Export nftables statistics to prometheus, original source from https://github.com/Sheridan/nftables_exporter
- Create a feature request, describe the metric that you would like to have and attach exported from nftables json file
--config=/path/to/file.yaml: Path to configuration file, default/etc/nftables_exporter.yaml--version: Show version and exit
Example content:
nftables_exporter:
bind_to: "[::1]:9630"
url_path: "/metrics"
nft_location: /sbin/nft
fake_nft_json: /path/to/nft.json
log_level: warnfake_nft_json used for debugging. I create this file with the command nft -j list ruleset > /path/to/nft.json. For normal exporter usage, this option is not needed.
log_level can be one of the following: debug, info, warn, error.
Default: warn.
nftables_set_elements reports the current number of entries in each named set (including empty IPv4 and IPv6 sets), labeled by name, family, and table. It reads nftables' count field, not size (which is the maximum capacity), so nft -j -t list ruleset can keep omitting set contents.
For example, these set entries in the JSON ruleset (other entries omitted):
{"nftables": [
{"set": {"family": "inet", "table": "filter", "name": "blocked_v4", "type": "ipv4_addr", "size": 100, "count": 0}},
{"set": {"family": "inet", "table": "filter", "name": "blocked_v6", "type": "ipv6_addr", "count": 2}}
]}produce the following metrics:
# HELP nftables_set_elements Count elements in set
# TYPE nftables_set_elements gauge
nftables_set_elements{family="inet",name="blocked_v4",table="filter"} 0
nftables_set_elements{family="inet",name="blocked_v6",table="filter"} 2
# HELP nftables_chain_rules Count rules in chain
# TYPE nftables_chain_rules gauge
nftables_chain_rules{family="inet",name="forward",table="filter"} 2.0
nftables_chain_rules{family="inet",name="global",table="filter"} 15.0
# HELP nftables_table_chains Count chains in table
# TYPE nftables_table_chains gauge
nftables_table_chains{family="inet",name="filter"} 7.0
nftables_table_chains{family="ip",name="nat"} 4.0
# HELP nftables_rule_bytes Bytes, matched by rule per rule comment
# TYPE nftables_rule_bytes gauge
nftables_rule_bytes{action="accept",chain="host_spc",comment="[spc->internet] Default http [tcp]",destination_addresses="any",destination_ports="http",family="inet",input_interfaces="internal_0",output_interfaces="external_kis_0",source_addresses="10.0.0.10",source_ports="any",table="filter"} 2280.0
# HELP nftables_rule_packets Packets, matched by rule per rule comment
# TYPE nftables_rule_packets gauge
nftables_rule_packets{action="accept",chain="host_spc",comment="[spc->internet] Default http [tcp]",destination_addresses="any",destination_ports="http",family="inet",input_interfaces="internal_0",output_interfaces="external_kis_0",source_addresses="10.0.0.10",source_ports="any",table="filter"} 38.0