64 +
65 +```
66 +netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --status
67 +netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --trafficstatus
68 +```
69 +
70 +Make sure the path `/sbin/ipsec` matches your setup (execute `which ipsec` to find the right path).
71 +
72 +---
73 +
74 # mysql
75
76 The plugin will monitor one or more mysql servers
@@ -76,67 +147,89 @@ The above sets the mysql command only for server2. server1 will use the system d
147
148 If no configuration is given, the plugin will attempt to connect to mysql server at localhost.
149
150 +
151 ---
152
81 -# squid
153 +# nut
154
83 -The plugin will monitor a squid server.
155 +The plugin will collect UPS data for all UPSes configured in the system.
156
85 -It will produce 4 charts:
157 +The following charts will be created:
158
87 -1. **Squid Client Bandwidth** in kbps
159 +1. **UPS Charge**
160
89 - * in
90 - * out
91 - * hits
161 + * percentage changed
162
93 -2. **Squid Client Requests** in requests/sec
163 +2. **UPS Battery Voltage**
164
95 - * requests
96 - * hits
97 - * errors
165 + * current voltage
166 + * high voltage
167 + * low voltage
168 + * nominal voltage
169
99 -3. **Squid Server Bandwidth** in kbps
170 +3. **UPS Input Voltage**
171
101 - * in
102 - * out
172 + * current voltage
173 + * fault voltage
174 + * nominal voltage
175
104 -4. **Squid Server Requests** in requests/sec
176 +4. **UPS Input Current**
177
106 - * requests
107 - * errors
178 + * nominal current
179
109 -### autoconfig
180 +5. **UPS Input Frequency**
181
111 -The plugin will by itself detect squid servers running on
112 -localhost, on ports 3128 or 8080.
182 + * current frequency
183 + * nominal frequency
184
114 -It will attempt to download URLs in the form:
185 +6. **UPS Output Voltage**
186
116 -- `cache_object://HOST:PORT/counters`
117 -- `/squid-internal-mgr/counters`
187 + * current voltage
188 +
189 +7. **UPS Load**
190 +
191 + * current load
192 +
193 +8. **UPS Temperature**
194 +
195 + * current temperature
196
119 -If any succeeds, it will use this.
197
198 ### configuration
199
123 -If you need to configure it by hand, create the file
124 -`/etc/netdata/squid.conf` with the following variables:
200 +This is the internal default for `/etc/netdata/nut.conf`
201
126 -- `squid_host=IP` the IP of the squid host
127 -- `squid_port=PORT` the port the squid is listening
128 -- `squid_url="URL"` the URL with the statistics to be fetched from squid
129 -- `squid_timeout=SECONDS` how much time we should wait for squid to respond
130 -- `squid_update_every=SECONDS` the frequency of the data collection
202 +```sh
203 +# a space separated list of UPS names
204 +# if empty, the list returned by 'upsc -l' will be used
205 +nut_ups=
206
132 -Example `/etc/netdata/squid.conf`:
207 +# how frequently to collect UPS data
208 +nut_update_every=2
209 +```
210 +
211 +---
212 +
213 +# postfix
214 +
215 +The plugin will collect the postfix queue size.
216 +
217 +It will create two charts:
218 +
219 +1. **queue size in emails**
220 +2. **queue size in KB**
221 +
222 +### configuration
223 +
224 +This is the internal default for `/etc/netdata/postfix.conf`
225
226 ```sh
135 -squid_host=127.0.0.1
136 -squid_port=3128
137 -squid_url="cache_object://127.0.0.1:3128/counters"
138 -squid_timeout=2
139 -squid_update_every=5
227 +# the postqueue command
228 +# if empty, it will use the one found in the system path
229 +postfix_postqueue=
230 +
231 +# how frequently to collect queue size
232 +postfix_update_every=15
233 ```
234
235 ---
@@ -189,113 +282,63 @@ sensors_excluded=()
282
283 ---
284
192 -# hddtemp
193 -
194 -The plugin will collect temperatures from disks
195 -
196 -It will create one chart with all active disks
197 -
198 -1. **temperature in Celsius**
199 -
200 -### configuration
201 -
202 -hddtemp needs to be running in daemonized mode
203 -
204 -```sh
205 -# host with daemonized hddtemp
206 -hddtemp_host="localhost"
207 -
208 -# port on which hddtemp is showing data
209 -hddtemp_port="7634"
210 -
211 -# array of included disks
212 -# the default is to include all
213 -hddtemp_disks=()
214 -```
215 -
216 ----
217 -
218 -# postfix
219 -
220 -The plugin will collect the postfix queue size.
