Spry Methuselah

Charly's Column – darkstat

Article from Issue 234/2020
Author(s):

Thanks to its minimal footprint, 20-year-old darkstat hardly generates any noticeable load even on low-powered systems, making it the perfect monitoring tool for Charly's home utility room.

Next to our kitchen, there is a small utility room. I don't think its floorspace is even two square meters. In addition to the usual building services, such as fuse box, there are two firewalls, a web and mail server, network attached storage (NAS), and a large switch.

The tiny router supplied by my Internet provider sits a little intimidated in the corner. I downgraded it to something like the IT equivalent of a flow heater. It opens the connection to the provider and passes it to the firewall. I have switched off everything else, like WLAN, telephony, and the DHCP server; I prefer to do that myself, on my own hardware.

You need to monitor what you run. For long-term monitoring of loads and latencies, I use Munin and SmokePing. But if I just want to have a quick look at what currently is happening on the firewall interface, darkstat [1] is the hero of the day.

Darkstat, a true Methuselah at the ripe old age of almost 20, has been under the GPL license since 2002. I had my first contact with the software when I tried pfSense [2]. Thanks to its minimal footprint, the monitoring tool generates so little system load that it even runs unobtrusively on my ancient NAS box with 128MB RAM [3].

Darkstat gets its data via libpcap; the output comes courtesy of a built-in, lean web server. The most important parameters are stored in a small configuration file, which resides in /etc/darkstat/ on my Ubuntu test system. Using the configuration file is voluntary; I could ignore it and simply start darkstat at the command line.

The only mandatory parameter is -i <interface>. The darkstat --help command lists all the other parameters. Be careful with --syslog. If you enable this option, darkstat suppresses all console messages. It therefore makes sense not to set this parameter until everything else is working to your satisfaction.

Once darkstat is running as desired, a web server on port 667 displays the current traffic data (Figure 1). It is a pity that darkstat displays the data in bytes, not in bits, but it's fine for a quick overview of what's crossing the wire.

Figure 1: Darkstat returns clear evaluations via a web server on port 667.

More details can be found in the hosts tab. This is where darkstat lists the devices in a table; you can sort by the column headers. This is how I found out, for example, that music streaming is very popular today. My eldest child is embarking on a career as an Instagram influencer, or whatever the kids call it nowadays (Figure 2).

Figure 2: Darkstat uses the hosts tab to list the devices.

Also practical: darkstat not only displays live data, but also visualizes sessions that you record with Wireshark or Tcpdump. Conclusions: Methuselah has aged with dignity and is still very much needed.

Infos

  1. darkstat: https://unix4lyfe.org/darkstat/
  2. pfSense: https://www.pfsense.org
  3. darkstat package for Synology NAS: https://synocommunity.com/package/darkstat

The Author

Charly Kühnast manages Unix systems in a data center in the Lower Rhine region of Germany. His responsibilities include ensuring the security and availability of firewalls and the DMZ.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Charly's Column – pwquality

    Regular password changes are a thing of the past: Strong passwords for each individual service provide more protection. Charly pimped his Ubuntu accordingly with a suitable PAM module.

  • Master of the Keys

    Charly makes life easier for himself by using the lean Age tool for command-line data encryption tasks.

  • Charly's Column

    Who has the longest uptime? Linux systems used to win hands down when it comes to maximum uptime without rebooting. Today, uptime statistics help admins with monitoring tasks and discovering tricky bugs.

  • Charly's Column: Netdiscover

    This month, sys admin Charly grabs the fairly ancient Netdiscover wardriving tool and takes care of his neighbors' WiFi networks.

  • Charly's Column: GestióIP

    A tidy house, a tidy mind they say, and I’ll leave it up to you to consider what being disorganized might mean. Anybody who has tried to manage hundreds of IP addresses using just a sheet of paper or a spreadsheet will probably appreciate some help.

comments powered by Disqus