Watching traffic
This page covers the Activity hub (Activity and System status) and the Monitor hub (Connections, Routing log, DNS, Logs and Events). For each page it lists what the page shows, what you can do there and where its links lead.
Activity
Activity is the page doona opens by default. Some cards link to the page that holds their details; the Outbound mode and Global mode outbound cards hold controls instead.
Outbound mode
- In the Outbound mode card, select Rule, Direct or Global.
- For Global, choose a policy group in the Global mode outbound card. Until a group is chosen, Apply stays disabled and the card shows Global mode needs an outbound. Choosing a group also selects Global.
- Select Apply. doona writes the mode into the main configuration and reloads it, and a toast confirms the new mode. Selecting a mode without Apply changes nothing.
If the card shows Read-only, doona cannot write the main configuration. Select Read-only to see the reason, then see read-only sources. If it shows Not provided by this backend, the backend does not offer a configuration this card can edit.
Cards
- The status card shows the engine state. When some features are off, select the feature count (for example, 2 features are off) to open Features that are off on System status. View details opens System status.
- Select the Download or Upload tile to open the Traffic tab of Connections. Select Active connections to open the connection list.
- In the Latency card, choose a node from the Node menu. This changes only the latency shown on the card, not routing. Select the latency value to open that node on the Nodes page.
- Select the CPU usage value to open System status.
- In the Traffic card, choose Live, 10 min, 1 h, 6 h, 24 h or 7 d.
- In Outbound downloads, select an outbound to open Connections filtered to it. The chart counts downloads since the time shown beside its title; it does not show current rates.
- In Top traffic, switch between Devices and Domains. Select a device to open Connections filtered to that device, or a domain to open Connections searched for it. The ranking covers visible connections only; Truncated means the connection list was cut short.
- The Memory card charts process memory over time. Its View details also opens System status.
- Notifications lists recent notices. Consecutive identical notices are folded into one row with a count. Select View all to open Events.
System status
Open System status from the navigation, or from View details or the CPU usage value on Activity. The header shows the engine state, Config version, Uptime, CPU usage and Last reload. Config version identifies the configuration revision in effect; it is not the generation number.
- Engine shows the engine version, API, Build, Instance, Started and Configuration activated. A badge shows the backend's profile: Base or Full observability.
- Traffic counters shows TCP connections, UDP connections, Total connections, Upload, Download and Rate interval. The line below gives the counter start time and whether the counters cover all traffic or visible traffic.
- Memory shows Resident memory, the cgroup figures and OOM events, where the backend reports them. A cgroup usage bar appears when a cgroup limit is known.
- Datapath shows the checks of the eBPF programs, hooks and maps in the kernel, and an Attachments table. Datapath errors and runtime degradations appear as warnings under the card.
- Backend features lists the features the backend provides. Select one to open the page that uses it.
- Features that are off appears only when some features are off. Each row names the cause and the affected features. How to turn on shows the settings to add; Possible causes explains why; other rows link to Backend options or Geodata in Settings, or to this guide.
- Select Export state JSON to download the reported state. Reload, Suspend and Resume appear only when the backend allows them; a toast reports each result.
Connections
Connections opens on the Traffic tab. A link that filters the list or selects a connection opens the Connections tab instead.
Traffic tab
- Traffic per connection plots each connection: horizontal is upload, vertical is download. Select a point to open that connection in the Connections tab.
- Node latency places each node at the TCP latency the Nodes page shows, and separates nodes In use from nodes Not in use.
Connections tab
- The default columns are Target, Device, Node, Rule, State, Download, Download rate and Started. Use Columns to show or hide columns. Select a sortable heading to sort.
- Type a domain, IP, device or process in Filter. The text also matches the outbound, chain and rule. Use Network protocol, Outbound or Select (a device or a rule) to narrow the list. On narrow screens these filters sit under Filters.
- Use Group by to group By device, by Outbound or None. Expand all and Collapse all fold every group. Clear filters removes all filters.
- A notice appears when the list is truncated. Partial connection visibility or No connection visibility means an empty list does not prove the device has no connections.
- Select Export CSV to download the filtered list.
- Select a row to open its detail panel: state, target, device, process, observation source, Outbound, Chain and Rule.
- Add rule is the panel's primary action. The toolbar's Add rule does the same for the selected row. The dialog is described in Adding a rule.
- More actions offers, when available:
- Show matched rule: opens the rule on the Rules page.
- Edit matched rule's outbound settings: opens that rule for editing on the Rules page.
- View flow: opens the flow record in Routing log.
