原理:
netstat -an|awk '/^tcp/{++S[$NF]}END{for(a in S) print a,S[a]}'
TIME_WAIT 79
ESTABLISHED 6
LISTEN 3
可以使用man netstat查看TCP的各种状态信息描述
ESTABLISHED socket已经建立连接
CLOSED socket没有被使用,无连接
CLOSING 服务器端和客户端都同时关闭连接
CLOSE_WAIT 等待关闭连接
TIME_WAIT 表示收到了对方的FIN报文,并发送出了ACK报文,等待2MSL后就可回到CLOSED状态
LAST_ACK 远端关闭,当前socket被动关闭后发送FIN报文,等待对方ACK报文
LISTEN 监听状态
SYN_RECV 接收到SYN报文
SYN_SENT 已经发送SYN报文
FIN_WAIT1 The socket is closed, and the connection is shutting down
FIN_WAIT2 Connection is closed, and the socket is waiting for a shutdown from the remote end.
2.在需要被监控的zabbix-agent端添加脚本编写
创建文件夹
mkdir -p /usr/local/zabbix-agent/scripts/
mkdir -p /etc/zabbix/zabbix_agentd.d/
vim /usr/local/zabbix-agent/scripts/tcp_conn_status.sh
#!/bin/bash
#this script is used to get tcp and udp connetion status
#tcp status
metric=$1
tmp_file=/tmp/tcp_status.txt
/bin/netstat -an|awk '/^tcp/{++S[$NF]}END{for(a in S) print a,S[a]}' > $tmp_file
case $metric in
closed)
output=$(awk '/CLOSED/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
listen)
output=$(awk '/LISTEN/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
synrecv)
output=$(awk '/SYN_RECV/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
synsent)
output=$(awk '/SYN_SENT/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
established)
output=$(awk '/ESTABLISHED/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
timewait)
output=$(awk '/TIME_WAIT/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
closing)
output=$(awk '/CLOSING/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
closewait)
output=$(awk '/CLOSE_WAIT/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
lastack)
output=$(awk '/LAST_ACK/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
finwait1)
output=$(awk '/FIN_WAIT1/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
finwait2)
output=$(awk '/FIN_WAIT2/{print $2}' $tmp_file)
if [ "$output" == "" ];then
echo 0
else
echo $output
fi
;;
*)
echo -e "\e[033mUsage: sh $0 [closed|closing|closewait|synrecv|synsent|finwait1|finwait2|listen|established|lastack|timewait]\e[0m"
esac
赋予脚本执行权限
chmod o+x /usr/local/zabbix-agent/scripts/tcp_conn_status.sh
3.agent的配置文件 /etc/zabbix/zabbix_agentd.conf 中定义了其他key的包含目录 Include=/etc/zabbix/zabbix_agentd.d/, 接着在 /etc/zabbix/zabbix_agentd.d/ 目录新建一个文件 tcp-status-params.conf, 内容如下
vim /etc/zabbix/zabbix_agentd.d/tcp-status-params.conf
UserParameter=tcp.status[*],/usr/local/zabbix-agent/scripts/tcp_conn_status.sh $1
重启agent
service zabbix-agent restart
4.zabbix-master服务端测试
zabbix_get -s 192.168.3.86 -p 10050 -k "tcp.status[listen]"
13
5.zabbix web端配置:
登录Zabbix3.0 的web界面,一次选择 Configuration > Templates , 在主界面的右上角有个 Import 按钮,用来导入模板
zabbix-tcp-status.xml
2.0
2014-12-04T09:41:57Z
Templates
Template TCP Connection Status
Template TCP Connection Status
Templates
TCP Status
-
CLOSED
0
0
tcp.status[closed]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
CLOSE_WAIT
0
0
tcp.status[closewait]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
CLOSING
0
0
tcp.status[closing]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
ESTABLISHED
0
0
tcp.status[established]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
FIN_WAIT1
0
0
tcp.status[finwait1]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
FIN_WAIT2
0
0
tcp.status[finwait2]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
LAST_ACK
0
0
tcp.status[lastack]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
LISTEN
0
0
tcp.status[listen]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
SYN_RECV
0
0
tcp.status[synrecv]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
SYN_SENT
0
0
tcp.status[synsent]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
-
TIME_WAIT
0
0
tcp.status[timewait]
60
90
365
0
3
0
0
0
0
1
0
0
0
TCP Status
{Template TCP Connection Status:tcp.status[timewait].last()}>10000
There are too many TCP TIME_WAIT status
0
4
0
TCP Status
900
200
0.0000
100.0000
1
1
0
1
0
0.0000
0.0000
0
0
0
0
0
0
C80000
0
2
0
-
Template TCP Connection Status
tcp.status[closed]
1
0
00C800
0
2
0
-
Template TCP Connection Status
tcp.status[closewait]
2
0
0000C8
0
2
0
-
Template TCP Connection Status
tcp.status[closing]
3
0
C800C8
0
2
0
-
Template TCP Connection Status
tcp.status[established]
4
0
00C8C8
0
2
0
-
Template TCP Connection Status
tcp.status[finwait1]
5
0
C8C800
0
2
0
-
Template TCP Connection Status
tcp.status[finwait2]
6
0
C8C8C8
0
2
0
-
Template TCP Connection Status
tcp.status[lastack]
7
0
960000
0
2
0
-
Template TCP Connection Status
tcp.status[listen]
8
0
009600
0
2
0
-
Template TCP Connection Status
tcp.status[synrecv]
9
0
000096
0
2
0
-
Template TCP Connection Status
tcp.status[synsent]
10
0
960096
0
2
0
-
Template TCP Connection Status
tcp.status[timewait]
在对应主机上添加tcp的监控:
添加报警,当tcp连接数超过5W报警:
{Template TCP Connection Status:tcp.status[established].last()}>50000
最终效果图:
某些服务器的established连接很多(3W或更多),如果突然下降到一定的值(1000),这个可能也是问题(可能某个前端的服务出问题了,新的用户进不来),需要对这个值进行监控
{192.168.1.13:tcp_est_status.last()}<1000
后记:发现通过netstat监控服务器的tcp等连接数效率比较低,netstat统计占用大量cpu带来服务器额外的压力,通过ss命令会更加合适,详情请看:
zabbix3.0对tcp连接数和状态的监控优化
http://blog.csdn.net/reblue520/article/details/52908966