关于通过SNMP准确获取Fortinet防火墙WAN接口带宽及Grafana监控锯齿图修正的技术咨询
Hey there! Let's break down why your Grafana graph is showing that sawtooth pattern while Fortinet's native dashboard looks smooth, and how to fix it.
First, let's clarify what your OID does
The OID 1.3.6.1.2.1.2.2.1.16.187 corresponds to ifOutOctets—this is a cumulative counter that tracks the total number of bytes sent out through your WAN interface over time. It doesn't show real-time bandwidth on its own, which is probably why your graph looks choppy. Fortinet's dashboard automatically converts this raw counter data into a smooth bandwidth rate, which you need to replicate in Grafana.
Step-by-step fixes to get a smooth bandwidth graph
Calculate the actual bandwidth rate
Grafana (and most monitoring tools) needs to convert the cumulative counter into a per-second rate. Here's how depending on your data source:- If you're using Prometheus: Use the
rate()orirate()function to compute the per-second byte rate. For example:
Therate(ifOutOctets{instance="your_fortinet_ip", ifIndex="187"}[1m]) * 8 / 1000000*8/1000000converts bytes per second to Mbps, which is the standard bandwidth unit.rate()uses a 1-minute window to smooth out short-term fluctuations, whileirate()is more responsive to sudden changes—pick based on your needs. - If you're using InfluxDB: Use the
DERIVATIVE()function to calculate the rate of change of the counter, then convert units:SELECT derivative("ifOutOctets", 1s) * 8 / 1000000 FROM "snmp" WHERE "ifIndex" = '187' AND time > now() - 1h
- If you're using Prometheus: Use the
Adjust your SNMP sampling interval
If your SNMP exporter is pulling data too infrequently (e.g., every 5 minutes), the large jumps between counter values will create sharp sawtooth edges. Aim for a sampling interval of 30 seconds to 1 minute—this balances accuracy and resource usage, matching how Fortinet's dashboard collects data.Add smoothing for a near-identical curve to Fortinet's dashboard
Fortinet's native view likely uses rolling averages to smooth out minor fluctuations. In Grafana, you can replicate this with functions likeavg_over_time()(for Prometheus):avg_over_time(rate(ifOutOctets{instance="your_fortinet_ip", ifIndex="187"}[1m])[5m:1m]) * 8 / 1000000This takes the average of the 1-minute rate over a 5-minute window, softening short-term spikes and giving you that smooth, flat curve you see in Fortinet's interface.
Verify SNMP configuration on your Fortinet firewall
Double-check that SNMP is enabled for the WAN interface, and that the SNMP community/credentials you're using have permission to read interface statistics. Sometimes restricted SNMP access can lead to incomplete or delayed counter data.
Quick sanity check: If you look at the raw
ifOutOctetsvalues in your monitoring database, you'll see they only go up (they reset when the interface reboots). The sawtooth happens when Grafana plots these cumulative values directly—converting to a rate is the key fix here.
备注:内容来源于stack exchange,提问作者xis10z

