Skip to content

Connection events and uptime ​

Two RIPE Atlas built-in measurements underpin most of the health and outage analysis in Atlas. Both are ingested continuously and kept forever.

Connection events — measurement 7000 ​

Every time a probe connects to or disconnects from RIPE's infrastructure it emits an event. Atlas pulls these every 15 minutes into a permanent archive, one row per event.

Stitched together, connect/disconnect pairs are the ground truth for a probe's uptime — and, aggregated by AS, country or time bucket, for the health of a whole network. When a country "goes dark" or an AS drops off, this is the series that says so.

Late arrivals ​

An event carries both when it happened and when RIPE accepted it, and the second can lag the first by seconds to minutes — occasionally hours during an incident. Rather than trying to track a moving watermark, ingest re-scans a generous overlap window on every pass and relies on each event having a stable identity, so re-importing the same event changes nothing.

The practical consequence: the most recent few minutes of any event-derived view can still fill in. Don't read a sharp drop at the right-hand edge of a chart as an outage until it has had time to settle.

Longer holes — a multi-hour storage delay upstream, or extended downtime on this side — are recovered by an explicit backfill rather than automatically.

Uptime — measurement 7001 ​

Every probe reports its uptime roughly every three minutes. Storing that raw would be millions of near-identical samples a day, so Atlas stores change-points instead: a row is written only when something meaningful moves.

Four things count as meaningful:

  • Firmware version changed
  • Source IP changed — the probe was renumbered or re-homed
  • A reboot — the uptime counter went backwards
  • A clock resync — the probe's local time jumped far enough to mean a real re-sync rather than the sub-second drift of a healthy probe

A quiet fleet writes almost nothing. This is why probe history in Atlas reads as a list of events rather than a continuous trace: the flat stretches genuinely contained no news.

Coverage is tracked separately ​

Because a day with no change-points is indistinguishable from a day that was never processed, Atlas records which time windows were scanned independently of what was found. A quiet day reads as fully processed rather than as a gap — which is what the coverage calendars on the archive views are showing you.

Reading uptime from events ​

Uptime for a period is reconstructed by pairing connects with disconnects. Two cases need care:

  • Open intervals. A probe still connected has no closing event; a probe that disconnected and never came back has no reopening one. Both are normal.
  • Missed disconnects. Sometimes a probe goes away without a disconnect event being recorded — it lost power, or the event was lost upstream. Naive uptime then counts the probe as connected for the whole gap, inflating the number. There is a staff view (/statistics/missed-disconnects) dedicated to finding these; see Statistics.

Where it shows up ​

Atlas — built on RIPE Atlas data.