Tag Archives: Zabbix

You Asked, We Delivered: What’s New in Zabbix Cloud

Post Syndicated from Michael Kammer original https://blog.zabbix.com/you-asked-we-delivered-whats-new-in-zabbix-cloud/33608/

We’re always looking for ways to make Zabbix Cloud easier to use, and one of the best sources of inspiration is you – our users.

Your feedback and support requests help us understand where things can be simpler, clearer, or just a little less frustrating. Over the past few releases, we’ve made a number of improvements focused on exactly that – smoother onboarding, easier configuration, and fewer common setup issues.

Here are five recent updates that make it easier to deploy nodes, manage secure access, and get your environment up and running with confidence.

1. The ability to deploy Zabbix proxies directly in the cloud

Distributed monitoring often relies on Zabbix Proxies to collect data from remote locations, reduce server load, and improve scalability. Until now, deploying and maintaining proxies required users to provision and manage their own infrastructure.

Zabbix Cloud now supports cloud-based Zabbix Proxy deployment, allowing users to deploy a proxy in their preferred cloud region with the same ease as deploying a Zabbix Cloud server. Once deployed, the proxy can be connected to either a Zabbix Cloud server or an on-premises Zabbix server, giving users greater flexibility in how they design and scale their monitoring environments.

Key benefits

  • Simplified proxy deployment, making it easy to launch a Zabbix Proxy in just a few clicks without provisioning your own infrastructure.
  • Flexible distributed monitoring, which lets you deploy proxies in the cloud regions that best match your infrastructure and monitoring needs.
  • Hybrid environment support, so that you can connect cloud-based proxies to either Zabbix Cloud servers or on-premise Zabbix servers.
  • A reduced server workload, which allows you to offload data collection and preprocessing tasks from your Zabbix server to cloud-hosted proxies.
  • Easy testing and evaluation, so that you can experiment with distributed monitoring architectures without the overhead of installing, patching, or maintaining proxy infrastructure.

Why it matters

This enhancement makes it easier than ever to build scalable, distributed, and hybrid monitoring environments. Whether you’re extending an existing on-premises deployment, reducing the load on your Zabbix server, or evaluating a proxy-based architecture, cloud-hosted proxies provide a fast and flexible way to expand your monitoring capabilities.

2. A redesigned and improved node creation experience

Creating a new Zabbix Cloud node is now more intuitive than ever, with an updated interface designed to streamline deployment. The redesigned workflow makes key information easier to find, reduces unnecessary steps, and guides users through the essential configuration process.

Key benefits

  • A cleaner, more intuitive interface that reduces visual clutter and makes it easier to understand what needs to be configured, allowing users to focus on essential settings without being overwhelmed by unnecessary complexity.
  • A better onboarding flow designed to guide users step by step, making it easier for both new and experienced users to get a node configured correctly and reducing uncertainty about what to do next.
  • Improved visibility of critical setup information, which helps users avoid missing essential settings, credentials, or connection information and reduces the need to search through different parts of the interface.
  • Multiple usability improvements based on customer feedback (such as the ability to specify a server’s time zone during node creation), which address common pain points and make node creation faster, more straightforward, and less frustrating.

Why it matters

New nodes can be deployed more confidently with fewer interruptions during the initial setup.

3. Simplified access filters management

Managing IP allowlists manually can become time-consuming, especially when working with multiple environments or larger infrastructures. Zabbix Cloud now lets users upload or paste multiple IP addresses or CIDR ranges at once using either JSON or TXT format. Users can configure access for Frontend/API, server, or both components simultaneously

Key benefits:

  • Mass import of IP addresses and CIDR ranges, which saves time by allowing large access lists to be configured without repetitive manual entry.
  • Support for JSON and TXT formats, which makes automated workflows easier to implement and gives administrators more flexibility in how they prepare and exchange access lists.
  • The ability to configure Frontend/API and server access independently or together, which makes access control more granular and better suited to different network architectures and security policies.
  • Faster, more consistent access management, which means that changes can be implemented more quickly while reducing differences between configurations.
  • An increased whitelist capacity of up to 200 IP addresses per entry, making large whitelists easier to maintain for organizations with distributed infrastructure or many trusted networks.
  • Reduced manual work and configuration errors, eliminating opportunities for mistakes such as typos, missing addresses, duplicate entries, or accidentally allowing the wrong network.

