Wayseer

User guideWayseer 0.28.3Contents

This machine

The localhost module shows the machine Wayseer runs on: the host, its CPUs, memory, disks, filesystems, network interfaces and processes, with metrics for each. Where the machine runs systemd, it adds the system units with their dependencies, and journal entries as events; on Windows, it adds the services. On Linux it reads /proc, /sys, systemd over D-Bus, and journalctl; on macOS, the system's own counters (below); on Windows, its own calls (below). It needs no privileges and changes nothing. It runs on Linux and macOS, and on Windows from 0.28.0.

Configuration

modules:
  - kind: localhost
    name: this-machine

The default config written on first run has these lines already, so a first run opens on this machine (install). That is enough. The options below go under options:

modules:
  - kind: localhost
    name: this-machine
    options:
      processes: false     # no processes, only the machine
      journal: err         # only errors and worse from the journal
      units: [service]     # only services, not sockets or timers

interval

How often the machine is read.

Type
duration
Default
2s

history

How far back machine series are kept, 10 intervals to 24h.

Type
duration
Default
1h

processes

List processes as entities.

Type
bool
Default
true

process_history

How far back per-process series are kept, up to history.

Type
duration
Default
5m

commands

Show command lines, which can hold secrets.

Type
bool
Default
true

root

Where proc, sys and etc are found, such as a container's mount of the host.

Type
string
Default
/

units

Systemd unit types listed, [] for none.

Type
list of string
Default
service, socket, timer, target, path

journal

Least severe journal priority sent, emerg to debug, or off.

Type
string
Default
warning

journal_backlog

Journal entries sent from before the start, up to 1000.

Type
integer
Default
100

keep_stopped

How long a unit that stopped stays listed, up to 24h.

Type
duration
Default
1h

commands shows each process's full command line. A command line can hold a password passed as an argument, so set commands: false on a shared screen. root suits running in a container with the host's filesystem mounted, such as at /host.

What shows

host

hostname, kernel, os, cores, memory, booted, ip

localhost/cpu

index

localhost/memory

total, swap_total

disk

size, model, rotational, removable

localhost/filesystem

type, mounts, size

interface

mac, mtu, address

process

pid, ppid, user, started, command

localhost/unit

unit, type, description, state, sub_state, file_state, result

memory, total, swap_total and both sizes are in bytes, and Detail shows them so, as 15.6 GiB. Filter on them the same way: /kind:host memory>=32GiB.

A filesystem is warn at 90% used and crit at 95%, counted as df counts it. An interface whose link is down shows as down.

Units. A unit shows once it has been seen running. A unit that stops stays on screen for keep_stopped, and a failed one stays until it recovers.

  • A unit that should be running and stops without anyone asking is down, "should be running". "Should be running" means it is enabled, or wanted by an active target. A oneshot, or a unit a timer or path starts when due, is not counted.
  • A unit stopped on request is unknown, "stopped".
  • A oneshot that ends is "finished".
  • Any other failed unit is crit.

Each change of a unit's state is an event on it. A unit's dependencies are its links.

Journal. Entries at journal priority or worse show as events in Stream and on the Timeline, on the unit they are about or came from, else on their process, else on the host. The last journal_backlog entries from before Wayseer started are sent too. A machine without systemd, or a journal Wayseer cannot read, shows as a note in the module's health, not as an error. To read the whole journal, add your user to the systemd-journal group, which your distribution may call something else.

Metrics

cpu.utilisation

Share of CPU time spent busy; for a process, its share of the whole host.

Unit
percent
Kinds
host
localhost/cpu
process

memory.utilisation

Share of memory not available to new work.

Unit
percent
Kinds
host
localhost/memory

memory.used

Memory not available to new work.

Unit
bytes
Kinds
localhost/memory

memory.available

Memory available to new work without swapping.

Unit
bytes
Kinds
localhost/memory

swap.used

Swap in use.

Unit
bytes
Kinds
localhost/memory

disk.read

Bytes read.

Unit
bytes_per_second
Kinds
disk

disk.write

Bytes written.

Unit
bytes_per_second
Kinds
disk

disk.utilisation

Share of time with I/O in flight.

Unit
percent
Kinds
disk

fs.used

Space used.

Unit
bytes
Kinds
localhost/filesystem

fs.utilisation

Share of space used, as df reports it.

Unit
percent
Kinds
localhost/filesystem

net.receive

Bytes received.

Unit
bytes_per_second
Kinds
interface

net.transmit

Bytes sent.

Unit
bytes_per_second
Kinds
interface

memory.rss

Resident memory.

Unit
bytes
Kinds
process

Machine metrics are kept for history, and process metrics for process_history.

On macOS

A Mac shows the same host, CPUs, memory, filesystems, network interfaces and processes, with the same metrics, with these differences:

  • No disks. macOS keeps disks behind IOKit, which the module does not read yet, so there are no disk entities and no disk.* metrics; each filesystem links to the host. Detail and the palette offer only the metrics a Mac has.
  • Filesystems. The system's own hidden volumes (VM, Preboot, Update and the like) are left out. The Data volume, /System/Volumes/Data, is kept: it holds your files.
  • Memory available is free and inactive memory, as Activity Monitor counts it.
  • Another user's processes, root's included, have no CPU or memory metrics: macOS tells only an administrator. They are still listed, with their user and parent. Their command lines are hidden too.
  • No units or journal. launchd services are not listed, and units, journal, journal_backlog and keep_stopped do nothing.
  • root still reads a Linux machine's copied /proc and /sys, as on Linux.

On Windows

From 0.28.0, Windows shows the host, its CPUs, memory, volumes, network interfaces, processes and services, with the same metrics, and the default config lists the module there too. A config 0.27 wrote on Windows has its entry commented out; remove the # before its two lines. The differences:

  • No disks. As on a Mac, there are no disk entities and no disk.* metrics; each volume links to the host.
  • Volumes. Each fixed drive is a localhost/filesystem named by its letter, such as C:\. DVD drives, USB sticks and network shares are left out. A drive BitLocker keeps locked is listed, with its usage unknown.
  • Memory available is what Task Manager calls Available. Windows has no swap partition, so there is no swap.used.
  • The host's os is the edition and release, as Settings shows them, such as Windows 11 Pro 24H2, and kernel is the build, such as 10.0.26100.
  • CPUs. On a machine with more than 64 logical processors, only one group of up to 64 is listed; the host's CPU use counts them all.
  • Processes show their user and command line. A process Wayseer can't open is listed by name and PID only, with no start time, CPU or memory: another user's, unless Wayseer runs as administrator, or a protected one.
  • Services come from the service control manager, as service units; drivers are left out. Each is named as Windows names it, such as Spooler, with its display name as description and its startup type as file_state, such as Automatic (Delayed Start). The services it depends on are its links, a load-order group counting as each service in it, and the process it runs in is a member of it.
  • Should be running means the startup type is Automatic, with or without Delayed Start. A Manual or Trigger Start service is not counted.
  • A service that stops cleanly is unknown, "stopped", as Windows can't say whether it was asked to or stopped on its own; "stopped by request" when Wayseer saw it stopping. One that stops with an error code is crit, "failed", with the code in result, or down, "should be running", if it should be.
  • No journal. The Event Log is not read, so journal and journal_backlog do nothing. units: [] turns services off; the other unit types don't exist on Windows.