Skip to main content

Prometheus Metrics Reference

All backend metrics are created via OpenTelemetry instruments and exported on the /metrics endpoint (port 8080) in Prometheus format. Metrics are defined in backend/internal/observability/metrics.go.

HTTP​

MetricTypeLabelsDescription
proxima_http_requests_totalcountermethod, path, statusTotal HTTP requests
proxima_http_request_duration_secondshistogrammethod, pathHTTP request duration in seconds

Auth​

MetricTypeLabelsDescription
proxima_auth_login_totalcounterprovider, resultTotal login attempts (result: success, failed, mfa_required)
proxima_auth_token_refresh_totalcounterresultTotal token refresh attempts (result: success, invalid, revoked, expired)
proxima_auth_mfa_verification_totalcounterresultTotal MFA verification attempts (result: success, failed, recovery_code)
proxima_auth_session_revocation_totalcounterreasonTotal session revocations (reason: logout, disabled)
proxima_auth_cache_hit_totalcounter—Total auth cache hits
proxima_auth_cache_miss_totalcounter—Total auth cache misses
proxima_auth_access_resolution_secondshistogram—Access resolution latency in seconds
proxima_auth_lockout_activeupdowncounter—Currently locked out accounts
proxima_auth_password_reset_totalcountertypeTotal password resets (type: admin)
MetricTypeLabelsDescription
proxima_search_query_totalcounter—Total PQL queries
proxima_search_query_duration_secondshistogram—End-to-end PQL query latency in seconds
proxima_search_results_totalcounter—Total search result rows returned

NATS Workers​

MetricTypeLabelsDescription
proxima_nats_messages_received_totalcountertypeTotal NATS messages received
proxima_nats_messages_processed_totalcountertype, statusTotal NATS messages processed
proxima_nats_message_processing_duration_secondshistogramsubject_class, statusPer-message processing time in seconds

VictoriaMetrics Client​

MetricTypeLabelsDescription
proxima_vm_operation_totalcounter—Total VictoriaMetrics API calls
proxima_vm_operation_duration_secondshistogram—VictoriaMetrics API call latency in seconds

Tenant Cache​

MetricTypeLabelsDescription
proxima_tenantcache_lookup_totalcounter—Tenant cache hit/miss counter
proxima_tenantcache_lookup_duration_secondshistogram—Tenant cache lookup latency in seconds

Stale Detector​

MetricTypeLabelsDescription
proxima_stale_hosts_marked_offline_totalcounter—Cumulative hosts marked offline by stale detector

Panic Recovery​

MetricTypeLabelsDescription
proxima_api_panic_recovery_totalcounter—Recovered panics in HTTP handlers

Change Detection​

MetricTypeLabelsDescription
proxima_changes_processed_totalcounterscan_type, event_typeTotal file change events processed
proxima_changes_processing_duration_secondshistogram—Change detection message processing duration in seconds
proxima_file_versions_created_totalcounter—Total file versions created

Log Collection​

MetricTypeLabelsDescription
proxima_logs_entries_processed_totalcountersourceTotal log entries processed from agents
proxima_logs_processing_duration_secondshistogram—Log message processing duration in seconds
proxima_logs_query_totalcounter—Total log queries from frontend
proxima_logs_query_duration_secondshistogram—Log query latency in seconds

NATS JWT Lifecycle​

MetricTypeLabelsDescription
proxima_install_token_created_totalcounter—Total install tokens created
proxima_jwt_issued_totalcounter—Total NATS user JWTs issued
proxima_jwt_renewed_totalcountermethodTotal NATS user JWTs renewed (method: nats, https)
proxima_jwt_revoked_totalcounter—Total NATS user JWTs revoked
proxima_jwt_credential_challenge_totalcounterstatusTotal credential challenge requests
proxima_jwt_credential_exchange_totalcounterstatusTotal credential exchange requests

Healthcheck​

MetricTypeLabelsDescription
proxima_healthcheck_runs_processed_totalcounterscanner, statusTotal healthcheck runs processed
proxima_healthcheck_results_processed_totalcounterstatus, sourceTotal healthcheck results processed
proxima_healthcheck_findings_processed_totalcounterscanner, severity, typeTotal scanner findings processed
proxima_healthcheck_processing_duration_secondshistogram—Healthcheck processing duration in seconds
proxima_healthcheck_trigger_totalcounter—Total healthcheck triggers via API
proxima_healthcheck_score_calculatedhistogram—Distribution of calculated healthcheck scores (0–100)

Compliance​

MetricTypeLabelsDescription
proxima_compliance_evaluations_totalcounterframework, statusTotal control evaluations performed
proxima_compliance_evaluation_duration_secondshistogram—Time to evaluate all controls for one host
proxima_compliance_controls_totalupdowncounter—Size of the control library: +1 on create, −1 on delete. Not a status distribution — it carries no status attribute.

Alerting​

MetricTypeLabelsDescription
proxima_alerts_resolved_totalcounter—Total alert groups resolved
proxima_alert_resolve_no_open_group_totalcountersource_typeResolve-only deliveries dropped because no open alert group exists for their (source, grouping key). A resolve never creates a group — see A resolution never creates an alert group

Telegram Alert Card​

Collected only: no alert rule ships for either. See When edits fail: what operators see.