Why it matters

Managing secure network access is now significantly faster, making it easier to maintain consistent security policies across multiple Zabbix Cloud environments.

4. Better visibility for credentials and access configuration

Our support team identified two of the most common issues reported by new users:

  • Users couldn’t easily find their initial credentials.
  • Users couldn’t connect because their IP address hadn’t been added to the access whitelist.

The node creation experience has now been redesigned to surface the most important information immediately. During node provisioning, users now see the generated password immediately as well as the Access tab before provisioning is complete.

Once the node is ready, two attention indicators (save your credentials and configure access filters) highlight any required actions. The indicators automatically disappear once both actions have been completed.

Key benefits:

  • Faster onboarding, so that you can immediately see the information you need to access your new node, reducing delays during setup.
  • Reduced setup errors, with important credentials and access configuration now being prominently displayed in order to help users avoid common mistakes that prevent successful connections.
  • An improved user experience, with critical information made available at the right time in the provisioning workflow, eliminating the need to search through different screens.
  • Better security practices that encourage users to capture their credentials and configure access filters immediately, helping to guarantee secure access from the start.

Why it matters

These improvements help users get connected faster while reducing common onboarding mistakes and support requests.

5. A refreshed node card and configuration view

We’ve updated both the node card and node configuration pages to provide a cleaner, more organized experience. The redesigned layout makes important information easier to locate while improving navigation throughout node management.

Key benefits

  • Improved visual organization, making important details such as node status, key properties, and actions easier to distinguish, reducing visual clutter and helping you find what you need faster.
  • Better readability, so that you can quickly identify important settings without having to work through dense or confusing screens.
  • Easier access to configuration settings, which reduces the number of steps needed to find or modify node settings and makes configuration tasks more straightforward.
  • A more consistent user experience across the platform, meaning that it’s not necessary to learn a different interface for each part of the platform – the same navigation, terminology, and design principles carry over.

Why it matters

Managing cloud nodes is now faster and more intuitive, whether you’re administering one deployment or many.

In conclusion

All five of these improvements have one thing in common – they’re designed to make Zabbix Cloud easier to use. From faster access filter management and a smoother node creation experience to cleaner interfaces and cloud-based proxy deployment, we’re focused on removing friction from the things you do every day.

And, as always, your feedback plays a big part in deciding what we improve next. So please keep the feedback coming, because we’re listening!

If you haven’t tried Zabbix Cloud yet and like what you’ve seen here, why not give it a try? Get started with Zabbix Cloud today and see how much easier cloud monitoring can be.

The post You Asked, We Delivered: What’s New in Zabbix Cloud appeared first on Zabbix Blog.

Learn, Connect, and Level Up at Zabbix Summit 2026

Post Syndicated from Michael Kammer original https://blog.zabbix.com/learn-connect-and-level-up-at-zabbix-summit-2026/33415/

Let’s be honest. You could spend another October watching webinars at 1.5x speed while answering Slack messages, pretending you’ll “circle back” to that infrastructure project you’ve been meaning to automate since 2023.

Or you could spend two days in Riga at Zabbix Summit 2026, surrounded by hundreds of people who actually get excited about automation, integrations, observability, and that oddly satisfying moment when every dashboard is perfectly green.

If you do, you’ll be among the first to dive into Zabbix 8.0, discover the latest innovations in Zabbix Cloud, and see where the platform is headed next. The choice seems fairly obvious.

It’s not just another tech conference

Some conferences are basically just an expensive delivery service for company-branded merch. Zabbix Summit 2026 isn’t one of them. On October 8-9, 2026, the global Zabbix community returns to Riga for two days packed with technical talks, real-world case studies, product announcements, workshops, networking, and enough ideas to completely rewrite your observability roadmap (well, we can’t promise you’ll finish rewriting it, but you’ll definitely want to start).

This year’s Summit is especially exciting as it marks the arrival of Zabbix 8.0, our next major release, alongside the continued evolution of Zabbix Cloud. That makes it the best place to discover what’s new, what’s next, and how these innovations can simplify and strengthen your observability strategy.

Whether you’re keeping tabs on a handful of servers, an international enterprise, industrial infrastructure, or something delightfully weird, you’ll leave with practical techniques you can put to work.

Start the week at the Zabbix Open House

Before Zabbix Summit 2026 officially begins on October 7, you can drop by the Zabbix offices, meet the people building and supporting the platform you use every day, and get a glimpse of the team behind the technology. Grab a coffee in the kitchen, swap stories with fellow community members, and test your Zabbix knowledge with a fun quiz that might teach even the most seasoned Zabbix fans a few new facts.