- Trace this connection: opens the Trace tab on the Rules page with this connection's input; see Trace.
- Only this device: filters the list to the connection's device.
- Close connection: closes the connection. It is disabled for connections observed only by eBPF, because the kernel forwards them and the backend has no userspace transfer to interrupt.
- Select Close all and confirm. With only a device and network filter, doona closes every matching connection, including ones opened after the dialog. Any other filter, or a truncated list, closes the listed connections one by one. Kernel-direct connections are skipped, and a toast reports how many were closed and skipped.
Routing log
Routing log shows how honk routed recorded flows. It has two tabs: Map and Records.
Map
- The Connection topology card draws the paths from rules or devices to outbounds and nodes, with the number of flows kept. Switch between By rule and By device.
- Select an item in the map to pin its path.
- Select Show the N flows on this path to open Records filtered to that path. Clear path filter removes the pin.
Records
- Filter by Network protocol (All, TCP or UDP) and by State. A path or connection filter appears as a chip (Path: … or Connection: …); select the chip to remove it. Observation coverage appears when part of the traffic was not fully observed.
- The columns are Target, Node, Rule, Protocol, State and Started.
- Select a flow to open its detail panel. It shows whether the trace is Complete or Partial, the configuration revision, State, Outbound, Node, Rule and, for a partial trace, Why incomplete. The ordered trace steps follow.
- Select View connection to open the live connection, if it still exists. Select Add a rule for this target to open the rule dialog; see Adding a rule.
- Recording settings opens Backend options in Settings, where flow recording is configured; see backend options.
DNS
DNS has up to four tabs, in this order: Statistics, Resolution log, Cache and Query. Only the tabs the backend supports appear.
- Statistics summarises the latest page of the resolution log: Median, P95, Cache hit rate and Failure rate, then upstream latency, Outcomes, Cache and Top queries.
- Open DNS configuration opens the configuration's
dnssection on the Configuration page. - View cache opens the Cache tab.
- In Top queries, switch between Devices and Domains. Select an entry to open Resolution log filtered to it.
- Open DNS configuration opens the configuration's
- Resolution log lists recent resolutions with Time, Domain, Type, Device, Result, Upstream and Elapsed.
- Filter by Domain, Type or Device.
- Select a row to see its answers, cache status and route. Add rule opens the rule dialog for it.
- Refresh loads the newest records. When newer records are waiting, a note says so; Refresh replaces the loaded records.
- Load older records extends the list. Export CSV covers only the loaded records.
- Cache lists entries with Domain, Type, State, Expires and Stale until.
- Select an entry, then Add rule to open the rule dialog for it.
- Delete removes one entry, when the backend supports it.
- Clear all cache removes every entry after a confirmation, when the backend supports it. This cannot be undone.
- Query sends a DNS query through honk's DNS routing.
- Enter a domain, choose a Type, then select Query.
- The result shows Cache hit or Cache miss, State, Upstream, Route source, Route rule, Elapsed and the answers.
- These queries are diagnostic: they do not appear in Resolution log.
- Add rule opens the rule dialog for the name or an answer address. View cache opens the matching cache entries.
Logs
Logs shows the engine's live log stream.
- Set Level to the minimum severity to show. Beside it, Engine records: … and above shows the level the engine records; levels below it are marked as needing a lower log level in Settings.
- Type a module prefix in Module to filter by module.
- Log activity over time charts the received records by level. Select a level in the chart to make it the minimum.
- Turn on Pause to hold the list. The status shows how many new records have arrived; they appear when you turn Pause off. Only the newest records are kept while paused.
- Clear removes the displayed records from this page. Export downloads the received records as a text file.
- Recording settings opens Backend options in Settings, where log recording and the log level are set.
- Select a row to read the whole message. The status shows Streaming, Reconnecting or Disconnected. On reconnection, retained records are replayed; if replay is no longer possible, the list marks the gap.
If the list shows Log recording is disabled in the configuration, change the honk configuration; see configuration. If it shows Turn on log recording in Settings first, turn it on under Recording settings.
Events
Events shows the backend's event stream, newest first.
- Kind starts at Exclude runtime updates. Choose All kinds, or one kind the backend advertises.
- The list shows Time, Kind and Summary. The toolbar shows the connection state, the number of events kept and, when available, Resumes from the last position.
- Select an event to read its full summary. A Configuration activated event links to View configuration. A Flow records lost event links to View flow record and Recording settings.
- Select Export JSON to download the events currently shown.
After a disconnection, retained events are replayed. If the replay cursor has expired, a row in the list marks the lost events.