LOGBOOK

HELP

Quiz Entry - updated: 2026.10.01

Every extra exporter opens another port on the host. What problem does that cause, and how can Telegraf help?

Each port must be allowed in the host firewall, which in a corporate setting costs compliance work and turns the firewall into Swiss cheese. Telegraf can scrape local exporters on 127.0.0.1 and re-expose everything through its single port.

Left: three exporters each need a hole in the host firewall; right: exporters listen on 127.0.0.1 and Telegraf re-exposes them through a single port

* Three firewall holes versus one: Telegraf scrapes the local exporters and re-exposes them. *

Prometheus pulls from every exporter over the network, so the MongoDB exporter, the IPMI exporter, the Node Exporter and so on each need an open port, with documentation and discussion for every one.

The Telegraf pattern:

  1. Each exporter listens only on localhost (127.0.0.1), so it is not reachable from outside and no firewall rule is needed.
  2. Telegraf's Prometheus input plug-in scrapes those local exporters and buffers the data.
  3. Prometheus scrapes only Telegraf.

The cost is maintaining Telegraf's config on each host. From a security standpoint it is usually the better choice, because the host firewall keeps a small attack surface. Whatever the approach, every exporter has to be rolled out by automation (Ansible, Chef, Puppet, Salt). Installing one by hand on 250 systems is not realistic.

Go deeper:

From Quiz: ITIA / Monitoring Lab: Prometheus and Grafana | Updated: Oct 01, 2026