It’s a relaxed way to kick off your Summit experience, put faces to names, and start the week surrounded by the people who make the Zabbix community what it is.

Come for Zabbix 8.0, stay because your notebook is full

Zabbix Summit 2026 features one of the biggest moments in recent Zabbix history – an in-depth look at Zabbix 8.0. You’ll hear directly from Zabbix Founder and CEO Alexei Vladishev about the next evolution of the platform, where observability is heading, what’s new under the hood, and how Zabbix continues to expand with solutions like Zabbix Cloud for organizations looking to deploy and scale faster. And that’s only the beginning.

Across the Main Track, Solutions Track, Dev Track, Community Track, and workshops, you’ll learn from engineers, architects, consultants, and customers who have solved problems you’ll probably encounter sooner or later. After all, why should you spend weeks reinventing solutions when someone else is willing to show you theirs?

Zabbix Marketplace – your shortcut to doing more with Zabbix

One of the best things about being part of the Zabbix ecosystem is that you don’t have to build everything from scratch. Zabbix Marketplace brings together a growing collection of integrations, templates, dashboards, and other ready-to-use resources that can help you extend your observability and get value from Zabbix faster.

Zabbix Summit 2026 is the perfect opportunity to go beyond simply downloading a template. Talk to the people behind integrations and community solutions, discover how others are using them in production, and pick up ideas for adapting them to your own environment. In other words, fewer “I’ll build that someday” projects, and more things you can actually try.

Zabbix in your pocket with the Zabbix Mobile app

Observability doesn’t stop being important just because you’ve stepped away from your desk. The Zabbix Mobile app makes it easier to stay connected to your monitoring environment when you’re on the move, whether you’re grabbing coffee between sessions, heading home after the Summit, or simply trying to avoid being permanently attached to your laptop.

It’s another example of how the Zabbix ecosystem is making monitoring accessible when and where you need it. And yes, that means you can leave the Summit with more than just new ideas – you can also take practical Zabbix capabilities with you wherever you go.

Real stories. Real environments. Real “Wait…you used Zabbix for what?”

The best Summit talks aren’t polished, rehearsed sales pitches. They’re stories from people who built something difficult, broke something important, fixed something impossible, and decided to tell everyone exactly how they did it.

Expect practical sessions covering automation, large-scale deployments, MSP environments, integrations, performance optimization, Zabbix Cloud deployments, and plenty of creative techniques that will have you quietly opening a new browser tab entitled “Things I Should Definitely Try.”

Workshops – because there’s a difference between reading documentation and actually doing the thing

If you’re the kind of person who learns by typing instead of watching, you’ll want to spend some time at the Summit workshops. Bring your laptop, break things, fix them, and ask questions. Leave with new skills instead of just good intentions. Workshops are included for Summit attendees and cover hands-on topics led by Zabbix experts, including new capabilities introduced in Zabbix 8.0.

Networking that doesn’t feel like networking

Nobody likes forced small talk over lukewarm coffee. Fortunately, that’s not really the Zabbix Summit vibe. Some of the best ideas at previous Summits started as conversations over coffee. Others probably started much later in the evening over other beverages.

This year’s three networking events (including the Welcome Event, Main Event, and Closing Event) will give you plenty of opportunities to meet the people whose blog posts you’ve bookmarked, whose templates you’ve borrowed (with gratitude), or whose infrastructure stories make yours seem almost reasonable.

And yes, Zabbix Summit 2026 is in Riga

If you’ve never been to Riga, you’re in for a treat. Historic architecture, fantastic food, a thriving tech scene, walkable streets, and (for one week in October) an unusually high concentration of people discussing triggers, proxies, APIs, template inheritance, and everything new in Zabbix 8.0 with genuine enthusiasm. It’s beautiful, it’s (slightly) nerdy, and it’s exactly where the Zabbix community belongs.

Bring your colleagues (they’ll thank you later)

Observability isn’t a one-person job. Bring your team, compare notes during sessions, divide and conquer the agenda, and return home with enough new ideas to keep everyone busy for months. There’s even a group discount for teams of three or more, making it considerably easier to convince your manager this is “a strategic investment in operational excellence.” Which, to be fair, it is!

See you in October!

