Visiting http://localhost:9115/probe?target=google.com&module=http_2xx
will return metrics for a HTTP probe against google.com. The probe_success
metric indicates if the probe succeeded. Adding a debug=true parameter
will return debug information for that probe.
The probe will also return timing metrics for measuring how long it takes to
probe the target.
For example, you can find out how much of the probe timeout is used. This is
useful because Prometheus timeouts can never be longer than the scrape interval.
probe_duration_seconds / probe_timeout_seconds
This query will return the ratio of remaining time.
Metrics concerning the operation of the exporter itself are available at the
endpoint http://localhost:9115/metrics.
TLS and basic authentication
The Blackbox Exporter supports TLS and basic authentication. This enables better
control of the various HTTP endpoints.
To use TLS and/or basic authentication, you need to pass a configuration file
using the --web.config.file parameter. The format of the file is described
in the exporter-toolkit repository.
Note that the TLS and basic authentication settings affect all HTTP endpoints:
/metrics for scraping, /probe for probing, and the web UI.
Controlling log level for probe logs
The blackbox_exporter has a primary structured logger that is used for logs related to the application itself. Application logs can be controlled by --log.level, which sets the log level for messages to output, valid levels are debug, info, warn, and error.
The blackbox_exporter also maintains a second, fully independent structured logger that is used specifically for logging related to the probers (http, tcp, icmp, dns, grpc) and their output.
The scrape probe logger defaults to info level filtering, similar to the primary logger. Prober logs can be controlled with --log.prober
Note
All log samples below used the following basic blackbox.yml configuration file and contain the probe logs of a single scrape generated by curl
~ $ curl -sL "http://localhost:9115/probe?target=prometheus.io&module=http_2xx&debug=true" | sed '/Metrics that would have been returned/q'
Logs for the probe:
time=2025-09-09T00:58:06.756-04:00 level=WARN source=http.go:490 msg="Received redirect" module=http_2xx target=prometheus.io location=https://prometheus.io/
Metrics that would have been returned:
Example stderr and debug module output with `--log.prober=debug`
Blackbox exporter is configured via a configuration file and command-line flags (such as what configuration file to load, what port to listen on, and the logging format and level).
Blackbox exporter can reload its configuration file at runtime. If the new configuration is not well-formed, the changes will not be applied.
A configuration reload is triggered by sending a SIGHUP to the Blackbox exporter process or by sending a HTTP POST request to the /-/reload endpoint.
Blackbox exporter also supports automatic configuration reloading. You can enable this feature using the --config.enable-auto-reload flag.
When enabled, the exporter will automatically check for changes to its configuration file at a specified interval in seconds.
The interval can be customized with the --config.auto-reload-interval flag, which is set to 30 (which is 30 seconds) by default.
To view all available command-line flags, run ./blackbox_exporter -h.
To specify which configuration file to load, use the --config.file flag.
HTTP, HTTPS (via the http prober), DNS, TCP socket, ICMP and gRPC (see permissions section) are currently supported.
Additional modules can be defined to meet your needs.
The timeout of each probe is automatically determined from the scrape_timeout in the Prometheus config, slightly reduced to allow for network delays.
This can be further limited by the timeout in the Blackbox exporter config file. If neither is specified, it defaults to 120 seconds.
The blackbox exporter needs to be passed the target as a parameter, this can be
done with relabelling.
Example config:
scrape_configs:
- job_name: 'blackbox'
metrics_path: /probe
params:
module: [http_2xx] # Look for a HTTP 200 response.
static_configs:
- targets:
- http://prometheus.io # Target to probe with http.
- https://prometheus.io # Target to probe with https.
- http://example.com:8080 # Target to probe with http on port 8080.
relabel_configs:
- source_labels: [__address__]
target_label: __param_target
- source_labels: [__param_target]
target_label: instance
- target_label: __address__
replacement: 127.0.0.1:9115 # The blackbox exporter's real hostname:port.
- job_name: 'blackbox_exporter' # collect blackbox exporter's operational metrics.
static_configs:
- targets: ['127.0.0.1:9115']
HTTP probes can accept an additional hostname parameter that will set Host header and TLS SNI. This can be especially useful with dns_sd_config:
scrape_configs:
- job_name: blackbox_all
metrics_path: /probe
params:
module: [ http_2xx ] # Look for a HTTP 200 response.
dns_sd_configs:
- names:
- example.com
- prometheus.io
type: A
port: 443
relabel_configs:
- source_labels: [__address__]
target_label: __param_target
replacement: https://$1/ # Make probe URL be like https://1.2.3.4:443/
- source_labels: [__param_target]
target_label: instance
- target_label: __address__
replacement: 127.0.0.1:9115 # The blackbox exporter's real hostname:port.