221 -
222 -It will create two charts:
223 -
224 -1. **queue size in emails**
225 -2. **queue size in KB**
226 -
227 -### configuration
228 -
229 -This is the internal default for `/etc/netdata/postfix.conf`
230 -
231 -```sh
232 -# the postqueue command
233 -# if empty, it will use the one found in the system path
234 -postfix_postqueue=
235 -
236 -# how frequently to collect queue size
237 -postfix_update_every=15
238 -```
239 -
240 ----
241 -
242 -# nut
243 -
244 -The plugin will collect UPS data for all UPSes configured in the system.
245 -
246 -The following charts will be created:
285 +# squid
286
248 -1. **UPS Charge**
287 +The plugin will monitor a squid server.
288
250 - * percentage changed
289 +It will produce 4 charts:
290
252 -2. **UPS Battery Voltage**
291 +1. **Squid Client Bandwidth** in kbps
292
254 - * current voltage
255 - * high voltage
256 - * low voltage
257 - * nominal voltage
293 + * in
294 + * out
295 + * hits
296
259 -3. **UPS Input Voltage**
297 +2. **Squid Client Requests** in requests/sec
298
261 - * current voltage
262 - * fault voltage
263 - * nominal voltage
299 + * requests
300 + * hits
301 + * errors
302
265 -4. **UPS Input Current**
303 +3. **Squid Server Bandwidth** in kbps
304
267 - * nominal current
305 + * in
306 + * out
307
269 -5. **UPS Input Frequency**
308 +4. **Squid Server Requests** in requests/sec
309
271 - * current frequency
272 - * nominal frequency
310 + * requests
311 + * errors
312
274 -6. **UPS Output Voltage**
313 +### autoconfig
314
276 - * current voltage
315 +The plugin will by itself detect squid servers running on
316 +localhost, on ports 3128 or 8080.
317
278 -7. **UPS Load**
318 +It will attempt to download URLs in the form:
319
280 - * current load
320 +- `cache_object://HOST:PORT/counters`
321 +- `/squid-internal-mgr/counters`
322
282 -8. **UPS Temperature**
323 +If any succeeds, it will use this.
324
284 - * current temperature
325 +### configuration
326
327 +If you need to configure it by hand, create the file
328 +`/etc/netdata/squid.conf` with the following variables:
329
287 -### configuration
330 +- `squid_host=IP` the IP of the squid host
331 +- `squid_port=PORT` the port the squid is listening
332 +- `squid_url="URL"` the URL with the statistics to be fetched from squid
333 +- `squid_timeout=SECONDS` how much time we should wait for squid to respond
334 +- `squid_update_every=SECONDS` the frequency of the data collection
335
289 -This is the internal default for `/etc/netdata/nut.conf`
336 +Example `/etc/netdata/squid.conf`:
337
338 ```sh
292 -# a space separated list of UPS names
293 -# if empty, the list returned by 'upsc -l' will be used
294 -nut_ups=
295 -
296 -# how frequently to collect UPS data
297 -nut_update_every=2
339 +squid_host=127.0.0.1
340 +squid_port=3128
341 +squid_url="cache_object://127.0.0.1:3128/counters"
342 +squid_timeout=2
343 +squid_update_every=5
344 ```
299 -
300 ----
301 -
charts.d/libreswan.chart.sh new
+166
@@ -0,0 +1,166 @@
1 +# no need for shebang - this file is loaded from charts.d.plugin
2 +
3 +# netdata
4 +# real-time performance and health monitoring, done right!