Whether this is your first Summit or you’ve already collected enough Summit t-shirts to avoid doing laundry for a week, Zabbix Summit 2026 promises fresh ideas, new technology, inspiring people, a comprehensive look at Zabbix 8.0, and the latest developments in Zabbix Cloud. If you want to see where observability is heading, this is where the conversation starts.

So grab your ticket, book the trip, charge your laptop, and prepare to spend two days with people who understand why a perfectly configured dashboard is a thing of beauty.

Register here, and we’ll see you in Riga!

 

The post Learn, Connect, and Level Up at Zabbix Summit 2026 appeared first on Zabbix Blog.

Achieving 100% Observability with BIND and Zabbix

Post Syndicated from Michael Kammer original https://blog.zabbix.com/achieving-100-observability-with-bind-and-zabbix/33358/

Argentina’s BIND Group is a diversified financial services ecosystem centered around BIND Banco Industrial, offering banking, investment, insurance, leasing, fintech, and digital payment solutions.

With roots dating back to Banco Industrial, the group has expanded into a broad portfolio of businesses designed to serve individuals, companies, and fintech partners through innovative financial products and technology-driven services.

With the help of Zabbix, BIND completely transformed its monitoring model, migrating from a third-party system with only 3,500 metrics and context-free alerts to an operation where 100% of its infrastructure is monitored.

The new environment features team-specific dashboards, automated real-time KPIs, and more than a 90% reduction in manual tasks, with projected cost savings of 93% over the coming years.

The challenge

BIND needed to completely overhaul its monitoring model to support the growth of its digital operations while improving visibility, operational efficiency, and business alignment. The main challenges included:

  • Limited infrastructure coverage: Monitoring was outsourced and limited to only 3,500 metrics, preventing a comprehensive view of the company’s six business lines and its entire technology infrastructure.
  • Context-free alerts: During critical incidents, excessive alerts made it difficult to identify the root cause, delaying response times.
  • A lack of alignment between IT and the business: Management indicators were manually compiled from multiple sources, and the monitoring platform did not reflect the priorities or SLAs specific to each business area.
  • High costs and limited scalability: The proprietary APM solution involved high licensing costs, limited integrations, and made it difficult to expand monitoring to new services.
  • Limited autonomy and expertise: Dependence on an external provider and limited in-house expertise reduced the organization’s ability to evolve its monitoring environment according to business needs.

The solution

The company brought monitoring operations in-house and adopted Zabbix as its central observability platform, with support from Custos Monitoring, a Zabbix Certified Delivery Partner in Uruguay. The transformation was carried out in three phases:

  • Foundation: Monitoring 100% of the infrastructure, migrating to Zabbix, and creating customized dashboards for each team.
  • Business Alignment: Implementing SLAs for each business line, creating unified executive dashboards, automating KPIs, and integrating with the CMDB.
  • Intelligence: Enhancing operations with AI, deploying a context-aware LLM to support operations, implementing intelligent alert routing through Slack, and adopting OpenTelemetry as the organization’s observability standard.

The results

The initiative transformed monitoring into a strategic business platform. Key outcomes include:

  • 100% of the infrastructure monitored.
  • More than a 90% reduction in manual monitoring and reporting tasks.
  • Automated KPIs and real-time information available for both IT and business teams.
  • Customized dashboards for technical teams and a unified executive view across the organization.
  • Stronger alignment between IT and the business, with the goal of reducing MTTR from 30 minutes to less than 5 minutes through the use of AI.
  • A projected 93% reduction in APM costs by migrating to OpenTelemetry integrated with Zabbix.

In conclusion

BIND’s case illustrates a monitoring maturity journey that goes far beyond replacing tools. In a short period, monitoring evolved from an outsourced technical service into a strategic platform that speaks the language of the business. The combination of Zabbix, a specialized partner, and a structured, phased approach made this transformation possible. To learn more about the benefits of Zabbix for maintaining banking and financial services infrastructure, contact us.

About Custos Monitoring

Custos Monitoring is a Uruguayan company and a Zabbix Certified Delivery Partner specializing in monitoring and performance management for technology environments. Its mission is to help organizations operate with greater security, control, and predictability by transforming operational data into valuable insights that protect service continuity, support decision-making, optimize processes, and drive business growth.

 

 

 

 

 

The post Achieving 100% Observability with BIND and Zabbix appeared first on Zabbix Blog.

