Install ntop on Red Hat Enterprise Linux / CentOS Linux

by Vivek Gite · 18 comments

This entry is part 17 of 2 in the series RRDtool

Q. ntop is a network probe that shows network usage in a way similar to what top does for processes. How do I install latest version of ntop on RHEL 5.x systems?

A. ntop is a network and traffic analyzer that provides a wealth of information on various networking hosts and protocols. ntop is primarily accessed via a built-in web interface.

Following instructions are tested on 32/64 bit versions only:
a) RHEL Linux 5.x
b) CentOS Linux 5.x

Download latest ntop

Visit ntop project to grab latest version. You can use wget to grab the same, enter:
# cd /opt
# wget http://freshmeat.net/redir/ntop/7279/url_tgz/ntop-3.3.6.tar.gz

Untar tar ball, enter:
# tar -zxvf ntop-3.3.6.tar.gz

Configure and Compile ntop under RHEL

You must have RRDTool installed. You also need to install libpcap, enter:
# yum install libpcap-devel libpcap
Type the following commands to compile and install ntop:
# cd ntop
# ./autogen.sh

Just type make to compile ntop:
# make
Just type make install to install ntop:
# make install
# make install-data-as

Create ntop user

Type the following command to run ntop as ntop user, enter:
# useradd -M -s /sbin/nologin -r ntop

Setup directory permissions

Next, you need to setup directory permissions, enter:
# chown ntop:root /usr/local/var/ntop/
# chown ntop:ntop /usr/local/share/ntop/

Setup ntop user admin password

Type the following command to set ntop admin password, enter:
# ntop -A
Sample output:

Mon Jul 28 03:38:34 2008  NOTE: Interface merge enabled by default
Mon Jul 28 03:38:34 2008  Initializing gdbm databases

ntop startup - waiting for user response!

Please enter the password for the admin user:
Please enter the password again:
Mon Jul 28 03:38:42 2008  Admin user password has been set

Start ntop

Type the following command to start ntop:
# /usr/local/bin/ntop -d -L -u ntop -P /usr/local/var/ntop --skip-version-check --use-syslog=daemon
Sample output:

Mon Jul 28 03:42:19 2008  NOTE: Interface merge enabled by default
Mon Jul 28 03:42:19 2008  Initializing gdbm databases

If you have multiple interface (eth0, eth1 and so on), start ntop as follows:
# /usr/local/bin/ntop -i "eth0,eth1" -d -L -u ntop -P /usr/local/var/ntop --skip-version-check --use-syslog=daemon
Where,

  • -i "eth0,eth1" : Specifies the network interface or interfaces to be used by ntop for network monitoring. Here you are monitoring eth0 and eth1.
  • -d : Run ntop as a daemon.
  • -L : Send all log messages to the system log (/var/log/messages) instead of screen.
  • -u ntop : Start ntop as ntop user
  • -P /usr/local/var/ntop : Specify where ntop stores database files. You may need to backup database as part of your disaster recovery program.
  • --skip-version-check : By default, ntop accesses a remote file to periodically check if the most current version is running. This option disables that check.
  • --use-syslog=daemon : Use syslog daemon.

How do I view ntop stats?

By default ntop listen on 3000 port. You can view ntop stats by visiting following url:
http://localhost:3000/
OR
http://server-ip:3000/
ntop in action
(Fig.01: ntop Global TCP/UDP Protocol Distribution Graphs [click to enlarge])

(Fig.02: Network Load Statistics (click to enlarge])

Open port 3000 using iptables

Open /etc/sysconfig/iptables file, enter:
# vi /etc/sysconfig/iptables
Append following code before final REJECT line:
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 3000 -j ACCEPT
Save and close the file. Restart firewall:
# service iptables restart

How do I view ntop stats without opening port 3000?

Setup simple tunnel using ssh, enter the following on your local UNIX / Linux desktop system:
$ ssh -L 3000:localhost:3000 -N -f user@server.yourcorp.com
Now open browser and type the following command:
http://localhost:3000/

How do I start ntop on boot?

Open /etc/rc.local file, enter:
# vi /etc/rc.local
Append the following line:
/usr/local/bin/ntop -i "eth0,eth1" -d -L -u ntop -P /usr/local/var/ntop --skip-version-check --use-syslog=daemon
Save and close the file.

How do I stop ntop?