5 +# (C) 2018 Costa Tsaousis <costa@tsaousis.gr>
6 +# GPL v3+
7 +#
8 +
9 +# _update_every is a special variable - it holds the number of seconds
10 +# between the calls of the _update() function
11 +libreswan_update_every=1
12 +
13 +# the priority is used to sort the charts on the dashboard
14 +# 1 = the first chart
15 +libreswan_priority=90000
16 +
17 +# set to 1, to run ipsec with sudo
18 +libreswan_sudo=1
19 +
20 +# global variables to store our collected data
21 +
22 +# [TUNNELID] = TUNNELNAME
23 +# here we track the *latest* established tunnels
24 +# as detected by: ipsec whack --status
25 +declare -A libreswan_connected_tunnels=()
26 +
27 +# [TUNNELID] = VALUE
28 +# here we track values of all established tunnels (not only the latest)
29 +# as detected by: ipsec whack --trafficstatus
30 +declare -A libreswan_traffic_in=()
31 +declare -A libreswan_traffic_out=()
32 +declare -A libreswan_established_add_time=()
33 +
34 +# [TUNNELNAME] = CHARTID
35 +# here we remember CHARTIDs of all tunnels
36 +# we need this to avoid converting tunnel names to chart IDs on every iteration
37 +declare -A libreswan_tunnel_charts=()
38 +
39 +# run the ipsec command
40 +libreswan_ipsec() {
41 + if [ ${libreswan_sudo} -ne 0 ]
42 + then
43 + sudo -n "${IPSEC_CMD}" "${@}"
44 + return $?
45 + else
46 + "${IPSEC_CMD}" "${@}"
47 + return $?
48 + fi
49 +}
50 +
51 +# fetch latest values - fill the arrays
52 +libreswan_get() {
53 + # do all the work to collect / calculate the values
54 + # for each dimension
55 +
56 + # empty the variables
57 + libreswan_traffic_in=()
58 + libreswan_traffic_out=()
59 + libreswan_established_add_time=()
60 + libreswan_connected_tunnels=()
61 +
62 + # convert the ipsec command output to a shell script
63 + # and source it to get the values
64 + source <(
65 + {
66 + libreswan_ipsec whack --status;
67 + libreswan_ipsec whack --trafficstatus;
68 + } | sed -n \
69 + -e "s|[0-9]\+ #\([0-9]\+\): \"\(.*\)\".*IPsec SA established.*newest IPSEC.*|libreswan_connected_tunnels[\"\1\"]=\"\2\"|p" \
70 + -e "s|[0-9]\+ #\([0-9]\+\): \"\(.*\)\",.* add_time=\([0-9]\+\),.* inBytes=\([0-9]\+\),.* outBytes=\([0-9]\+\).*|libreswan_traffic_in[\"\1\"]=\"\4\"; libreswan_traffic_out[\"\1\"]=\"\5\"; libreswan_established_add_time[\"\1\"]=\"\3\";|p"
71 + ) || return 1
72 +
73 + # check we got some data
74 + [ ${#libreswan_connected_tunnels[@]} -eq 0 ] && return 1
75 +
76 + return 0
77 +}
78 +
79 +# _check is called once, to find out if this chart should be enabled or not
80 +libreswan_check() {
81 + # this should return:
82 + # - 0 to enable the chart
83 + # - 1 to disable the chart
84 +
85 + require_cmd ipsec || return 1
86 +
87 + # check that we can collect data
88 + libreswan_get || return 1
89 +
90 + return 0
91 +}
92 +
93 +# create the charts for an ipsec tunnel
94 +libreswan_create_one() {
95 + local n="${1}" name
96 +
97 + name="${libreswan_connected_tunnels[${n}]}"
98 +
99 + [ ! -z "${libreswan_tunnel_charts[${name}]}" ] && return 0
100 +
101 + libreswan_tunnel_charts[${name}]="$(fixid "${name}")"
102 +
103 + cat <<EOF