The Evolution of an SNMP Auto-Discovery Tool

Post Syndicated from Patrik Uytterhoeven original https://blog.zabbix.com/the-evolution-of-an-snmp-auto-discovery-tool/33123/

Buckle up for the story of how we went from drowning in snmpwalk output to building a device-centric path toward Zabbix 7 walk-based templates.

The original problem

Every monitoring engineer knows this moment.

You get a new device on the network – a firewall, a NAS, a UPS, a switch from a vendor you have not standardized yet. You open the Zabbix template list. Nothing matches. You download the vendor MIB bundle. It is enormous. You run snmpwalk. The output is thousands of lines.

And then the real work begins: figuring out what any of it means for monitoring.

Not “what OIDs exist.” That part is usually easy. The hard part is deciding which of those OIDs deserve a place in a production template and which ones will create noise, duplicate data, or a discovery rule that walks itself into a timeout.

That was the problem we set out to solve. Not “discover SNMP.” SNMP already does that generously. We wanted to shorten the path from first walk to a usable Zabbix template , without pretending that automation can replace judgment.

That journey became snmp-scanner: a Node.js tool with a web UI that walks SNMP devices, analyzes OID structure, matches a built-in device knowledge base, and exports Zabbix 7 walk-based templates.

“Starting point — one walk, full visibility.”

The Scan tab: host, SNMP version, walk progress streaming in real time.

First goal: find interesting OIDs

Our first instinct was the obvious one: automate OID discovery with a one-click tool.

If we could programmatically surface “interesting” objects, we would save hours of manual grep through walk files. Early versions of the tool focused on exactly that:

  1. Determine the enterprise number: from sysObjectID
  2. Detect the vendor: from enterprise ID, sysDescr, and catalog metadata
  3. Collect MIB modules: parse vendor .mib files or resolve names via snmptranslate
  4. Select candidates: scalars, table columns, and table roots that looked monitorable

This worked better than expected…at first.

Enterprise detection and vendor matching gave us a foothold. MIB import filled in symbols and labels. Table analysis separated scalars from indexed structures. For the first time, a walk did not feel like a wall of numbers.

But we were solving the wrong headline problem.

Pipeline overview

The real problem was never finding OIDs

Here is what changed the direction of the project:

Finding OIDs is easy. Knowing which ones matter is hard.

A typical enterprise walk on a network or storage device surfaces far more data than any sane monitoring template should contain. Most of it falls into categories that look important until you try to operationalize them:

  • Configuration objects: useful for inventory, rarely for alerting
  • Diagnostic and debug counters: interesting in a lab, noisy in production
  • Counters without operational meaning: they increment, but nobody knows what to do when they change
  • Duplicates: the same concept exposed under multiple OIDs or table shapes
  • Hundreds of tables: many with one row, odd indexing, or no stable discovery key

We learned this the hard way.

Early exports produced templates with hundreds of items. Discovery rules timed out. LLD macros did not line up with index columns. Items had technically correct OIDs and practically useless names.

The tool was good at discovery. It was not yet good at curation.

That distinction became the core design principle: Show the full walk. Curate the selection.

The catalog suggests; the engineer decides. Nothing is hidden. But not everything is auto-selected.

Adding the context

Once we accepted that OID discovery was only step one, the tool had to answer harder questions about each candidate we scanned:

Question Why it matters
Is this a metric? Suitable for graphs and trends
Is this a status? Better as a trigger or valuemap
Is this a table? Candidate for LLD
Can this become walk-based LLD? Zabbix 7 pattern: one master walk, dependent discovery
Does it have trigger potential? Or is it inventory-only noise?

This is where snmp-scanner grew beyond a walk viewer.

OID analysis classifies scalars vs tables and samples row data. Table recipes handle known shapes like IF-MIB and ENTITY-MIB where generic parsing fails.

Item policies apply global rules for types, units, and preprocessing. LLD macro logic derives {#SNMPINDEX} and optional display macros from INDEX columns and name/descr fields.

Walk eligibility checks became equally important. A table with 4,000 rows and 12 selected columns is not just “discoverable”, it may be too large to walk safely. The tool now estimates varbind counts and applies caps, with UI feedback on skipped tables before you export.

For Zabbix specifically, we committed early to walk-based discovery. In Zabbix 7, dependent discovery rules fed by a preprocessing chain on a master SNMP walk, rather than multiplying standalone SNMP items for every column.

That choice trades template complexity during authoring for runtime efficiency and consistency,  but only if you select the right tables and columns.

