I&B Monitoring Platform documentation

Node exporter

Installation of Prometheus Node exporter in production environment consists from following high level steps:

  1. Install exporter;

  2. Configure authentication;

  3. Configure firewall;

  4. Configure service for autostart and restart;

  5. Check access to exporter from I&B monitoring platform.

1. Install Prometheus Node exporter.

  1. Check latest version, available platforms on node_exporter GitHub page and make necessary changes in variables on next step.

  2. Prepare environment variables to simplify installation and configuration process.

export EXPORTER_VERSION=1.9.1
export EXPORTER_PLATFORM=linux-amd64
  1. Download exporter

wget https://github.com/prometheus/node_exporter/releases/download/v$EXPORTER_VERSION/node_exporter-$EXPORTER_VERSION.$EXPORTER_PLATFORM.tar.gz
  1. Create directory /usr/local/bin/node_exporter and untar exporter into it.

sudo mkdir -p /usr/local/bin/node_exporter
sudo tar xvfz node_exporter-$EXPORTER_VERSION.$EXPORTER_PLATFORM.tar.gz -C /usr/local/bin/node_exporter --strip-components=1
  1. Create prometheus user. If it already exist - go to step 6.

Fedora (RHEL, CentOS)

sudo useradd -M -s /sbin/nologin prometheus
  • -M (or --no-create-home): This option prevents the creation of a home directory for the new user;

  • -s /sbin/nologin: This option sets the user's login shell to /sbin/nologin. This effectively prevents the user from interactively logging into the system. While the user won't have a password set, this further ensures they cannot log in.

Debian (Ubuntu)

sudo useradd -s /sbin/nologin prometheus --no-create-home
  1. Make prometheus user owner of node_exporter directory

sudo chown -hR prometheus:prometheus /usr/local/bin/node_exporter

2. Configure firewall

Configure firewall on resource

  1. Node exporter uses default port 9100, so allow it in firewall on resource.

Fedora (RHEL, CentOS)

sudo firewall-cmd --zone=public --add-port=9100/tcp --permanent
sudo systemctl reload firewalld

Check firewall configuration

sudo firewall-cmd --list-all

You should see in output:

ports: 9100/tcp

Debian (Ubuntu)

sudo ufw allow 9100

You should see in output:

Rules updated
Rules updated (v6)

Check firewall configuration

sudo ufw status

You should see in output:

To                             Action          From
--                             ------          ----
9100                           ALLOW           Anywhere

its good

3. Configure authentication for exporter

Do the steps described in Exporters configuration → Authentication section.

4. Check configuration

  1. Run node_exporter

/usr/local/bin/node_exporter/node_exporter --web.config.file=/usr/local/bin/node_exporter/web-config.yml

In output you should see:

... msg="TLS is enabled." ...

Check with browser if it is accessible at:

https://resource-hostname-or-ip:9100/metrics

After entering exporter’s user name and password you should see page like this:

# HELP go_gc_duration_seconds A summary of the wall-time pause (stop-the-world) duration in garbage collection cycles.
# TYPE go_gc_duration_seconds summary
go_gc_duration_seconds{quantile="0"} 2.2622e-05
...

Stop node exporter with Ctrl-c in terminal where you run it.

Make node_exporter service for autostart and restart.

Create file with your preferred text editor, for example nano …

sudo nano /etc/systemd/system/node_exporter.service

… and paste following text into it.

[Unit]
Description=Node Exporter

[Service]
User=prometheus
ExecStart=/usr/local/bin/node_exporter/node_exporter  --web.config.file=/usr/local/bin/node_exporter/web-config.yml

[Install]
WantedBy=multi-user.target

Save file and exit editor.

Start service …

sudo systemctl daemon-reload
sudo systemctl start node_exporter
sudo systemctl enable node_exporter

… and check

sudo systemctl status node_exporter

You should see following output similar to:

image-20250919-122901.png

In case of any problem, you should view log entries for service:

journalctl -u node_exporter.service -e

Now node exporter is ready to accept data and then expose it to Prometheus.