Back to articles
Technology Insight

Real-Time VPS Storage Analytics: Deploying ncdu and GoAccess for Automated Disk Monitoring

June 1, 2026

Introduction: The Growing Challenge of VPS Storage Management

In modern cloud infrastructure management, maintaining optimal storage capacity is critical for system stability, database performance, and uninterrupted service delivery. Virtual Private Servers (VPS) frequently encounter unexpected storage bottlenecks driven by runaway application logs, expanding container volumes, and unoptimized database dumps. Traditional monitoring utilities like df and du provide necessary snapshot metrics but lack the granularity and real-time visualization required for rapid troubleshooting.

To bridge this gap, enterprise system administrators are turning to sophisticated, lightweight terminal utilities. This guide outlines a comprehensive framework for implementing a real-time VPS disk capacity analytics system by combining two powerful open-source tools: ncdu (NCurses Disk Usage) and GoAccess. By orchestrating these technologies, you can transform raw filesystem data into dynamic, web-accessible visual analytics directly from your terminal environment.

Understanding the Core Components: ncdu and GoAccess

ncdu: The Granular Disk Analyzer

The NCurses Disk Usage (ncdu) utility is a tactical improvement over the standard Unix du command. Built on the ncurses library, it provides a fast, interactive, TUI (Text User Interface) wrapper for scanning and navigating directory trees. It allows administrators to identify storage hogs within seconds, navigate through subdirectories fluidly, and execute targeted deletions safely.

GoAccess: Real-Time Visual Analytics

While ncdu excels at interactive local exploration, GoAccess is an open-source real-time web log analyzer and interactive viewer. Traditionally used for web server logs (Nginx/Apache), GoAccess possesses a highly adaptable parsing engine. By structuring filesystem alterations, cron outputs, or custom terminal logs into a standardized format, GoAccess can translate raw storage mutations into a streaming HTML dashboard, rendering metrics in real-time with microsecond latency.

Step-by-Step Deployment Architecture

Step 1: Installing Essential Packages

To begin deployment, you must install the latest stable versions of both utilities on your Linux distribution. Update your package manager and execute the installation commands as follows:

Ensure your system repositories are fully updated before proceeding to prevent dependency conflicts with the ncurses and geoIP libraries.

For Debian/Ubuntu-based systems:

sudo apt update && sudo apt install ncdu goaccess -y

For RHEL/Rocky Linux environments:

sudo dnf install epel-release -y
sudo dnf install ncdu goaccess -y

Step 2: Conducting Deep Directory Scans with ncdu

Before automating real-time dashboards, you must establish a baseline filesystem scan using ncdu. To analyze the root directory while preventing the scanner from crossing filesystem boundaries (such as mounted network drives or virtual file systems like /proc), utilize the -x flag:

ncdu -x /

The terminal interface will display a sorted list of directories based on capacity consumption. Use the arrow keys to navigate, i to view detailed node information, and d to delete unnecessary files immediately. To export this snapshot data for chronicled analysis or external parsing, pipe the output into a JSON file:

ncdu -o /var/log/ncdu_snapshot.json /

Step 3: Configuring GoAccess for Storage Log Interpretation

To visualize disk usage patterns over time, we construct a logging pipeline where filesystem modifications are captured and piped into GoAccess. GoAccess requires a defined log format to parse incoming text streams. Edit the global configuration file or specify the format directly via the command line.Create a custom shell script located at /usr/local/bin/disk_tracker.sh that periodically logs directory sizes, or parses changes in specific high-growth volumes like /var/log or /opt:

#!/bin/bash
# Log disk usage changes to a structured format
TIMESTAMP=$(date '+%d/%b/%Y:%H:%M:%S %z')
DISK_USED=$(df / | tail -n 1 | awk '{print $3}')
DISK_AVAIL=$(df / | tail -n 1 | awk '{print $4}')
echo "$TIMESTAMP | Total Used: $DISK_USED KB | Available: $DISK_AVAIL KB" >> /var/log/vps_storage.log

Configure GoAccess to read this custom log format by defining the time-format, date-format, and log-format configurations within your execution string to match the incoming data structure perfectly.

Step 4: Orchestrating the Real-Time Web Dashboard

The true power of this implementation lies in generating a live-updating visual interface. By leveraging GoAccess's real-time WebSocket capabilities, you can stream filesystem event logs directly to an external, secure HTML dashboard.

Execute GoAccess in the background, directing it to output a real-time report accessible via a web server or a secured port:

goaccess /var/log/vps_storage.log -o /var/www/html/disk-analytics.html --log-format='%d/%b/%Y:%H:%M:%S %^ | Total Used: %h KB | Available: %^ KB' --date-format='%d/%b/%Y' --time-format='%H:%M:%S' --real-time-html &

This command establishes a persistent WebSocket server that pushes delta updates to the disk-analytics.html dashboard instantly whenever the vps_storage.log updates.

Securing and Optimizing the Analytics Pipeline

Deploying real-time monitoring tools introduces minor system overhead and security footprints that must be managed properly. Implement the following best practices to guarantee system integrity:

  • Access Control: Do not leave the GoAccess HTML output publicly accessible. Restrict directory access using Nginx basic HTTP authentication or implement firewall rules (via iptables or ufw) to whitelist only authorized corporate IP addresses.
  • Resource Throttling: Running ncdu filesystem scans continuously can degrade I/O performance on spinning disks or shared cloud environments. Restrict comprehensive scans to off-peak hours via cron scheduling.
  • Log Rotation: Prevent the tracking log itself from depleting storage capacity. Configure logrotate for /var/log/vps_storage.log to compress, archive, and purge data older than 30 days.

Conclusion: Proactive Enterprise Infrastructure Management

Integrating ncdu and GoAccess creates a robust, minimalist, and highly effective storage monitoring solution that circumvents the complexity of bloated third-party enterprise suites. By utilizing terminal-native applications, you maximize performance efficiency while gaining real-time operational intelligence over your VPS environments. This setup ensures that storage bottlenecks are identified, analyzed, and mitigated long before they impact client-facing operations.

Real-Time VPS Storage Analytics: Deploying ncdu and GoAccess for Automated Disk Monitoring | DPTCloud