1 [Unit] 2 Description=vnStat network traffic monitor 3 Documentation=man:vnstatd(8) man:vnstat(1) man:vnstat.conf(5) 4 After=network.target 5 StartLimitIntervalSec=20 6 StartLimitBurst=4 7 8 [Service] 9 ExecStart=/usr/sbin/vnstatd -n 10 ExecReload=/bin/kill -HUP $MAINPID 11 Restart=on-failure 12 RestartSec=2 13 14 # Hardening 15 CapabilityBoundingSet= 16 LockPersonality=yes 17 MemoryDenyWriteExecute=yes 18 NoNewPrivileges=yes 19 PrivateDevices=yes 20 PrivateTmp=yes 21 ProtectClock=yes 22 ProtectControlGroups=yes 23 ProtectHome=yes 24 ProtectKernelLogs=yes 25 ProtectKernelModules=yes 26 ProtectKernelTunables=yes 27 ProtectSystem=strict 28 ReadWritePaths=/var/lib 29 RestrictNamespaces=yes 30 RestrictRealtime=yes 31 RestrictSUIDSGID=yes 32 StateDirectory=vnstat 33 34 [Install] 35 WantedBy=multi-user.target 36 Alias=vnstatd.service