{"id":17729,"date":"2026-09-28T16:05:02","date_gmt":"2026-09-28T10:35:02","guid":{"rendered":"https:\/\/www.skynats.com\/blog\/?p=17729"},"modified":"2026-09-28T16:05:02","modified_gmt":"2026-09-28T10:35:02","slug":"install-node-exporter-linux","status":"publish","type":"post","link":"https:\/\/www.skynats.com\/blog\/install-node-exporter-linux\/","title":{"rendered":"How to Install and Configure Node Exporter on a Linux Server"},"content":{"rendered":"<h2><b>Introduction<\/b><\/h2>\n<p><strong data-start=\"105\" data-end=\"139\">Install Node Exporter on Linux<\/strong> to collect system-level metrics for effective server monitoring with Prometheus. Prometheus is a monitoring platform that collects metrics from configured targets. For Linux servers, Node Exporter is a monitoring agent installed on each server to collect system-level metrics such as CPU usage, memory utilization, disk space, filesystem statistics, network traffic, and system load. It exposes system metrics over <strong data-start=\"555\" data-end=\"572\">TCP port 9100<\/strong>, which the Prometheus server can access and scrape.<\/p>\n<p><span style=\"font-weight: 400;\">This guide explains how to install and configure Node Exporter on a Linux server and verify its connectivity from the Prometheus server.<\/span><\/p>\n<p>If you need assistance with <a href=\"https:\/\/www.skynats.com\/linux-server-management\">Linux server monitoring<\/a>, Node Exporter installation, or ongoing server management, a managed server provider can handle the setup and monitoring for you.<\/p>\n<p><strong>Node Exporter Installation at a Glance<\/strong><\/p>\n<p><a href=\"https:\/\/www.skynats.com\/blog\/how-install-node-exporter-on-ubuntu\/\">Node Exporter<\/a> is installed on a <span style=\"color: #999999;\"><a style=\"color: #999999;\" href=\"https:\/\/www.linux.org\/\" target=\"_blank\" rel=\"noopener\">Linux<\/a><\/span> server to collect system metrics such as CPU, memory, disk, and network usage for Prometheus. The basic setup involves installing <a href=\"https:\/\/www.skynats.com\/blog\/how-to-install-node-exporter-on-a-client-for-prometheus-monitoring\/\">Node Exporter, configuring<\/a> it as a systemd service, allowing secure access to TCP port 9100, and verifying connectivity with the Prometheus server.<\/p>\n<h2><b>Prerequisites<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">To proceed with the setup, we need:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">root or sudo access to the Linux server.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ensure that the server has network connectivity to the Prometheus server.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\"> is allowed between the Linux server and Prometheus server.<\/span><\/li>\n<\/ul>\n<p>For security, port 9100 should preferably be accessible only from the Prometheus server or trusted monitoring network rather than being exposed publicly.<\/p>\n<h2><b>Step 1: Download Node Exporter<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Download the Node Exporter package to a temporary directory:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">#cd \/tmp<\/span><\/p>\n<p><span style=\"font-weight: 400;\">#wget https:\/\/github.com\/prometheus\/node_exporter\/releases\/latest\/download\/node_exporter-linux-amd64.tar.gz<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Extract the downloaded archive:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">tar -xvf node_exporter-linux-amd64.tar.gz<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Copy the binary file to <\/span><span style=\"font-weight: 400;\">\/usr\/local\/bin\/<\/span><span style=\"font-weight: 400;\">:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">cp node_exporter-*\/node_exporter \/usr\/local\/bin\/<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Verify the installation using:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">node_exporter &#8211;version<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">The command should return the installed Node Exporter version.<\/span><\/p>\n<h2><b>Step 2: Create a Dedicated Node Exporter User<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">For security, run Node Exporter under a dedicated system user instead of the root user.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Create the user:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">useradd -rs \/bin\/false node_exporter<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Set the ownership for the binary:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">chown node_exporter:node_exporter \/usr\/local\/bin\/node_exporter<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><b>Step 3: Create a Systemd Service<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Create a systemd service for Node Exporter to start automatically when the server boots and to provide standard service management through systemctl.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Create the service file:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">vim \/etc\/systemd\/system\/node_exporter.service<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Add the following:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">[Unit]<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Description=Prometheus Node Exporter<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Wants=network-online.target<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After=network-online.target<\/span><\/p>\n<p><span style=\"font-weight: 400;\">[Service]<\/span><\/p>\n<p><span style=\"font-weight: 400;\">User=node_exporter<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Group=node_exporter<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Type=simple<\/span><\/p>\n<p><span style=\"font-weight: 400;\">ExecStart=\/usr\/local\/bin\/node_exporter<\/span><\/p>\n<p><span style=\"font-weight: 400;\">[Install]<\/span><\/p>\n<p><span style=\"font-weight: 400;\">WantedBy=multi-user.target<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Save the file using <\/span><b>wq!