Introduction
Install Node Exporter on Linux to collect system-level metrics for effective server monitoring with Prometheus. Prometheus is a monitoring platform that collects metrics from configured targets. For Linux servers, Node Exporter is a monitoring agent installed on each server to collect system-level metrics such as CPU usage, memory utilization, disk space, filesystem statistics, network traffic, and system load. It exposes system metrics over TCP port 9100, which the Prometheus server can access and scrape.
This guide explains how to install and configure Node Exporter on a Linux server and verify its connectivity from the Prometheus server.
If you need assistance with Linux server monitoring, Node Exporter installation, or ongoing server management, a managed server provider can handle the setup and monitoring for you.
Node Exporter Installation at a Glance
Node Exporter is installed on a Linux server to collect system metrics such as CPU, memory, disk, and network usage for Prometheus. The basic setup involves installing Node Exporter, configuring it as a systemd service, allowing secure access to TCP port 9100, and verifying connectivity with the Prometheus server.
Prerequisites
To proceed with the setup, we need:
- root or sudo access to the Linux server.
- Ensure that the server has network connectivity to the Prometheus server.
- TCP port 9100 is allowed between the Linux server and Prometheus server.
For security, port 9100 should preferably be accessible only from the Prometheus server or trusted monitoring network rather than being exposed publicly.
Step 1: Download Node Exporter
Download the Node Exporter package to a temporary directory:
| #cd /tmp #wget https://github.com/prometheus/node_exporter/releases/latest/download/node_exporter-linux-amd64.tar.gz |
Extract the downloaded archive:
| tar -xvf node_exporter-linux-amd64.tar.gz |
Copy the binary file to /usr/local/bin/:
| cp node_exporter-*/node_exporter /usr/local/bin/ |
Verify the installation using:
| node_exporter –version |
The command should return the installed Node Exporter version.
Step 2: Create a Dedicated Node Exporter User
For security, run Node Exporter under a dedicated system user instead of the root user.
Create the user:
| useradd -rs /bin/false node_exporter |
Set the ownership for the binary:
| chown node_exporter:node_exporter /usr/local/bin/node_exporter |
Step 3: Create a Systemd Service
Create a systemd service for Node Exporter to start automatically when the server boots and to provide standard service management through systemctl.
Create the service file:
| vim /etc/systemd/system/node_exporter.service |
Add the following:
| [Unit] Description=Prometheus Node Exporter Wants=network-online.target After=network-online.target [Service] User=node_exporter Group=node_exporter Type=simple ExecStart=/usr/local/bin/node_exporter [Install] WantedBy=multi-user.target |
Save the file using wq! and reload the systemd configuration:
| systemctl daemon-reload |
Enable the service to start automatically after reboot:
| systemctl enable node_exporter |
Start the service:
| systemctl start node_exporter |
Check the service status:
| systemctl status node_exporter |
The service should show:
Active: active (running)
Step 4: Verify Node Exporter Is Listening
Node Exporter listens on TCP port 9100 by default.
Check whether the port is listening:
| ss -lntp | grep 9100 |
A typical output will look similar to:
LISTEN 0 4096 *:9100 *:* users:((“node_exporter”,pid=1234,fd=3))
Step 5: Test Node Exporter Locally
Before testing connectivity from the Prometheus server, verify that Node Exporter is working locally.
Run:
| curl -v http://127.0.0.1:9100/metrics |
If Node Exporter is working correctly, the command will return a large set of metrics.
For example:
node_cpu_seconds_total
node_memory_MemTotal_bytes
node_memory_MemAvailable_bytes
node_filesystem_size_bytes
node_network_receive_bytes_total
This response means that Node Exporter is installed and functioning correctly on the server.
Step 6: Configure the Server Firewall
The Prometheus server needs to access the TCP port on the monitored server.
For security reasons, port 9100 should not normally be exposed to the public internet. Access should preferably be restricted to the private IP address of the Prometheus server or the trusted monitoring network.
UFW
If the server uses UFW and the Prometheus server has the private IP 10.0.1.23:
| ufw allow from 10.0.1.23 to any port 9100 proto tcp |
You can verify the rule using:
| ufw status |
Firewalld
For servers using firewalld:
| firewall-cmd –permanent \ –add-rich-rule=’rule family=”ipv4″ source address=”10.0.1.23/32″ port protocol=”tcp” port=”9100″ accept’ |
Reload the firewall:
| firewall-cmd –reload |
Verify the configuration:
| firewall-cmd –list-all |
CSF
If the server uses CSF, TCP port 9100 needs to be permitted appropriately.
However, instead of allowing the port globally, access should preferably be restricted to the Prometheus server’s private IP.
You can do this by adding the following lines at the bottom of the /etc/csf/csf.allow file:
| tcp|in|d=9100|s=10.0.1.23 |
Note: CSF configuration can vary depending on how the server’s firewall policies are structured.
Step 7: Configure the AWS Security Group
If the Linux server is hosted on AWS EC2, the Security Group attached to the instance must also permit TCP port 9100.
Add an inbound rule similar to:
Type: Custom TCP
Port: 9100
Protocol: TCP
Source: 10.0.1.23/32
If the Prometheus and monitored servers are located in different VPCs, through VPC peering, the appropriate VPC routes must also be configured between the two networks.
Step 8: Test Connectivity from the Prometheus Server
Once Node Exporter is running and the required firewall/network settings are configured, test connectivity from the Prometheus server.
For example, if the monitored server has the private IP 10.26.3.21
Run the following command from the Prometheus server:
| curl -v –connect-timeout 5 http://10.26.3.21:9100/metrics |
If the connection is successful, Prometheus should be able to retrieve the Node Exporter metrics.
A successful connection should return a message similar to:
Connection to 10.26.3.21 9100 port [tcp/*] succeeded!
Troubleshooting Connection Failures
If the connection times out, You can check whether connection attempts are reaching the monitored server using:
| tcpdump -ni any tcp port 9100 |
If no packets are observed, the issue is likely somewhere in the network path, such as routing, Security Groups, or NACLs. If packets reach the server but the connection is not established, investigate the local firewall or service configuration.
After checking everything, run the curl test again from the Prometheus server.
Conclusion
Node Exporter provides the system-level metrics required for monitoring Linux servers through Prometheus. The installation involves deploying the Node Exporter binary, creating a dedicated system user, configuring a systemd service verifying that the exporter is listening on TCP port 9100, and configure the local server to allow the the Prometheus server to access the Node Exporter endpoint securely.
With the right configuration, Node Exporter can be an important component of a reliable Linux server monitoring setup.
Need Help With Linux Server Monitoring?
Setting up and maintaining server monitoring across multiple Linux servers can require ongoing configuration, security, and maintenance. Skynats can help with Linux Server Support, monitoring, and infrastructure support.
Learn More About Linux Server Services