- source_labels: [__meta_dns_name]
target_label: __param_hostname # Make domain name become 'Host' header for probe requests
- source_labels: [__meta_dns_name]
target_label: vhost # and store it in 'vhost' label
Permissions
The ICMP probe requires elevated privileges to function:
Windows: Administrator privileges are required.
Linux: either a user with a group within net.ipv4.ping_group_range, the
CAP_NET_RAW capability or the root user is required.
Your distribution may configure net.ipv4.ping_group_range by default in
/etc/sysctl.conf or similar. If not you can set
net.ipv4.ping_group_range = 0 2147483647 to allow any user the ability
to use ping.
Alternatively the capability can be set by executing setcap cap_net_raw+ep blackbox_exporter
BSD: root user is required.
OS X: No additional privileges are needed.
The UNIX probe requires the process owner to have write permissions (w) to the UNIX socket,
and access permissions (x) to the directory structure the socket resides in.
Blackbox exporter
The blackbox exporter allows blackbox probing of endpoints over HTTP, HTTPS, DNS, TCP, ICMP and gRPC.
Running this software
From binaries
Download the most suitable binary from the releases tab
Then:
Using the docker image
Note: You may want to enable ipv6 in your docker configuration
Checking the results
Visiting http://localhost:9115/probe?target=google.com&module=http_2xx will return metrics for a HTTP probe against google.com. The
probe_successmetric indicates if the probe succeeded. Adding adebug=trueparameter will return debug information for that probe.The probe will also return timing metrics for measuring how long it takes to probe the target.
For example, you can find out how much of the probe timeout is used. This is useful because Prometheus timeouts can never be longer than the scrape interval.
This query will return the ratio of remaining time.
Metrics concerning the operation of the exporter itself are available at the endpoint http://localhost:9115/metrics.
TLS and basic authentication
The Blackbox Exporter supports TLS and basic authentication. This enables better control of the various HTTP endpoints.
To use TLS and/or basic authentication, you need to pass a configuration file using the
--web.config.fileparameter. The format of the file is described in the exporter-toolkit repository.Note that the TLS and basic authentication settings affect all HTTP endpoints: /metrics for scraping, /probe for probing, and the web UI.
Controlling log level for probe logs
The blackbox_exporter has a primary structured logger that is used for logs related to the application itself. Application logs can be controlled by
--log.level, which sets the log level for messages to output, valid levels aredebug,info,warn, anderror.The blackbox_exporter also maintains a second, fully independent structured logger that is used specifically for logging related to the probers (
http,tcp,icmp,dns,grpc) and their output. The scrape probe logger defaults toinfolevel filtering, similar to the primary logger. Prober logs can be controlled with--log.proberExample stderr and debug module output with `--log.prober=info` (default)
Example stderr and debug module output with `--log.prober=debug`
Building the software
Local Build
Building with Docker
After a successful local build:
Configuration
Blackbox exporter is configured via a configuration file and command-line flags (such as what configuration file to load, what port to listen on, and the logging format and level).
Blackbox exporter can reload its configuration file at runtime. If the new configuration is not well-formed, the changes will not be applied. A configuration reload is triggered by sending a
SIGHUPto the Blackbox exporter process or by sending a HTTP POST request to the/-/reloadendpoint.Blackbox exporter also supports automatic configuration reloading. You can enable this feature using the
--config.enable-auto-reloadflag. When enabled, the exporter will automatically check for changes to its configuration file at a specified interval in seconds. The interval can be customized with the--config.auto-reload-intervalflag, which is set to 30 (which is 30 seconds) by default.To view all available command-line flags, run
./blackbox_exporter -h.To specify which configuration file to load, use the
--config.fileflag.Additionally, an example configuration is also available.
HTTP, HTTPS (via the
httpprober), DNS, TCP socket, ICMP and gRPC (see permissions section) are currently supported. Additional modules can be defined to meet your needs.The timeout of each probe is automatically determined from the
scrape_timeoutin the Prometheus config, slightly reduced to allow for network delays. This can be further limited by thetimeoutin the Blackbox exporter config file. If neither is specified, it defaults to 120 seconds.Prometheus Configuration
Blackbox exporter implements the multi-target exporter pattern, so we advice to read the guide Understanding and using the multi-target exporter pattern to get the general idea about the configuration.
The blackbox exporter needs to be passed the target as a parameter, this can be done with relabelling.
Example config:
HTTP probes can accept an additional
hostnameparameter that will setHostheader and TLS SNI. This can be especially useful withdns_sd_config:Permissions
The ICMP probe requires elevated privileges to function:
net.ipv4.ping_group_range, theCAP_NET_RAWcapability or the root user is required.net.ipv4.ping_group_rangeby default in/etc/sysctl.confor similar. If not you can setnet.ipv4.ping_group_range = 0 2147483647to allow any user the ability to use ping.setcap cap_net_raw+ep blackbox_exporterThe UNIX probe requires the process owner to have write permissions (w) to the UNIX socket, and access permissions (x) to the directory structure the socket resides in.