Home / Alt manpages / rtacct(8)

  • rtacct(8)
  • Admin command
  • linux

Measure Linux Network Counter Changes with nstat and rtacct

You will finish with a safe way to inspect kernel network counters, compare activity between readings, select counters by name, and hand JSON to another tool. The examples use iproute2 6.1.0, installed here as package version 6.1.0-1ubuntu6.4. The same package provides both command names: nstat is the general counter viewer and rtacct presents per-realm accounting.

Allow about fifteen minutes. You need a shell and the iproute2 package. The normal readings are unprivileged and do not change interfaces, routes or services. A few options do change nstat's local history, so those are called out before use.

1. Confirm the installed commands

Start with read-only version and help checks. This establishes the syntax on the machine you are actually troubleshooting:

$ nstat --version
nstat utility, iproute2-6.1.0
$ rtacct --version
rtacct utility, iproute2-6.1.0
$ nstat --help

The two tools accept the same core switches. nstat also accepts counter patterns and JSON output. rtacct accepts an optional list of realms, but it does not accept nstat's pattern argument in that position.

Checkpoint: if either command is missing, stop and install or repair the distribution's iproute2 package through your normal change process. Do not copy a different binary into /usr/bin while investigating a live host.

2. Take a first nstat reading

Run the default command without elevated privileges:

$ nstat
#kernel
IpInReceives                 216893573          0.0
IpForwDatagrams                6319647          0.0
IpInDelivers                 209678920          0.0

Your counter names and values will differ. The first numeric column is the counter value reported for this reading. The last column is a rate calculated over the reporting interval. By default, zero-activity counters are hidden, and nstat calculates increments since its previous use rather than simply displaying every absolute value.

The first run can therefore look surprising. A newly started shell does not mean the kernel counters are new, and a later run may show only activity since the earlier run. Save the output when you need an audit trail, but do not treat a single snapshot as a traffic baseline.

3. Choose absolute values or changes deliberately

For a point-in-time inventory, ask for absolute values with --ignore, also written -a:

$ nstat --ignore 'Ip*'
#kernel
IpInReceives                 216893573          0.0
IpForwDatagrams                6319647          0.0
IpInDelivers                 209678920          0.0

The quoted Ip* pattern selects matching kernel counter names. Quoting matters: it leaves the wildcard for nstat instead of asking the shell to expand it against files in the current directory. Matching is case-insensitive and supports * and ?.

Use the default mode when you want activity since the previous reading. Use --noupdate or -s when you need to read without updating nstat's history:

$ nstat --noupdate 'Tcp*'
$ nstat 'Tcp*'

This is useful when a monitoring check should not consume the baseline expected by the next operator. It also explains why two people running nstat can affect what a later reading reports: they share the command's history rather than each having an independent in-memory session.

Checkpoint: choose one policy for your check. Use --ignore for absolute counters, or use the default with a controlled history owner for deltas. Do not compare an absolute reading with a delta as if they were the same measure.

4. Restrict output and use JSON

Patterns make a noisy host easier to inspect. This example selects IPv4 and IPv6 counters and emits machine-readable JSON:

$ nstat --ignore --json 'Ip*'
{"kernel":{"IpInReceives":216893573,"IpForwDatagrams":6319647,"IpInDelivers":209678920}}

The exact set and values depend on the kernel's exported counters. With --pretty or -p, the same JSON is formatted for a person, but it remains JSON:

$ nstat --ignore --json --pretty 'Ip*'
{
    "kernel": {
        "IpInReceives": 216893573
    }
}

Do not parse the aligned human output with fragile column positions when a script can consume JSON. If your check needs zero-valued counters as well, add --zeros or -z. Otherwise nstat hides counters with no activity.

5. Average activity over a chosen interval

The default averaging interval is 60 seconds. Set it explicitly with --interval or -t when the measurement needs a different window:

$ nstat --interval 10 'IpIn*' 'IpOut*'
#kernel
IpInReceives                 1234             123.4
IpOutRequests                 987              98.7

The two patterns are separate arguments. Use a quoted pattern for each group you want to include. This command does not generate traffic and does not modify networking; the result is simply a view of counters already maintained by the kernel.

For repeated collection, --scan or -d runs in daemon mode and collects statistics at the supplied number of seconds:

$ nstat --scan 10 --json 'Ip*'

It is a long-running foreground command. Press Ctrl-C to stop it. Before placing it under a service manager, decide who owns the history and where stdout and stderr go; two collectors sharing the same history can make each other's deltas misleading.

6. Inspect realm accounting with rtacct

Run rtacct without arguments to display the realm accounting table:

$ rtacct
#kernel
Realm      BytesTo    PktsTo     BytesFrom  PktsFrom
           BPSTo      PPSTo      BPSFrom    PPSFrom

An empty table is a valid result on a host with no accounting rows to show. If your deployment uses named realms, pass the exact realm names as positional arguments:

$ rtacct REALM_NAME

REALM_NAME is a placeholder, not a universal name to paste. Obtain the name from the accounting setup used on your host. Do not guess a realm or treat an empty result as proof that the network is idle.

Like nstat, rtacct supports --zeros, --reset, --nooutput, --ignore, --noupdate, --scan and --interval. Keep the default until you understand the local history. The --reset option is state-changing: it resets history and can remove the baseline another check expects. Use it only during an agreed maintenance action, and record the time so later deltas are not misread.

7. Recover from confusing readings

First repeat the query with --ignore and a narrow pattern. If the absolute value is sensible but the delta is zero, the counter did not change during the relevant history window, or another process consumed or replaced the baseline. If the output is missing, add --zeros and check the spelling of the pattern.

For a script, check the command's exit status and preserve its JSON output. A successful command with zero counters is still a successful measurement. An absent counter is not automatically an error: counter availability depends on the kernel and enabled protocols.

Do not use sudo by habit. These read operations normally work as an ordinary user. If a hardened host denies access, investigate the local permission and packaging policy before granting broad privileges. Neither command changes routes, interfaces or firewall rules, so there is no network rollback step for the read-only examples. If you used --reset, there is no documented undo switch; stop the dependent collector and establish a new baseline instead.

Done means

  • You confirmed the installed iproute2 version and command syntax.
  • You can distinguish absolute counters from history-based changes.
  • You quoted counter patterns and can select only the names you need.
  • You can produce JSON for automation and explain hidden zero counters.
  • You know that scan mode is long-running and history is shared.
  • You treated realm names and history reset as host-specific operational details.