title: TCP/UDP connections per port
agents: linux, aix, solaris, windows
catalog: os/networking
license: GPL-2.0-only
distribution: port_connections
description:
 This check monitors the number of connections per state on configurable
 local ports.

 It evaluates ONLY the {port_connections} section of the agent plug-in
 shipped with this MKP (deploy it via the "Port connections agent" bakery
 rule, or copy it to the host manually). The generic {netstat} section is
 never read.

 ESTABLISHED (ss: ESTAB) is always evaluated. For UDP, a socket counts as
 established if it is connected to a concrete peer (remote address is not a
 wildcard such as {0.0.0.0:*}).

 Other states (LISTEN, TIME_WAIT, CLOSE_WAIT, ..., UNCONN) can optionally
 get their own upper/lower levels - fixed, or predictive levels based on that
 state's own history. With predictive levels and the period "Day of the week",
 use a horizon of at least 15 days, otherwise no prediction is available.
 All states are always graphed in "Port connections by state", with or
 without levels.

 Optional local/remote address filters (exact IP, CIDR network or prefix)
 restrict counting. The protocol "TCP + UDP" creates two services for one
 port.

 The rule "Port connections: levels per connection state" overrides
 the discovered levels without re-discovery. The summary shows ESTABLISHED;
 other states only appear there once they go WARN/CRIT.

item:
 The protocol and the local port number separated by a space, e.g.
 {"TCP 443"}.

discovery:
 One service is created for each entry configured in the discovery ruleset
 "Port connections: ports to monitor".