Scalars and LLD tables side by side, with catalog match banner and suggestion badges.

“Full walk visible,  curated selection highlighted.”

Template tab with walk limit banner showing skipped tables and row caps.

 “Discovery is not the same as walk eligibility.”

Learning from existing monitoring systems

Raw MIB files tell you what a vendor defined. They do not tell you what operators monitor.

So we looked elsewhere — not for runtime dependencies, but for domain knowledge.

Zabbix official and community templates became our primary enrichment source. At dev time, we parse template YAML and merge metadata by OID into device bundles: item keys, preprocessing steps, trigger prototypes, valuemaps. Nothing is fetched from Zabbix at scan time, the knowledge is versioned in git and shipped with the tool.

Based on opensource info from other vendors we have build our own OS detection model, a large, battle-tested map of sysObjectID prefixes, sysDescr patterns, and device fingerprints as a hint layer for catalog matching. Think of it as: “Thousands of deployments already classified this shape of device.”

The same principle applies to historical ingest from other monitoring tool profiles: provenance and cross-source agreement matter more than any single vendor tree.

The insight worth stealing is this: Existing monitoring projects are a knowledge base of what humans already decided was worth watching.

MIB import answers “what exists.” Monitoring templates answer “what people actually use.”

Our ingest priority today reflects that:

  1. Zabbix templates → curation + keys + triggers
  2. SNMP walks → evidence a binding works on this device
  3. OID catalog → identity (symbol, label, MIB module)
  4. MIB parse → candidates only!! never auto-recommended alone!!

 Our Knowledge layers

From OIDs to metrics: the bigger redesign

The next bottleneck was semantic, not technical.

The same monitoring meaning : CPU utilization, disk SMART, interface traffic, appeared under different OIDs across vendors, templates, and MIB modules.

We had parallel structures: integration presets, OID catalogs, monitoring profiles, suggestion categories, and OID-keyed scoring. No shared identity for “what this measures.”

So we are migrating now toward a device-centric knowledge model:

  • A metric is the monitoring meaning (cpu_utilization, disk_smart, if_in_octets).
  • A binding is how that metric appears on a specific product.
  • OID identity stays global and device files reference it.

Scoring is deliberately split into three layers:

Layer Question Stored in git?
monitoring_value How important is this metric? Yes
binding_confidence Does this binding work on this device? No — scan evidence
effective_score What to highlight or auto-select now? No — runtime only

Device match score and metric rank must never be merged. Picking the right Cisco switch model is a different problem from ranking which metrics belong in the template.

We also consolidated roughly 830 legacy integration presets into enterprise-scoped device bundles. Native curated bundles where possible, consolidated drafts where not. While keeping backward compatibility through a virtual adapter layer.

Feature → Metric panel with monitoring value, tier, and effective score.

 “The unit of curation is the metric, not the OID.”

Lessons learned

These are the lessons we wish we had written on the wall on day one.

Lesson 1: Most SNMP data is not useful monitoring data

A complete walk is a complete inventory of what the agent exposes. A good template is a subset chosen for operability. Confusing the two is how you get 500-item templates that nobody maintains.

Lesson 2: Device classification matters more than OID discovery

Knowing that you are on a QNAP QTS 5 box, a Cisco IOS-XE switch, or a NetApp FAS filer narrows the candidate set more than any generic “interesting OID” heuristic. Match rules on sysObjectID, sysDescr, and enterprise ID outperform symbol pattern matching alone.

Lesson 3: Tables are often more valuable than scalar objects

Scalars give you hostname and uptime. Tables give you interfaces, disks, sensors, fans, and power supplies, the structures that LLD was invented for. Table root detection, index handling, and walk recipes deserved more engineering time than scalar picking.

Lesson 4: Generating everything creates unusable templates

Our first “success” metric was item count. Our useful metric is maintainable item count. We now enforce a template safe auto-select policy: hard caps on auto-selected items, MIB drafts never auto-selected, and progressive learning only after repeated user selection.

Lesson 5: Good filtering is more important than good discovery

Discovery tells you what is there. Filtering tells you what belongs in production. Global deny lists, device-class suggestions, monitoring value tiers, and walk size limits are not afterthoughts, they are the product.

Lesson 6: Existing monitoring projects contain valuable domain knowledge

MIBs are necessary. Templates are opinionated. The combination is template wisdom plus walk evidence plus MIB identity, …. this beats any single source.

