How to Monitor Nginx with Vigilmon (HTTP, SSL, and Process Checks)
Nginx powers over 30% of the web — it's the reverse proxy, load balancer, and web server of choice for millions of production deployments. Despite its reputation for stability, Nginx can fail: misconfigured upstreams, certificate expiry, memory exhaustion, or a rogue configuration reload can bring it down silently.
This guide covers how to monitor Nginx with Vigilmon — from basic HTTP checks to SSL certificate monitoring and upstream health validation.
Why Monitor Nginx Specifically?
Nginx sits at the edge of your stack. If Nginx is down:
- All traffic is blocked — every service behind it becomes unreachable
- Errors may be invisible — Nginx can return 502/503 without your app logging anything
- SSL expiry — Nginx terminates TLS; expired certs silently kill HTTPS traffic
-
Config drift — a bad
nginx -s reloadcan silently break routing rules
Step 1: Monitor the HTTP/HTTPS Endpoint
The simplest and most effective check: monitor the public URL that Nginx serves.
- Log in to vigilmon.online and click Add Monitor
- Set type to HTTP(S)
- Enter your URL:
https://yourdomain.com - Set check interval: 60 seconds (or 30s on paid plans)
- Set alert threshold: notify if HTTP status is not 200, or response time > 3000ms
- Configure alert channels (email, Slack, PagerDuty, webhook)
Vigilmon checks from multiple regions — so a single data center outage won't trigger a false alarm.
Step 2: Monitor SSL Certificate Expiry
Nginx terminates SSL/TLS. An expired certificate means all HTTPS traffic returns an untrusted error — users see browser warnings and bounce.
Vigilmon's SSL monitor tracks your certificate and alerts you 14, 7, and 3 days before expiry so you can renew before it's a crisis.
- Add a second monitor with type SSL Certificate
- Enter domain:
yourdomain.com - Set alert threshold: notify if certificate expires in < 14 days
This is especially important if you use Let's Encrypt with auto-renewal via certbot — auto-renewals sometimes fail silently.
Step 3: Enable Nginx Status Module
Nginx has a built-in status endpoint you can expose internally for health checks:
# In your nginx.conf or site config
server {
listen 127.0.0.1:8080;
server_name localhost;
location /nginx_status {
stub_status on;
access_log off;
allow 127.0.0.1;
deny all;
}
}
This returns:
Active connections: 42
server accepts handled requests
1234 1234 5678
Reading: 0 Writing: 5 Waiting: 37
You can expose this securely at an internal health endpoint:
location /health {
access_log off;
return 200 'ok';
add_header Content-Type text/plain;
}
Then monitor https://yourdomain.com/health with Vigilmon for a lightweight liveness check.
Step 4: Monitor Upstream Backend Health
If Nginx is proxying to an upstream app (Node.js, Django, Laravel, etc.), add a monitor for the upstream health endpoint too:
location /api {
proxy_pass http://backend:3000;
proxy_connect_timeout 5s;
proxy_read_timeout 30s;
}
Monitor https://yourdomain.com/api/health — if this returns 502/503, it means Nginx is up but your backend is down. This gives you precise failure attribution.
Step 5: Monitor Nginx Process with a Heartbeat
For critical infrastructure, use a heartbeat monitor to verify Nginx's process health:
Create a cron job that pings Vigilmon every 2 minutes:
# Check if nginx is running, ping heartbeat only if healthy
*/2 * * * * systemctl is-active --quiet nginx && curl -sf https://hb.vigilmon.online/YOUR-HEARTBEAT-ID > /dev/null
If Vigilmon doesn't receive a heartbeat ping within the expected window, it fires an alert — even if the HTTP check is passing (some zombie nginx states can respond to HTTP while the process is wedged).
What to Monitor for Full Nginx Coverage
| Monitor Type | Target | Alert Condition |
|---|---|---|
| HTTP(S) | https://yourdomain.com |
Status != 200 or latency > 3s |
| SSL Certificate | yourdomain.com |
Expires in < 14 days |
| HTTP(S) | https://yourdomain.com/health |
Status != 200 |
| HTTP(S) | https://yourdomain.com/api/health |
Status != 200 |
| Heartbeat | nginx process cron | No ping in > 3 minutes |
Conclusion
Nginx monitoring is non-negotiable for any production setup. With Vigilmon, you get HTTP, SSL, and heartbeat checks in one dashboard — no self-hosted Prometheus stack required.
Top comments (0)