104 +CHART libreswan.${libreswan_tunnel_charts[${name}]}_net '${name}_net' "LibreSWAN Tunnel ${name} Traffic" "kilobits/s" "${name}" libreswan.net area $((libreswan_priority)) $libreswan_update_every
105 +DIMENSION in '' incremental 8 1000
106 +DIMENSION out '' incremental -8 1000
107 +CHART libreswan.${libreswan_tunnel_charts[${name}]}_uptime '${name}_uptime' "LibreSWAN Tunnel ${name} Uptime" "seconds" "${name}" libreswan.uptime line $((libreswan_priority + 1)) $libreswan_update_every
108 +DIMENSION uptime '' absolute 1 1
109 +EOF
110 +
111 + return 0
112 +
113 +}
114 +
115 +# _create is called once, to create the charts
116 +libreswan_create() {
117 + local n
118 + for n in "${!libreswan_connected_tunnels[@]}"
119 + do
120 + libreswan_create_one "${n}"
121 + done
122 + return 0
123 +}
124 +
125 +libreswan_now=$(date +%s)
126 +
127 +# send the values to netdata for an ipsec tunnel
128 +libreswan_update_one() {
129 + local n="${1}" microseconds="${2}" name id uptime
130 +
131 + name="${libreswan_connected_tunnels[${n}]}"
132 + id="${libreswan_tunnel_charts[${name}]}"
133 +
134 + [ -z "${id}" ] && libreswan_create_one "${name}"
135 +
136 + uptime=$(( ${libreswan_now} - ${libreswan_established_add_time[${n}]} ))
137 + [ ${uptime} -lt 0 ] && uptime=0
138 +
139 + # write the result of the work.
140 + cat <<VALUESEOF
141 +BEGIN libreswan.${id}_net ${microseconds}
142 +SET in = ${libreswan_traffic_in[${n}]}
143 +SET out = ${libreswan_traffic_out[${n}]}
144 +END
145 +BEGIN libreswan.${id}_uptime ${microseconds}
146 +SET uptime = ${uptime}
147 +END
148 +VALUESEOF
149 +}
150 +
151 +# _update is called continiously, to collect the values
152 +libreswan_update() {
153 + # the first argument to this function is the microseconds since last update
154 + # pass this parameter to the BEGIN statement (see bellow).
155 +
156 + libreswan_get || return 1
157 + libreswan_now=$(date +%s)
158 +
159 + local n
160 + for n in "${!libreswan_connected_tunnels[@]}"
161 + do
162 + libreswan_update_one "${n}" "${@}"
163 + done
164 +
165 + return 0
166 +}
conf.d/Makefile.am
+1
@@ -122,6 +122,7 @@ dist_chartsconfig_DATA = \
122 charts.d/apcupsd.conf \
123 charts.d/cpufreq.conf \
124 charts.d/exim.conf \
125 + charts.d/libreswan.conf \
126 charts.d/load_average.conf \
127 charts.d/mysql.conf \
128 charts.d/nut.conf \
conf.d/charts.d/libreswan.conf new
+25
@@ -0,0 +1,25 @@
1 +# no need for shebang - this file is loaded from charts.d.plugin
2 +
3 +# netdata
4 +# real-time performance and health monitoring, done right!
5 +# (C) 2018 Costa Tsaousis <costa@tsaousis.gr>
6 +# GPL v3+
7 +#
8 +
9 +# the data collection frequency
10 +# if unset, will inherit the netdata update frequency
11 +#libreswan_update_every=1
12 +
13 +# the charts priority on the dashboard
14 +#libreswan_priority=90000
15 +
16 +# set to 1, to run ipsec with sudo (the default)
17 +# set to 0, to run ipsec without sudo
18 +#libreswan_sudo=1
19 +
20 +# TO ALLOW NETDATA RUN ipsec AS ROOT
21 +# CREATE THE FILE: /etc/sudoers.d/netdata
22 +# WITH THESE 2 LINES (uncommented of course):
23 +#
24 +# netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --status
25 +# netdata ALL = (root) NOPASSWD: /sbin/ipsec whack --trafficstatus