How to Install and Configure Node Exporter on a Linux Server

Table of Contents

Introduction

Install Node Exporter on Linux to collect system-level metrics for effective server monitoring with Prometheus. Prometheus is a monitoring platform that collects metrics from configured targets. For Linux servers, Node Exporter is a monitoring agent installed on each server to collect system-level metrics such as CPU usage, memory utilization, disk space, filesystem statistics, network traffic, and system load. It exposes system metrics over TCP port 9100, which the Prometheus server can access and scrape.

This guide explains how to install and configure Node Exporter on a Linux server and verify its connectivity from the Prometheus server.

If you need assistance with Linux server monitoring, Node Exporter installation, or ongoing server management, a managed server provider can handle the setup and monitoring for you.

Node Exporter Installation at a Glance

Node Exporter is installed on a Linux server to collect system metrics such as CPU, memory, disk, and network usage for Prometheus. The basic setup involves installing Node Exporter, configuring it as a systemd service, allowing secure access to TCP port 9100, and verifying connectivity with the Prometheus server.

Prerequisites

To proceed with the setup, we need:

  • root or sudo access to the Linux server.
  • Ensure that the server has network connectivity to the Prometheus server.
  • TCP port 9100 is allowed between the Linux server and Prometheus server.

For security, port 9100 should preferably be accessible only from the Prometheus server or trusted monitoring network rather than being exposed publicly.

Step 1: Download Node Exporter

Download the Node Exporter package to a temporary directory:

#cd /tmp

#wget https://github.com/prometheus/node_exporter/releases/latest/download/node_exporter-linux-amd64.tar.gz

Extract the downloaded archive:

tar -xvf node_exporter-linux-amd64.tar.gz

Copy the binary file to /usr/local/bin/:

cp node_exporter-*/node_exporter /usr/local/bin/

Verify the installation using:

node_exporter –version

The command should return the installed Node Exporter version.

Step 2: Create a Dedicated Node Exporter User

For security, run Node Exporter under a dedicated system user instead of the root user.

Create the user:

useradd -rs /bin/false node_exporter 

Set the ownership for the binary:

chown node_exporter:node_exporter /usr/local/bin/node_exporter

Step 3: Create a Systemd Service

Create a systemd service for Node Exporter to start automatically when the server boots and to provide standard service management through systemctl.

Create the service file:

vim /etc/systemd/system/node_exporter.service

Add the following:

[Unit]

Description=Prometheus Node Exporter

Wants=network-online.target

After=network-online.target

[Service]

User=node_exporter

Group=node_exporter

Type=simple

ExecStart=/usr/local/bin/node_exporter

[Install]

WantedBy=multi-user.target

 

Save the file using wq! and reload the systemd configuration:

systemctl daemon-reload

Enable the service to start automatically after reboot:

systemctl enable node_exporter

Start the service:

systemctl start node_exporter

Check the service status:

systemctl status node_exporter

The service should show:

Active: active (running)

Step 4: Verify Node Exporter Is Listening

Node Exporter listens on TCP port 9100 by default.

Check whether the port is listening:

ss -lntp | grep 9100

A typical output will look similar to:

LISTEN 0 4096 *:9100 *:* users:((“node_exporter”,pid=1234,fd=3))

Step 5: Test Node Exporter Locally

Before testing connectivity from the Prometheus server, verify that Node Exporter is working locally.

Run:

curl -v http://127.0.0.1:9100/metrics

If Node Exporter is working correctly, the command will return a large set of metrics.

For example:

node_cpu_seconds_total

node_memory_MemTotal_bytes

node_memory_MemAvailable_bytes

node_filesystem_size_bytes

node_network_receive_bytes_total

This response means that Node Exporter is installed and functioning correctly on the server.

Step 6: Configure the Server Firewall

The Prometheus server needs to access the TCP port on the monitored server.

For security reasons, port 9100 should not normally be exposed to the public internet. Access should preferably be restricted to the private IP address of the Prometheus server or the trusted monitoring network.

UFW

If the server uses UFW and the Prometheus server has the private IP 10.0.1.23:

ufw allow from 10.0.1.23 to any port 9100 proto tcp

 

You can verify the rule using: 

ufw status

 

Firewalld

For servers using firewalld:

firewall-cmd –permanent \

  –add-rich-rule=’rule family=”ipv4″ source address=”10.0.1.23/32″ port protocol=”tcp” port=”9100″ accept’

Reload the firewall:

firewall-cmd –reload

Verify the configuration:

firewall-cmd –list-all

 

CSF

If the server uses CSF, TCP port 9100 needs to be permitted appropriately.

However, instead of allowing the port globally, access should preferably be restricted to the Prometheus server’s private IP.

You can do this by adding the following lines at the bottom of the /etc/csf/csf.allow file:

tcp|in|d=9100|s=10.0.1.23

Note: CSF configuration can vary depending on how the server’s firewall policies are structured.

Step 7: Configure the AWS Security Group

If the Linux server is hosted on AWS EC2, the Security Group attached to the instance must also permit TCP port 9100.

Add an inbound rule similar to:

Type:        Custom TCP

Port:        9100

Protocol:    TCP

Source:      10.0.1.23/32

If the Prometheus and monitored servers are located in different VPCs, through VPC peering, the appropriate VPC routes must also be configured between the two networks.

Step 8: Test Connectivity from the Prometheus Server

Once Node Exporter is running and the required firewall/network settings are configured, test connectivity from the Prometheus server.

For example, if the monitored server has the private IP 10.26.3.21

Run the following command from the Prometheus server:

curl -v –connect-timeout 5 http://10.26.3.21:9100/metrics

If the connection is successful, Prometheus should be able to retrieve the Node Exporter metrics.

A successful connection should return a message similar to: 

Connection to 10.26.3.21 9100 port [tcp/*] succeeded!

 

Troubleshooting Connection Failures

If the connection times out, You can check whether connection attempts are reaching the monitored server using:

tcpdump -ni any tcp port 9100

If no packets are observed, the issue is likely somewhere in the network path, such as routing, Security Groups, or NACLs. If packets reach the server but the connection is not established, investigate the local firewall or service configuration. 

After checking everything, run the curl test again from the Prometheus server.

Conclusion

Node Exporter provides the system-level metrics required for monitoring Linux servers through Prometheus. The installation involves deploying the Node Exporter binary, creating a dedicated system user, configuring a systemd service verifying that the exporter is listening on TCP port 9100, and configure the local server to allow the  the Prometheus server to access the Node Exporter endpoint securely.

With the right configuration, Node Exporter can be an important component of a reliable Linux server monitoring setup.

Need Help With Linux Server Monitoring?

Setting up and maintaining server monitoring across multiple Linux servers can require ongoing configuration, security, and maintenance. Skynats can help with Linux Server Support, monitoring, and infrastructure support.

Learn More About Linux Server Services

Picture of Sourav AJ

Sourav AJ

Sourav A J is a Level 3 System Engineer at Skynats Technologies, specializing in Linux server administration, cloud infrastructure, and advanced server management solutions.

Liked!! Share the post.

Get Support right now!

Start server management with our 24x7 monitoring and active support team

Subscribe and get your first issue fixed for Free!

Looking for server support and 24x7 monitoring?

Have doubts? Connect with us now.