Home / Alt manpages / pppstats(8)

  • pppstats(8)
  • Admin command
  • linux

Read PPP Link Counters Safely with pppstats

You will use pppstats to take a one-shot or repeating view of a PPP interface, tell cumulative counters from per-interval deltas, and recognise the columns that relate to compression. Allow about ten minutes if the link name is known. The examples only read statistics; they do not bring a link up, change PPP configuration or restart a service.

1. Confirm the installed command

This guide follows the pppstats(8) manual installed with the Ubuntu ppp package on this machine. The package version is 2.4.9-1+1.1ubuntu4. The utility is old enough that its output format and kernel interface should be treated as version-specific rather than assumed to match a different PPP implementation.

$ command -v pppstats
/usr/sbin/pppstats
$ dpkg-query -W -f='${Package} ${Version}\n' ppp
ppp 2.4.9-1+1.1ubuntu4
$ man pppstats

Checkpoint: you have confirmed both the binary and the package version. If command -v prints nothing, stop here and install or repair the package using your normal system-management process. Do not copy a binary from another host just to make the example work.

2. Identify the PPP interface

pppstats defaults to ppp0 when no interface is supplied. That is convenient on a single-link system, but it is also the most common distraction: a machine can have no ppp0, or its active link can use another name. Check the interfaces before interpreting an error.

$ ip -brief link
$ ip -brief address
$ ls /sys/class/net

Choose an interface whose name is actually present, then store it in a shell variable so that later commands are easy to review:

$ PPP_IF='ppp0'
$ test -e "/sys/class/net/$PPP_IF" && echo "interface exists: $PPP_IF"
interface exists: ppp0

Replace ppp0 with the exact name from your host. If the test fails, do not guess. A missing interface usually means that the PPP session is down or has a different name; pppstats cannot create one.

3. Take one safe snapshot

Run a single report first. With no -w option, the manual says the default repeat count is one. Supplying -c 1 makes that intention visible in a script or incident note.

$ pppstats -c 1 "$PPP_IF"
  IN  PACK  VJCOMP  VJUNC  VJERR       OUT  PACK  VJCOMP  VJUNC  NON-VJ
    ...interface counters...

The precise spacing and numbers depend on traffic and the installed kernel PPP support. The input section describes received traffic; the output section describes transmitted traffic. IN and OUT are byte counts, and each PACK column is a packet count. A successful zero-traffic snapshot can therefore contain zeroes, while a nonexistent interface produces an error instead:

$ pppstats -c 1 ppp0
pppstats: nonexistent interface 'ppp0' specified

That message means the named interface was not available to the program at that moment. Re-run the interface checks and confirm the PPP session before trying elevated privileges. If a real interface exists but access is denied, inspect the local device and process permissions first; use sudo only when your host's access policy requires it. Nothing in this read-only command needs a configuration edit.

Use -w when you need a small time series. The value is the number of seconds between reports. When -w is present without -c, the manual specifies an infinite repeat count, so choose a finite count for a bounded diagnostic capture.

$ pppstats -w 5 -c 6 "$PPP_IF"

This requests six reports, five seconds apart. Without -a, the first report is a starting view and later reports show activity since the preceding report. In quiet periods, later values can be zero. That is not the same as a broken link.

For a cumulative view from link start instead, add -a:

$ pppstats -a -w 5 -c 6 "$PPP_IF"

Use the delta form to answer, "What moved during each interval?" Use the absolute form to answer, "How much has this link moved since it was initiated?" Do not compare a delta report with a cumulative report as if their columns measured the same thing.

The following switches select additional views. Add one at a time so that a crowded report does not become a new source of confusion:

  • -d reports data rate in kB/s instead of bytes.
  • -v adds Van Jacobson TCP header-compression statistics, including receive-side drops and transmit-side cache searches.
  • -r adds compression ratios and uncompressed byte totals. Ratios describe uncompressed size divided by compressed size.
  • -z replaces the standard report with packet-compression counters. If compression is not in use, the manual says these fields display zeroes.

For example, this gives a short rate sample with compression details:

$ pppstats -d -r -v -w 5 -c 3 "$PPP_IF"

With -r, some standard columns such as VJUNC, VJERR or NON-VJ are omitted according to the selected report. Read the heading actually printed above the numbers rather than relying on a fixed column position. With -z, look for compressed and incompressible byte and packet counts on both input and output sides, plus a recent compression ratio.

6. Diagnose a result before escalating

If one snapshot fails, record the exact interface name and repeat the harmless checks:

$ printf 'requested interface: %s\n' "$PPP_IF"
$ test -e "/sys/class/net/$PPP_IF" && echo present || echo absent
$ pppstats -c 1 "$PPP_IF"
$ printf 'exit status: %s\n' "$?"

A non-zero status or a "nonexistent interface" message points to interface state or naming, not to a need for -a, -d or -z. If the interface disappears between the check and the report, the PPP session may have renegotiated or disconnected. Check the service's existing logs and status commands, but do not restart it as a blind test: that would interrupt the link and is outside this guide's read-only workflow.

For a repeating command, use a finite -c count when collecting evidence. If you deliberately omit it, press Ctrl-C to stop the display. Stopping pppstats ends the reporting process; it does not stop PPP itself.

Done means

  • You confirmed the installed pppstats binary and local ppp version.
  • You selected an interface that exists instead of relying on the ppp0 default.
  • You captured one bounded report with -c 1.
  • You can distinguish interval deltas from link-lifetime totals using -a.
  • You know that -z is a different compression report, not an extra column set.
  • You have not restarted PPP or changed persistent configuration while diagnosing the counters.