How to log and monitor traffic consumption with vnStat
vnStat is a lightweight console tool that keeps a history of network traffic on Linux. A background service, vnstatd, reads the interface counters from the kernel and saves them to a small database. You can then view traffic by hours, days, months and years, or watch the current transfer rate in real time. vnStat does not capture packets, so its overhead is very low. It shows how much traffic passed through each interface, but not which IP addresses, ports or connections created it.
This guide shows how to install vnStat from the repository or from source code, and how to view traffic statistics. vnStat is useful on any server where traffic is limited or billed, for example on an INTROSERV Linux VPS or dedicated server.
Install vnStat from the repository
Connect to your server over SSH. For details, see Connecting via SSH.
Ubuntu and Debian
vnStat is available in the standard repositories. Install it:
sudo apt update sudo apt install -y vnstat
The installation starts the vnstat service and enables it at boot. Check that it is running:
sudo systemctl status vnstat
The output must show active (running). If the service is not running, enable and start it with sudo systemctl enable --now vnstat.

AlmaLinux and Rocky Linux
vnStat is available in the EPEL repository. Enable EPEL and install vnStat:
sudo dnf install -y epel-release sudo dnf install -y vnstat
Enable and start the service:
sudo systemctl enable vnstat && sudo systemctl start vnstat
Check that it is running:
sudo systemctl status vnstat
Install vnStat from source code
Build vnStat from source if the package is not available for your distribution or if you need the latest version.
If vnStat is already installed from the repository, remove the package first: sudo apt remove -y vnstat on Ubuntu and Debian or sudo dnf remove -y vnstat on AlmaLinux and Rocky Linux. Both installations use the same configuration file, database and service name, so keeping them together causes conflicts.
Install the build dependencies. On Ubuntu and Debian:
sudo apt update && sudo apt install -y build-essential libsqlite3-dev wget
On AlmaLinux and Rocky Linux:
sudo dnf group install -y "Development Tools" sudo dnf install -y sqlite-devel wget
Download and unpack the latest release:
wget https://humdi.net/vnstat/vnstat-latest.tar.gz tar -xf vnstat-latest.tar.gz cd vnstat-*/
The archive unpacks into a directory with the version number in its name, for example vnstat-2.13. The wildcard vnstat-*/ lets you enter it without typing the version number.
Build and install vnStat:
./configure --prefix=/usr --sysconfdir=/etc && make && sudo make install
The --prefix=/usr option installs the programs to /usr/bin and /usr/sbin, and --sysconfdir=/etc places the configuration file in /etc/vnstat.conf.
On AlmaLinux and Rocky Linux with SELinux enabled, if vnStat was previously installed from the repository, restore the SELinux labels of the database directory first. Otherwise the service fails to start with a Permission denied error:
sudo restorecon -Rv /var/lib/vnstat
Install the systemd service, then enable and start it:
sudo cp -v examples/systemd/vnstat.service /etc/systemd/system/ sudo systemctl daemon-reload sudo systemctl enable --now vnstat
Check the version and the service status:
vnstat --version sudo systemctl status vnstat
Find the network interface
By default, vnStat adds all network interfaces of the server to its database, except the loopback interface. To see the interfaces currently stored in the database, run:
vnstat --dbiflist
You can also list the interfaces with ip a. The examples below use the interface ens3. Replace it with the name of your interface, for example eth0 or enp1s0.
By default, vnStat saves new data to the database every 5 minutes. Right after installation, the vnstat command reports that there is no data yet, for example Not enough data available yet or No data. Wait a few minutes and run the command again.
View traffic statistics
Run vnstat without options to see a summary for all interfaces, including traffic for the current day and month and an estimate for the end of each period.
vnstat
In all reports, rx is incoming traffic, tx is outgoing traffic, and total is their sum.
Traffic by hour
To view the 12 latest hourly entries, run:
vnstat -i ens3 -h --limit 12

Traffic by day
To view the 2 latest daily entries, run:
vnstat -i ens3 -d --limit 2
Without --limit, the number of entries shown is set by the ListDays parameter in /etc/vnstat.conf, 30 by default. It limits only the output, not the data stored in the database.
Traffic by month
vnstat -i ens3 -m

Traffic by year
vnstat -i ens3 -y
Traffic in real time
To watch the current transfer rate, run:
vnstat -i ens3 -l
The rate updates until you press Ctrl+C. If the command ran for more than 10 seconds, vnStat then shows a summary for this time.

Traffic for a set number of seconds
To measure the average traffic rate over a period of time, set the period in seconds. For example, 20 seconds:
vnstat -i ens3 -tr 20
Without a number, the measurement takes 5 seconds. The result is shown when the time is up.
Graph for the last 24 hours
To show the traffic for the last 24 hours as a text graph, run:
vnstat -i ens3 -hg

To process the statistics in a script, use the --json or --oneline option. For example, vnstat -i ens3 --json d exports daily statistics in JSON format.
Set the default interface
If the server has several interfaces and you usually check one of them, set it as the default in the configuration file /etc/vnstat.conf. Open the file:
sudo nano /etc/vnstat.conf
On AlmaLinux and Rocky Linux, nano is not installed by default. Install it with sudo dnf install -y nano or use vi.
Find the Interface line, remove the semicolon at the beginning and enter the name of your interface:
Interface "ens3"
Save the file. Now vnstat shows this interface when you run it without the -i option, for example vnstat -d. The vnstat service continues to monitor all interfaces.
For the full list of options, run vnstat --longhelp or see man vnstat.