Andy Smith said:
[iptables counters]
That is in fact how BitFolk is doing it, because of
having to
disregard internal data flows.
I did fall a bit down the rabbit hole on this one and landed up on
"nfacct", which looks nice. You can request and clear counters as a
single atomic request and the userland side can export in various
machine readable forms. Makes the "get it into a backend database" part
very simple.
Cheers,
Alun.