- Home
- Multi-Cloud Networking
- Customer Edge diagnostics
- Command reference
- Network commands
- chronyc-sources
chronyc-sources
Captured 2026-08-03 from one CE of this deployment.
chronyc-sources
Section titled “chronyc-sources”{"command":["chronyc-sources"]}MS Name/IP address Stratum Poll Reach LastRx Last sample===============================================================================^+ 169.254.0.10 4 9 377 211 -758us[ -705us] +/- 47ms^* 169.254.0.11 3 9 77 200 +324us[ +377us] +/- 27ms^- time4.google.com 1 10 377 97 -4210us[-4210us] +/- 5284usThe MS column is two characters, not one. The first is the mode — ^ for a server —
and the second is the state: * is the source currently selected, + an acceptable
alternative, - one excluded by the selection algorithm, and ? one that is unreachable.
So ^* is the selected server and ^? is an unreachable one; reading only the first
character tells you nothing, because it is ^ on every line here.
Exactly one * is the healthy case, and that holds even when other sources show ?.
Reach is an octal register of the last eight polls, so 377 means all eight succeeded.
Anything lower means at least one of the last eight did not — but that includes a source that
has only recently started answering, whose register is still filling. A run taken while
writing this showed 3 and 37 alongside a 377 on a node that had one source selected
(^*) and whose login banner reported NTP: Synced. Read Reach together with LastRx,
which shows how long ago the source last answered, rather than treating any value below 377
as a fault.
Worth checking early when authentication or TLS is failing for no visible reason: a node whose clock has drifted far enough will reject valid certificates and have its tokens rejected, and the resulting errors rarely mention time.