Use web interface to shutdown ntop, or use normal kill / killall command:
# killall ntop

Further readings:

Series Navigation«Install RRDTool on Red Hat Enterprise Linux

Featured Articles:

Want to read Linux tips and tricks, but don't have time to check our blog everyday? Subscribe to our daily email newsletter to make sure you don't miss a single tip/tricks. Subscribe to our weekly newsletter here!

{ 18 comments… read them below or add one }

1 Gagan Brahmi 07.29.08 at 11:58 am

Thanks for the wonderful post Vivek. I have tried this out and it works flawlessly.

Maybe you need to mention that the installation of gdbm-devel as by default, I could not find that on the server. The other requirements are libtool automake autoconf.

So maybe someone would require to use this command as well:-

# yum install libtool automake autoconf gdbm-devel

2 vivek 07.29.08 at 12:28 pm

Gagan,

No problem. Yes, deps may vary from one installation to other.

I appropriate your post.

3 dot22 07.29.08 at 12:44 pm

Under the Centos5 you can install ntop natively by using rpmforge and epel repos.
I just enter the command:
“yum install ntop”
and voilà .) :

Resolving Dependencies
–> Running transaction check
—> Package ntop.i386 0:3.3.6-1.el5.rf set to be updated
–> Processing Dependency: librrd_th.so.2 for package: ntop
–> Running transaction check
—> Package rrdtool.i386 0:1.2.27-3.el5 set to be updated
–> Finished Dependency Resolution
===8<—–
Installed: ntop.i386 0:3.3.6-1.el5.rf
Dependency Installed: rrdtool.i386 0:1.2.27-3.el5
Complete!

4 vivek 07.29.08 at 12:46 pm

dot22,

Thanks for pointing out rpmforge repos. I generally don’t mix 3rd party repos with RHEL (as I might break their TOS). But under CentOS I don’t mind using rpmforge.

5 Ruben 11.05.08 at 1:06 pm

hi i have problems in the installation here is it:

[root@124 ~]# /usr/local/bin/ntop -i “eth0,eth1″ -d -L -u ntop -P /usr/local/var/ntop –skip-version-check –use-syslog=daemon
Wed Nov 5 09:27:49 2008 NOTE: Interface merge enabled by default
Wed Nov 5 09:27:49 2008 Initializing gdbm databases
Wed Nov 5 09:27:49 2008 **ERROR** ….open of /usr/local/var/ntop/prefsCache.db failed: Can’t be writer
Wed Nov 5 09:27:49 2008 Possible solution: please use ‘-P ‘
Wed Nov 5 09:27:49 2008 **FATAL_ERROR** GDBM open failed, ntop shutting down…
Wed Nov 5 09:27:49 2008 CLEANUP[t3086464704]: ntop caught signal 2 [state=2]
Wed Nov 5 09:27:49 2008 ntop is now quitting…

what would be the possible solution to this….

6 Tommy 12.16.08 at 11:51 am

Hi, How to install ntop v3.x + mySQL ?

7 LJ 01.30.09 at 11:59 am

Thanks for this post, I was running into a lot of compilation errors, and no other website out there had as clear instructions as you did. Thanks again !

8 shrirang 03.07.09 at 10:33 am

Hi Ruben,

Just do the following first before invoking above command & you will be able to start ntop :-)

$ killall ntop

9 irado 04.08.09 at 1:10 pm

I follow your instructions (including on install rddtool), but autogen.sh is stuck with this error message:

configure: error: Unable to find RRD at /usr/local/rrdtool: please use –with-rrd-home=DIR

verifying:

[root@HPAllan:/usr/src/ntop-3.3.9#]: ls /usr/local/rrdtool
lrwxrwxrwx 1 root root 23 Abr 8 09:47 /usr/local/rrdtool -> /usr/src/rrdtool-1.3.6/

so, rrdtool IS there :(

any hint?

10 irado 04.08.09 at 1:22 pm

another question:
ntop is up and running BUT.. :
when asking for the graphical (network load or anyother) it show this:
“NOTE: this page is not operational when the RRD plugin is disabled, misconfigured or missing.”

in the configuration, the rrd plugin is ENABLED (shows ‘yes’).

now I am stuck :(

any advice, PLEASE?