What our snmp-scanner does today

If you want the concrete picture, here is the current workflow:

  1. Scan the device (SNMPv2c/v3) or import an existing walk file
  2. Analyze OID structure — scalars, tables, row samples
  3. Match a device bundle from the catalog (~830 device lines, consolidating toward native bundles)
  4. Pre-select metrics via three layers: universal defaults, device preset, heuristic suggestions
  5. Edit the discovery profile in the UI — toggle selection, adjust macros, review walk limits
  6. Export a Zabbix 7 YAML template and import it via the API

 

Key properties:

  • Full walk, curated selection: nothing is hidden
  • JSON knowledge in git: no runtime database, no live fetch from external repos
  • Walk-based LLD: for Zabbix 7
  • MIB import: for OID identity; MIB-to-device drafts for candidate bundles (curator-reviewed before promotion)
  • Metric-keyed learning: repeated user selections influence runtime ranking, not git, until a maintainer promotes them
  • Regression fixtures: pipeline changes tested against anonymized walks (NetApp, Palo Alto, Cisco, and others) without live SNMP

The tool serves two audiences at once: engineers who need to explore and debug a walk, and engineers who need to ship a template faster on a known device class.

Generated Zabbix template preview + successful API import.

“From walk to imported template in one session.”

Where we are today

We are past the “find OIDs” phase and deep into the “govern automation” phase.

Recent work focuses on controlled auto-selection: first scan respects only git-curated default_selected bindings; repeat scans can soft auto-select when community learning and effective score cross thresholds,  always within template-safe caps. MIB-derived drafts stay in candidate scope until a human promotes them.

The catalog is mid-migration: legacy integration JSON is being retired in favor of canonical devices/*.json bundles, with synthesis for backward compatibility. OID catalog data is sharded for scale. OS detection and Zabbix enrichment sit alongside native bundles for vendors we have walked and curated end to end  like  Cisco, QNAP, NetApp, Palo Alto, Eaton, F5, and others.

We are honest about what automation does not do: it does not replace template design judgment. It compresses the tedious middle — walk parsing, naming, table detection, preset matching, and first-draft item structure.

What’s next

The roadmap follows the same principle: more intelligence, more guardrails.

Better trigger generation: Merge more trigger prototype semantics from Zabbix source templates; improve scalar and table-level trigger exports beyond uptime-style defaults.

Smarter metric classification: Expand the metric registry and feature taxonomy (cpu, memory, disk_health, interface, psu, …). Derive tiers from monitoring_value instead of parallel scoring systems. Formalize binding lifecycle: candidate → known_good → recommended → blocked.

AI-assisted monitoring recommendations: The idea is that it can serve likely as a ranking and review accelerator, not as an autonomous template author. The hard constraints, walk size, trigger sanity, device class, duplicate detection, are structural. AI can help classify ambiguous symbols or propose metric mappings for curator review; it should not bypass the evidence ladder from walk → template → recommended.

Operational polish: Per-table-type walk limits (interfaces vs routing vs ARP), SNMP trap / notification support, and a clearer “promote this scan selection to catalog” path in the UI.

Closing thought

SNMP auto-discovery sounds like a search problem. In practice, it is a curation problem wrapped in a classification problem, wrapped in a template ergonomics problem.

We started by trying to find interesting OIDs. We stayed useful when we admitted that interesting ≠ monitorable, and built a system that respects both the completeness of the walk and the discipline of the template.

If you are staring at a fresh snmpwalk output and a missing Zabbix template, you are not failing at SNMP. You are at the exact step where domain knowledge matters most.

SNMP auto-discovery is not a discovery problem. It is a curation problem built on top of classification and domain knowledge.

This is where our tool helps us, with the walk visible, the candidates ranked, and the path to a Zabbix 7 template shorter than an afternoon of manual OID archaeology.

If you need assistance with the migration or want to ensure best practices for scaling and optimizing Zabbix, don’t hesitate to reach out to OICTS. We are a Zabbix Premium Partner operating globally, with offices in the USAUKthe Netherlands, and Belgium, and we’re ready to help you every step of the way.

The post The Evolution of an SNMP Auto-Discovery Tool appeared first on Zabbix Blog.

Discover More with Zabbix Marketplace

Post Syndicated from Michael Kammer original https://blog.zabbix.com/discover-more-with-zabbix-marketplace/33191/

What if extending Zabbix was as easy as browsing an app store? Zabbix Marketplace is a new, centralized hub built to help users quickly discover integrations, extensions, templates, and observability solutions.

