DEV Community

Vigilmon
Vigilmon

Posted on

How to Monitor Nginx with Vigilmon (HTTP, SSL, and Process Checks)

How to Monitor Nginx with Vigilmon (HTTP, SSL, and Process Checks)

Nginx powers over 30% of the web — it's the reverse proxy, load balancer, and web server of choice for millions of production deployments. Despite its reputation for stability, Nginx can fail: misconfigured upstreams, certificate expiry, memory exhaustion, or a rogue configuration reload can bring it down silently.

This guide covers how to monitor Nginx with Vigilmon — from basic HTTP checks to SSL certificate monitoring and upstream health validation.


Why Monitor Nginx Specifically?

Nginx sits at the edge of your stack. If Nginx is down:

  • All traffic is blocked — every service behind it becomes unreachable
  • Errors may be invisible — Nginx can return 502/503 without your app logging anything
  • SSL expiry — Nginx terminates TLS; expired certs silently kill HTTPS traffic
  • Config drift — a bad nginx -s reload can silently break routing rules

Step 1: Monitor the HTTP/HTTPS Endpoint

The simplest and most effective check: monitor the public URL that Nginx serves.

  1. Log in to vigilmon.online and click Add Monitor
  2. Set type to HTTP(S)
  3. Enter your URL: https://yourdomain.com
  4. Set check interval: 60 seconds (or 30s on paid plans)
  5. Set alert threshold: notify if HTTP status is not 200, or response time > 3000ms
  6. Configure alert channels (email, Slack, PagerDuty, webhook)

Vigilmon checks from multiple regions — so a single data center outage won't trigger a false alarm.


Step 2: Monitor SSL Certificate Expiry

Nginx terminates SSL/TLS. An expired certificate means all HTTPS traffic returns an untrusted error — users see browser warnings and bounce.

Vigilmon's SSL monitor tracks your certificate and alerts you 14, 7, and 3 days before expiry so you can renew before it's a crisis.

  1. Add a second monitor with type SSL Certificate
  2. Enter domain: yourdomain.com
  3. Set alert threshold: notify if certificate expires in < 14 days

This is especially important if you use Let's Encrypt with auto-renewal via certbot — auto-renewals sometimes fail silently.


Step 3: Enable Nginx Status Module

Nginx has a built-in status endpoint you can expose internally for health checks:

# In your nginx.conf or site config
server {
    listen 127.0.0.1:8080;
    server_name localhost;

    location /nginx_status {
        stub_status on;
        access_log off;
        allow 127.0.0.1;
        deny all;
    }
}
Enter fullscreen mode Exit fullscreen mode

This returns:

Active connections: 42
server accepts handled requests
 1234 1234 5678
Reading: 0 Writing: 5 Waiting: 37
Enter fullscreen mode Exit fullscreen mode

You can expose this securely at an internal health endpoint:

location /health {
    access_log off;
    return 200 'ok';
    add_header Content-Type text/plain;
}
Enter fullscreen mode Exit fullscreen mode

Then monitor https://yourdomain.com/health with Vigilmon for a lightweight liveness check.


Step 4: Monitor Upstream Backend Health

If Nginx is proxying to an upstream app (Node.js, Django, Laravel, etc.), add a monitor for the upstream health endpoint too:

location /api {
    proxy_pass http://backend:3000;
    proxy_connect_timeout 5s;
    proxy_read_timeout 30s;
}
Enter fullscreen mode Exit fullscreen mode

Monitor https://yourdomain.com/api/health — if this returns 502/503, it means Nginx is up but your backend is down. This gives you precise failure attribution.


Step 5: Monitor Nginx Process with a Heartbeat

For critical infrastructure, use a heartbeat monitor to verify Nginx's process health:

Create a cron job that pings Vigilmon every 2 minutes:

# Check if nginx is running, ping heartbeat only if healthy
*/2 * * * * systemctl is-active --quiet nginx && curl -sf https://hb.vigilmon.online/YOUR-HEARTBEAT-ID > /dev/null
Enter fullscreen mode Exit fullscreen mode

If Vigilmon doesn't receive a heartbeat ping within the expected window, it fires an alert — even if the HTTP check is passing (some zombie nginx states can respond to HTTP while the process is wedged).


What to Monitor for Full Nginx Coverage

Monitor Type Target Alert Condition
HTTP(S) https://yourdomain.com Status != 200 or latency > 3s
SSL Certificate yourdomain.com Expires in < 14 days
HTTP(S) https://yourdomain.com/health Status != 200
HTTP(S) https://yourdomain.com/api/health Status != 200
Heartbeat nginx process cron No ping in > 3 minutes

Conclusion

Nginx monitoring is non-negotiable for any production setup. With Vigilmon, you get HTTP, SSL, and heartbeat checks in one dashboard — no self-hosted Prometheus stack required.

Add your first Nginx monitor free at vigilmon.online

Top comments (0)