Skip to content

Observability metrics (platform monitoring)

OpenCTI exposes operational metrics using the OpenTelemetry standard, which can be exported to various systems such as Prometheus or OTLP collectors. These metrics provide insights into the platform's performance and health, and are intended for your own monitoring infrastructure.

This is NOT anonymous usage telemetry

This page documents the operational metrics you can scrape to monitor your OpenCTI deployment. If you are looking for information about the anonymous product analytics automatically sent to Filigran, see Reference > Usage telemetry.

Configuration

To enable metrics, you need to configure the telemetry section in your platform configuration. See Configuration for details on how to enable and configure exporters.

Available Metrics

The following metrics are exposed by the OpenCTI API.

Metric Name Type Description Unit
opencti_sent_email Counter Counts the total number of emails sent by the platform. Count
opencti_api_requests Counter Counts the total number of API requests received. Count
opencti_api_errors Counter Counts the total number of API errors encountered. Count
opencti_api_latency Histogram Measures the latency of API query execution. Milliseconds
opencti_api_direct_bulk Gauge Measures the size of bulks for direct ingestion (fast path). Count
opencti_api_side_bulk Gauge Measures the size of bulks for absorption impacts (worker path). Count
opencti_dependency_up Gauge Reports the connectivity state of a platform dependency: 1 when the dependency answers, 0 when it fails. Boolean
opencti_elasticsearch_used_size_bytes Gauge Reports the total ElasticSearch/OpenSearch primary store size, replicas excluded. Bytes
opencti_storage_used_size_bytes Gauge Reports the total size of the objects stored in the S3/MinIO bucket. Bytes
opencti_queue_consumers Gauge Reports the number of active consumers on the push queues, per connector type. Count

Platform Health Metrics

A background monitor refreshes the health metrics periodically, so scraping them never triggers a request to a dependency. The same collected state answers the /health endpoint, which therefore never probes ElasticSearch, S3, RabbitMQ or Redis per request. Configure both refresh intervals with app:health_monitoring:dependency_check_interval and app:health_monitoring:usage_metrics_interval (see Configuration).

Dependency checks run on every node, so each node reports the connectivity it observes itself. Usage metrics are cluster wide instead: collecting them is expensive (full bucket scan, engine stats), so a dedicated manager (platform_usage_metrics_manager, see Configuration) computes the value once per interval and shares it with the rest of the cluster through Redis; every node then just adopts that shared value on its own polling cycle, which keeps every node reporting the same figure.

A usage metric that cannot be collected is not exported, instead of being exported as 0.

The platform reports raw consumer counts per connector type and does not aggregate them into an ingestion capacity value. Consumers of the metric decide how to combine the types that are relevant to them.

Dependency Metrics Attributes

Applies to: opencti_dependency_up

Attribute Description Example
dependency The monitored platform dependency. elasticsearch, storage, rabbitmq, redis

Queue Consumers Metrics Attributes

Applies to: opencti_queue_consumers

Attribute Description Example
connector_type The connector type declared on the push queue. Queues without a declared type are reported as UNKNOWN. EXTERNAL_IMPORT, INTERNAL_ENRICHMENT, INTERNAL_IMPORT_FILE, INTERNAL_EXPORT_FILE

Metric Attributes

Metrics exported by OpenCTI include various attributes (labels) to provide granular context.

API Metrics Attributes

Applies to: opencti_api_requests, opencti_api_errors, opencti_api_latency

Attribute Description Example
operation The GraphQL operation type. query, mutation, subscription
name The name of the GraphQL operation. StixCoreObjectFind, Unspecified
status The outcome of the request. SUCCESS, ERROR
type The error type (only present if status is ERROR). AUTH_REQUIRED, FORBIDDEN_ACCESS
user_agent The client user agent initiating the request. Mozilla/5.0..., OpenCTI-Client

Email Metrics Attributes

Applies to: opencti_sent_email

Attribute Description Example
category The functional category of the email. hub-registration, dissemination, password-reset, notification
identifier The ID of the related entity (e.g., user, trigger, list). uuid-v4-string

Bulk Metrics Attributes

Applies to: opencti_api_direct_bulk, opencti_api_side_bulk

Attribute Description Example
type The context or source of the indexing operation. import, connector

Node.js Runtime Metrics

In addition to the application-specific metrics above, OpenCTI also exposes standard Node.js runtime metrics provided by opentelemetry-node-metrics. These include metrics for:

  • Process: CPU usage, memory usage, uptime, etc.
  • Event Loop: Lag, active handles, etc.
  • GC: Garbage collection duration and counts.
  • Memory: Heap usage, heap limits, etc.

Common examples include: - process_cpu_user_seconds_total - process_cpu_system_seconds_total - process_resident_memory_bytes - nodejs_eventloop_lag_seconds - nodejs_gc_duration_seconds