[Unit] Description=Collectd After=local-fs.target network.target Requires=local-fs.target network.target [Service] ExecStart=/usr/sbin/collectd EnvironmentFile=-/etc/sysconfig/collectd EnvironmentFile=-/etc/default/collectd ProtectSystem=full ProtectHome=true # drop all capabilities: CapabilityBoundingSet= # use this instead if you use the dns or ping plugin #CapabilityBoundingSet=CAP_NET_RAW # turn this on if you use the iptables next to the dns or ping plugin #CapabilityBoundingSet=CAP_NET_RAW CAP_NET_ADMIN NoNewPrivileges=true # Tell systemd it will receive a notification from collectd over it's control # socket once the daemon is ready. See systemd.service(5) for more details. Type=notify # Restart the collectd daemon after a 10 seconds delay, in case it crashes. Restart=on-failure [Install] WantedBy=multi-user.target