MetricTypeLabelsDescription
proxima_telegram_card_edits_totalcounterresult (ok, not_modified, transient, permanent, skipped_known_failure)Outcomes of the alert card Syncer's edits, one per tracked message a run tried to bring up to date. transient is retried (up to 3 retries per burst); permanent is not retried by the run; skipped_known_failure made no call because the same edit already failed permanently within the hour. A message already showing its group's state is not counted
proxima_telegram_card_edit_retries_exhausted_totalcounter—Bursts of card sync runs for one alert group that still needed a retry after 3 retries; the group's messages wait for its next sync or a reconciler sweep

Credentials​

MetricTypeLabelsDescription
proxima_credential_operations_totalcounteroperation, statusTotal credential CRUD operations (operation: create, list, get, update, delete, test)
proxima_credential_operation_duration_secondshistogram—Credential operation duration
proxima_credential_encrypt_totalcountercredential_typeTotal Vault Transit encrypt operations
proxima_credential_decrypt_totalcountercredential_id, credential_typeTotal Vault Transit decrypt operations
proxima_credential_test_totalcountercredential_type, successTotal credential connectivity tests
proxima_credential_rotation_totalcounter—Total credential secret rotations

Config Sync​

MetricTypeLabelsDescription
proxima_configsync_push_totalcounter—Total config push operations to agents
proxima_configsync_push_duration_secondshistogram—Config push duration
proxima_configsync_apply_totalcounterconfig_type, statusTotal config apply acks from agents
proxima_configsync_resolve_totalcounterconfig_typeTotal config resolution operations
proxima_configsync_resolve_duration_secondshistogram—Config resolution duration

Database​

MetricTypeLabelsDescription
proxima_db_connections_opengauge (observable)—Number of open database connections
proxima_db_connections_idlegauge (observable)—Number of idle database connections

Business​

MetricTypeLabelsDescription
proxima_agents_online_totalgauge (observable)—Number of agents currently online
proxima_hosts_totalgauge (observable)—Total number of hosts

Terminal​

MetricTypeLabelsDescription
proxima_terminal_sessions_totalcounterlogin, roleTotal sessions started
proxima_terminal_sessions_activeupdowncounter—Currently active sessions
proxima_terminal_session_duration_secondshistogramend_reasonSession duration
proxima_terminal_auth_denied_totalcounterlogin, roleRBAC denials
proxima_terminal_errors_totalcounterreasonSession errors
proxima_terminal_peers_activeupdowncounter—Currently connected session peers (session sharing)
proxima_terminal_peer_joins_totalcounter—Total peer join events
proxima_terminal_file_transfer_totalcounterdirection, statusTotal terminal file transfers
proxima_terminal_file_transfer_bytes_totalcounterdirectionTotal bytes transferred via terminal file transfer
proxima_terminal_file_transfer_duration_secondshistogramdirectionTerminal file transfer duration in seconds

Fleet​

MetricTypeLabelsDescription
proxima_fleet_rollouts_totalcounterstatus (created/paused/completed/aborted)Rollout lifecycle transitions
proxima_fleet_rollouts_activegauge—Currently active rollouts
proxima_fleet_agent_updates_totalcounterstatus (sent/healthy/failed/timed_out/skipped_offline)Per-agent update transitions
proxima_fleet_update_duration_secondshistogram—Rollout duration from start to terminal status
proxima_fleet_auth_denied_totalcounter—Tenant/scope denials on rollout requests

AI Chat & MCP​

MetricTypeLabelsDescription
proxima_chat_messages_totalcounterroleTotal chat messages
proxima_chat_tokens_totalcountermodel, direction (input/output)Total tokens consumed
proxima_chat_cost_usd_totalcountermodelEstimated AI cost in USD
proxima_chat_tool_calls_totalcountertoolTotal MCP tool calls from chat
proxima_chat_tool_duration_secondshistogramtoolTool call duration
proxima_chat_response_duration_secondshistogram—Full chat response duration
proxima_chat_model_routing_totalcountertier, reasonModel routing decisions
proxima_chat_conversations_activeupdowncounter—Active conversations
proxima_chat_errors_totalcountererror_typeChat errors
proxima_chat_credential_source_totalcountersourceAI credential source usage

L1 Incident Agent​

MetricTypeLabelsDescription
proxima_l1_triage_tokens_totalcounter—Tokens consumed by unattended L1 triage runs
proxima_l1_triage_cost_usd_totalcounter—LLM cost in USD for unattended L1 triage runs
proxima_l1_engage_tokens_totalcounter—Tokens consumed by reactive L1 engage (listening-bot) runs
proxima_l1_engage_cost_usd_totalcounter—LLM cost in USD for reactive L1 engage runs
proxima_escalation_steps_totalcounterclient_idEscalation groups advanced one step by the timer worker
proxima_escalation_drift_totalcounter—Shadow-poll on-call drift events

Runbook Execution​

MetricTypeLabelsDescription
proxima_runbook_executions_totalcounterstatusRunbook executions that reached a terminal state
proxima_runbook_dispatched_totalcountertrigger_sourceRunbook executions dispatched to agents
proxima_runbook_executions_timed_out_totalcounter—Executions force-failed by the watchdog for exceeding their timeout
proxima_runbook_watchdog_errors_totalcounter—Watchdog DB errors while sweeping for stale executions

Trace Ingest​

MetricTypeLabelsDescription
proxima_trace_ingest_totalcounterresult (ok/malformed/forward_error)Agent trace batches ingested
proxima_trace_ingest_spans_totalcounter—Agent spans forwarded to Tempo

Agent​

MetricTypeLabelsDescription
proxima_agent_selflogs_ingested_totalcounterresult (ok/error)Agent self-log entries forwarded to the ops VictoriaLogs tenant (account 0)
agent_healthcheck_last_findingsgaugeagent_version, hostnameFindings count from last scan

All metrics follow OpenMetrics naming conventions with the proxima_ prefix for backend metrics and agent_ prefix for agent-side metrics.

note

This reference covers the primary subsystems. The backend registers additional metrics for other subsystems (JSM, OIDC, ClickHouse, email, Kubernetes sync, service desk, tunnel/transport, briefing, and more). The authoritative list is always the /metrics endpoint and the backend/internal/observability/metrics_*.go registration files.