Skip to content

ntpstats.parsers

Readers for the log formats produced by today's NTP implementations.

Supported formats (fmt names):

loopstats ntpd (4.2.8) and NTPsec clock-discipline log: MJD sec offset[s] freq[ppm] jitter[s] wander[ppm] timeconst peerstats ntpd / NTPsec per-peer log: MJD sec addr status offset[s] delay[s] dispersion[s] jitter[s] rawstats ntpd / NTPsec raw packet timestamps: MJD sec src dst T1 T2 T3 T4 ... (NTP-era seconds). Offset and delay are computed here from the four on-wire timestamps. chrony-tracking / chrony-measurements / chrony-statistics / chrony-refclocks chrony's tracking.log, measurements.log, statistics.log and refclocks.log (log tracking measurements statistics refclocks). Signs follow chrony.conf(5): measurements (theta) and refclocks (cooked offset) are already reference - local; tracking and statistics are local - reference and are negated, so every series uses the ntpd convention (see :mod:ntpstats.series). linuxptp ptp4l, phc2sys and ts2phc output (stdout or syslog/journal), per-sample lines (master offset ... s2 freq ... path delay ...) and summary lines (rms ... max ... freq ... delay ...). One series per program/clock. Offsets are ns local - reference in linuxptp and are converted to seconds, reference - local. csv Generic delimited text: time,offset[,more columns] with an optional header. ntpstats monitor writes this format. A single column of offsets is accepted too (then tau0 must be supplied). gsoc2012 The estimators.log files written by the 2012 prototype.

detect_format(lines)

Guess the format of a log from its first lines.

parse_chrony_refclocks(lines, name='refclocks.log')

refclocks.log: Date Time Refid DP L P RawOffset CookedOffset Disp.

Filtered samples (- in the raw column) are skipped; the cooked offset ("positive indicates that the local clock is slow") is used as is.

parse_linuxptp(lines, name='linuxptp')

linuxptp ptp4l/phc2sys/ts2phc messages.

Time base: linuxptp stamps messages with CLOCK_MONOTONIC. If lines also carry an ISO-8601 wall-clock prefix (journalctl -o short-iso-precise) the monotonic stamps are mapped to UTC; otherwise times are monotonic seconds (meta['time_base']).

parse_w32tm(lines, name='w32tm')

w32tm /stripchart /dataonly text, or w32tm /stripchart /rdtsc CSV.

The offset is w32tm's NtpOffset, "computed as per NTP offset computations" (server - local), which is the ntpstats convention. The text form only prints a time of day: the date comes from the "The current time is ..." line when it can be read, and the times are the local wall clock of the Windows host (the time zone is not in the output).

parse_prometheus(lines, name='prometheus', negate=False)

A saved Prometheus query_range JSON response (one series per label set).

Offsets are taken as reference - local (e.g. ntpd-rs ntp_source_offset_seconds, "offset between the upstream source and system time"). Use negate for metrics that report local - reference.

format_descriptions()

Every format (built-in and plugin) with a short description.

all_formats()

Built-in formats plus those of installed parser plugins.

load(source, fmt='auto', tau0=None, name=None)

Load a log file (path, file object or text) and return one :class:TimeSeries per source/peer it contains.

load_one(source, fmt='auto', peer=None, **kw)

Load a single series. For multi-peer logs pick peer (substring match on the address) or, by default, the peer ntpd selected as sys.peer most often, else the one with the most samples.