<\/b><span style=\"font-weight: 400;\"> and reload the systemd configuration:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">systemctl daemon-reload<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Enable the service to start automatically after reboot:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">systemctl enable node_exporter<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Start the service:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">systemctl start node_exporter<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Check the service status:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">systemctl status node_exporter<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">The service should show:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Active: active (running)<\/span><\/p>\n<h2><b>Step 4: Verify Node Exporter Is Listening<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Node Exporter listens on TCP port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\"> by default.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check whether the port is listening:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">ss -lntp | grep 9100<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">A typical output will look similar to:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">LISTEN 0 4096 *:9100 *:* users:((&#8220;node_exporter&#8221;,pid=1234,fd=3))<\/span><\/p>\n<h2><b>Step 5: Test Node Exporter Locally<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Before testing connectivity from the Prometheus server, verify that Node Exporter is working locally.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Run:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">curl -v http:\/\/127.0.0.1:9100\/metrics<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">If Node Exporter is working correctly, the command will return a large set of metrics.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">node_cpu_seconds_total<\/span><\/p>\n<p><span style=\"font-weight: 400;\">node_memory_MemTotal_bytes<\/span><\/p>\n<p><span style=\"font-weight: 400;\">node_memory_MemAvailable_bytes<\/span><\/p>\n<p><span style=\"font-weight: 400;\">node_filesystem_size_bytes<\/span><\/p>\n<p><span style=\"font-weight: 400;\">node_network_receive_bytes_total<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This response means that Node Exporter is installed and functioning correctly on the server.<\/span><\/p>\n<h2><b>Step 6: Configure the Server Firewall<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The Prometheus server needs to access the TCP port on the monitored server.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For security reasons, port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\"> should <\/span><b>not normally be exposed to the public internet<\/b><span style=\"font-weight: 400;\">. Access should preferably be restricted to the private IP address of the Prometheus server or the trusted monitoring network.<\/span><\/p>\n<h3><b>UFW<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">If the server uses UFW and the Prometheus server has the private IP <\/span><span style=\"font-weight: 400;\">10.0.1.23<\/span><span style=\"font-weight: 400;\">:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">ufw allow from 10.0.1.23 to any port 9100 proto tcp<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">You can verify the rule using:\u00a0<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">ufw status<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3><b>Firewalld<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">For servers using firewalld:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">firewall-cmd &#8211;permanent \\<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0&#8211;add-rich-rule=&#8217;rule family=&#8221;ipv4&#8243; source address=&#8221;10.0.1.23\/32&#8243; port protocol=&#8221;tcp&#8221; port=&#8221;9100&#8243; accept&#8217;<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Reload the firewall:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">firewall-cmd &#8211;reload<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Verify the configuration:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">firewall-cmd &#8211;list-all<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3><b>CSF<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">If the server uses CSF, TCP port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\"> needs to be permitted appropriately.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, instead of allowing the port globally, access should preferably be restricted to the Prometheus server&#8217;s private IP.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can do this by adding the following lines at the bottom of the <\/span><b>\/etc\/csf\/csf.allow<\/b><span style=\"font-weight: 400;\"> file:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">tcp|in|d=9100|s=10.0.1.23<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Note: CSF configuration can vary depending on how the server&#8217;s firewall policies are structured.