Hello.
On 14/10/2025 13.38, Stephane Paillet wrote:
I'm doing tests of filtering DNS with RPZ lists.
Now, I would like to collect stats and metrics about blocked requests (blocked domains,
sources IP, count of blocked requests...).
In journalctl I have logs like this : "[rules ] => local data applied, user:
xxx.xxx.xxx.xxx, name: blocked-domain.tld." Main infos I want to collect exist.
Is there a way to do this with Prometheus format metrics + Grafana ? I didn't really
find anything in documentation.
No, we don't collect these counts so far.
And I don't expect we could expose them as metrics in a straightforward
way, as there might be like millions of different domains in your
blocklists and the user count could be way too large, too. Maybe
prometheus could be OK with exposing just some changing set of top
names/users, but we currently don't even have suitable data structures
for that internally.
--Vladimir