11 Thanuwat 05.18.09 at 10:47 am

I have a problem doing install in method make install

cp: cannot stat `GeoLiteCity.dat’: No such file or directory
make[2]: *** [install-data-local] Error 1
make[2]: Leaving directory `/usr/local/ntop-3.3.10-rc1′
make[1]: *** [install-am] Error 2
make[1]: Leaving directory `/usr/local/ntop-3.3.10-rc1′
make: *** [install-recursive] Error 1

how to solve it, Thank you.

12 Saeid 05.24.09 at 12:22 am

mkdir -p — //usr/local/etc/ntop
cp: cannot stat `GeoLiteCity.dat’: No such file or directory
make[2]: *** [install-data-local] Error 1
make[2]: Leaving directory `/root/ntop-3.3.9′
make[1]: *** [install-am] Error 2
make[1]: Leaving directory `/root/ntop-3.3.9′
make: *** [install-recursive] Error 1
[root@localhost ntop-3.3.9]#

13 Mihir Joshi 07.22.09 at 4:39 am

Hello Vivek,

I m not able to view graphs.
When i click on “Network Load”, gives below error
Error: NOTE: this page is not operational when the RRD plugin is disabled, misconfigured or missing. Please check the ntop log file.

Below are the permission.
root@scare [/usr/local/var/ntop/rrd]# ll
total 10
drwxr-xr-x 5 ntop ntop 2048 Jul 21 13:31 ./
drwxr-xr-x 3 ntop root 2048 Jul 22 14:31 ../
drwxrwxrwx 8 ntop ntop 2048 Jul 22 14:26 flows/
drwxrwxrwx 2 ntop ntop 2048 Jul 21 13:31 graphics/
drwxrwxrwx 3 ntop ntop 2048 Jul 21 13:31 interfaces/

Below is the log.
Wed Jul 22 14:31:29 2009 **ERROR** RRD: Disabled – unable to create directory (err 13, /usr/local/var/ntop/rrd/graphics)

Regards,
Mihirj

14 m++ 08.09.09 at 5:37 am

I noticed rrd didn’t work for me if I started `ntop -d` as a daemon. If I started it without the the -d flag as `ntop &` the rrd graphs work fine. I’m using v.3.3.11-dev which warns of possible funny business. Overall, the tool built easily and is completely awesome for monitoring network traffic!

15 charles 08.27.09 at 7:06 pm

cp: cannot stat `GeoLiteCity.dat’: No such file or directory
make[2]: *** [install-data-local] Error 1
make[2]: Leaving directory `/usr/local/ntop-3.3.10-rc1′
make[1]: *** [install-am] Error 2
make[1]: Leaving directory `/usr/local/ntop-3.3.10-rc1′
make: *** [install-recursive] Error 1

how to solve it, Thank you.

16 praveen 09.24.09 at 5:39 am

i install ntop from rpm . when i start the ntop it starts well but after sometime it automatically stops

17 Nishth Vyas 12.07.09 at 7:56 am

The provided link is not present. Please check.
wget http://freshmeat.net/redir/ntop/7279/url_tgz/ntop-3.3.6.tar.gz

18 Sachin Gholap 01.14.10 at 7:51 am

I m getting error when i use make command
plzzz help me
ntop.h:417:19: error: evdns.h: No such file or directory
address.c: In function ‘dns_response_callback’:
address.c:123: error: ‘DNS_ERR_NONE’ undeclared (first use in this function)
address.c:123: error: (Each undeclared identifier is reported only once
address.c:123: error: for each function it appears in.)
address.c:129: error: ‘DNS_IPv6_AAAA’ undeclared (first use in this function)
address.c:142: warning: assignment discards qualifiers from pointer target type
address.c:150: error: ‘DNS_IPv4_A’ undeclared (first use in this function)
address.c:164: error: ‘DNS_PTR’ undeclared (first use in this function)
address.c: In function ‘queueAddress’:
address.c:243: warning: nested extern declaration of ‘evdns_resolve_reverse’
address.c:243: error: ‘DNS_ERR_NONE’ undeclared (first use in this function)
address.c:249: warning: nested extern declaration of ‘evdns_resolve_reverse_ipv6′
make[2]: *** [address.lo] Error 1
make[2]: Leaving directory `/opt/ntop-3.3.10′
make[1]: *** [all-recursive] Error 1
make[1]: Leaving directory `/opt/ntop-3.3.10′
make: *** [all] Error 2

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Previous FAQ:

Next FAQ:

nixCraft FAQ PDF Collection Now Available To All