<\/span><\/p>\n<h2><b>Step 7: Configure the AWS Security Group<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If the Linux server is hosted on AWS EC2, the Security Group attached to the instance must also permit TCP port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Add an inbound rule similar to:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Type:\u00a0 \u00a0 \u00a0 \u00a0 Custom TCP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Port:\u00a0 \u00a0 \u00a0 \u00a0 9100<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Protocol:\u00a0 \u00a0 TCP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Source:\u00a0 \u00a0 \u00a0 10.0.1.23\/32<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If the Prometheus and monitored servers are located in different VPCs, through <\/span><b>VPC peering<\/b><span style=\"font-weight: 400;\">, the appropriate VPC routes must also be configured between the two networks.<\/span><\/p>\n<h2><b>Step 8: Test Connectivity from the Prometheus Server<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Once Node Exporter is running and the required firewall\/network settings are configured, test connectivity from the Prometheus server.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, if the monitored server has the private IP <\/span><span style=\"font-weight: 400;\">10.26.3.21<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Run the following command from the Prometheus server:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">curl -v &#8211;connect-timeout 5 http:\/\/10.26.3.21:9100\/metrics<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">If the connection is successful, Prometheus should be able to retrieve the Node Exporter metrics.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A successful connection should return a message similar to:\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Connection to 10.26.3.21 9100 port [tcp\/*] succeeded!<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Troubleshooting Connection Failures<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">If the connection times out, You can check whether connection attempts are reaching the monitored server using:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><span style=\"font-weight: 400;\">tcpdump -ni any tcp port 9100<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">If no packets are observed, the issue is likely somewhere in the network path, such as routing, Security Groups, or NACLs. If packets reach the server but the connection is not established, investigate the local firewall or service configuration.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After checking everything, run the <\/span><span style=\"font-weight: 400;\">curl<\/span><span style=\"font-weight: 400;\"> test again from the Prometheus server.<\/span><\/p>\n<h2><b>Conclusion<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Node Exporter provides the system-level metrics required for monitoring Linux servers through Prometheus. The installation involves deploying the Node Exporter binary, creating a dedicated system user, configuring a systemd service verifying that the exporter is listening on TCP port <\/span><span style=\"font-weight: 400;\">9100<\/span><span style=\"font-weight: 400;\">, and configure the local server to allow the\u00a0 the Prometheus server to access the Node Exporter endpoint securely.<\/span><\/p>\n<p>With the right configuration, Node Exporter can be an important component of a reliable Linux server monitoring setup.<\/p>\n<h2 class=\"PDq2pG_selectionAnchorContainer\" dir=\"auto\" data-section-id=\"li01n0\" data-start=\"7936\" data-end=\"7982\"><span role=\"text\"><strong data-start=\"7939\" data-end=\"7982\">Need Help With Linux Server Monitoring?<\/strong><\/span><\/h2>\n<p dir=\"auto\" data-start=\"7984\" data-end=\"8211\">Setting up and maintaining server monitoring across multiple Linux servers can require ongoing configuration, security, and maintenance. Skynats can help with <a href=\"https:\/\/www.skynats.com\/linux-server-management\">Linux Server Support<\/a>, monitoring, and <a href=\"https:\/\/www.skynats.com\/cpanel-server-management-services\">infrastructure support<\/a>.<\/p>\n<p dir=\"auto\" data-start=\"8213\" data-end=\"8269\">Learn More About <a href=\"https:\/\/www.skynats.com\/linux-server-management\">Linux Server Services<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Install Node Exporter on Linux to collect system-level metrics for effective server monitoring with Prometheus. Prometheus is a monitoring platform that collects metrics from configured targets. For Linux servers, Node Exporter is a monitoring agent installed on each server to collect system-level metrics such as CPU usage, memory utilization, disk space, filesystem statistics, network [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-17729","post","type-post","status-publish","format-standard","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts\/17729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/comments?post=17729"}],"version-history":[{"count":2,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts\/17729\/revisions"}],"predecessor-version":[{"id":17732,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts\/17729\/revisions\/17732"}],"wp:attachment":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/media?parent=17729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/categories?post=17729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/tags?post=17729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}