diff options
Diffstat (limited to 'internal')
| -rw-r--r-- | internal/server/metrics/metrics.go | 6 | ||||
| -rw-r--r-- | internal/server/server.go | 2 |
2 files changed, 8 insertions, 0 deletions
diff --git a/internal/server/metrics/metrics.go b/internal/server/metrics/metrics.go index 4937787..1ce907c 100644 --- a/internal/server/metrics/metrics.go +++ b/internal/server/metrics/metrics.go @@ -26,6 +26,12 @@ var RequestProcessingDuration = promauto.NewHistogramVec(prometheus.HistogramOpt NativeHistogramBucketFactor: 1.00271, }, []string{"request_type", "dropped"}) +var ConnectionsRateLimited = promauto.NewCounterVec(prometheus.CounterOpts{ + Namespace: namespace, + Name: "connections_rate_limited_total", + Help: "The total number of rate limited connections", +}, []string{"category"}) + var ConnectionsEstablished = promauto.NewCounter(prometheus.CounterOpts{ Namespace: namespace, Name: "connections_established_total", diff --git a/internal/server/server.go b/internal/server/server.go index 90d24a3..ecb5234 100644 --- a/internal/server/server.go +++ b/internal/server/server.go @@ -636,6 +636,7 @@ func (s *server) isRateLimited(ip uint32) bool { s.ipConns[ip] = entry return false } else if entry.count < RateLimitCountThresholdMalicious { + metrics.ConnectionsRateLimited.WithLabelValues("suspicious").Inc() if entry.count == RateLimitCountThresholdSus { slog.Warn("suspicious connection activity", "ip", ipStr, "count", entry.count) // Only log the first one @@ -644,6 +645,7 @@ func (s *server) isRateLimited(ip uint32) bool { s.ipConns[ip] = entry return true } else { + metrics.ConnectionsRateLimited.WithLabelValues("malicious").Inc() if entry.count == RateLimitCountThresholdMalicious { slog.Warn("potential malicious connection behavior", "ip", ipStr, "count", entry.count) // Only log the first one |
