Hello selfhosters.

We all have bare-metal servres, VPS:es, containers and other things running. Some of them may be exposed openly to the internet, which is populated by autonomous malicious actors, and some may reside on a closed-off network since they contain sensitive data.

And there is a lot of solutions to monitor your servers, since none of us want our resources to be part of a botnet, or mine bitcoins for APTs, or simply have confidential data fall into the wrong hands.

Some of the tools I’ve looked at for this task are check_mk, netmonitor, monit: all of there monitor metrics such as CPU, RAM and network activity. Other tools such as Snort or Falco are designed to particularly detect suspicious activity. And there also are solutions that are hobbled together, like fail2ban actions together with pushover to get notified of intrusion attempts.

So my question to you is - how do you monitor your servers and with what tools? I need some inspiration to know what tooling to settle on to be able that detect unwanted external activity on my resources.

  • StritEnglish
    arrow-up
    15
    arrow-down
    0
    ·
    9 months ago
    link
    fedilink

    I’m pretty old school, but as I only have 1 server, I just use ssh, df, du and top.

    • Deebster
      cake
      English
      arrow-up
      12
      arrow-down
      0
      ·
      9 months ago
      link
      fedilink

      Not even htop? That is old school.

      • beta_testerEnglish
        arrow-up
        12
        arrow-down
        0
        ·
        9 months ago
        link
        fedilink

        Not even btop? That’s middle school.

        • SamsyEnglish
          arrow-up
          6
          arrow-down
          0
          ·
          9 months ago
          link
          fedilink

          Not even bottom? That’s elementary school.