Zabbix users will soon be able to access a growing catalog of ready-to-use solutions created by the global Zabbix community and our official technology partners, accelerating deployment and simplifying complex monitoring challenges.

At the same time, Marketplace will help solution creators reach a wider audience by making both commercial subscription-based offerings and free open source solutions easier to publish and promote, while giving Zabbix users faster access to tools that solve real operational challenges.

Think of Marketplace as a one-stop shop for integrations, extensions, templates, dashboards, visualization components, automation tools, and incident response enhancements that extend the capabilities of Zabbix across cloud infrastructure, applications, IoT, enterprise environments, and third-party systems. It will focus on several key extension categories, including:

  • Widgets. Custom visualization components and dashboard enhancements will provide new ways to display metrics, alerts, and operational data.
  • UI Modules. Frontend extensions add functionality, simplify workflows, and tailor the Zabbix interface for specific use cases and industries.
  • Webhooks. Ready-to-use integrations for notifications, ticketing systems, messaging platforms, and incident management tools.
  • Plugins and integrations. Extensions that will connect Zabbix with external platforms, cloud services, infrastructure tools, DevOps pipelines, and observability ecosystems.

How will Zabbix Marketplace work?

Our goal is to create a trusted, reliable ecosystem where developers, technology partners, system integrators, and community contributors can publish solutions that help organizations customize and expand their Zabbix environments faster and with less effort.

Designed with a clean and intuitive interface inspired by the familiar Zabbix documentation and frontend experience, Marketplace will be immediately accessible to both experienced users and Zabbix newcomers. Meanwhile, a rich visual browsing experience with screenshots, previews, detailed descriptions, and installation guidance will help users quickly evaluate solutions.

Security, transparency, and usability are also important priorities for Marketplace. We’re working toward a submission and review process that helps us guarantee that extensions will meet quality and compatibility standards while remaining simple for contributors to publish and maintain.

While the exact commercial model is still being finalized, the integrations portfolio will remain as is and we are actively exploring revenue-sharing approaches that support sustainable development, ongoing maintenance, and long-term support for high-quality integrations and extensions.

Stay tuned – more details as well as previews and early announcements are coming soon! And if you’ve already got an idea for a Zabbix-based solution, we’re definitely ready to hear about it. Fill out this form to register your interest and be among the first companies featured on Zabbix Marketplace!

The post Discover More with Zabbix Marketplace appeared first on Zabbix Blog.

Exploring AI Integration in Zabbix with Gemini and WebMCP

Post Syndicated from Cesar Caceres original https://blog.zabbix.com/exploring-ai-integration-in-zabbix-with-gemini-and-webmcp/33050/

When I first started working with Zabbix in banking and telecommunications over a decade ago, the workflow was always the same: something breaks, an alert fires, you open the dashboard, you diagnose, you fix. Every step required a human sitting in front of a screen reading charts and making decisions.

Then AI came along, and I started asking a simple question. What if I could just talk to my infrastructure and get answers? That question led me down a path from Telegram bots to WhatsApp integrations, and then from chatbots with custom modules to a full mobile application on the Google Play Store.

Along the way, I discovered that the real challenge is not connecting AI to Zabbix – it is defining how they should communicate. That is where protocols like MCP and WebMCP come in, and why they matter for anyone working in infrastructure monitoring today.

Phase 1: Just let me ask a question

The first thing I wanted was simple – to ask about my infrastructure in natural language and get a useful answer. Not parse JSON, not read raw metrics, just ask.

My early integrations used Telegram and WhatsApp as the interface. The AI (initially custom modules, later Gemini) would receive a question like “What alerts do I have right now?”, query the Zabbix API, and respond in plain language. It worked, but it was limited – the AI could only answer what I had explicitly programmed it to answer.

Phase 2: MCP gives AI a standard way to talk to Zabbix

The Model Context Protocol (MCP) developed by Anthropic solves a fundamental problem – how do you give an AI model structured access to external tools and data sources without reinventing the wheel every time?

Before MCP, every AI-to-Zabbix integration was custom. You wrote a script, parsed the API response, and formatted it for the model. If you wanted to switch from one AI provider to another, you started over. MCP standardizes this. You build an MCP server once, and any compatible AI client (Claude Desktop, Gemini CLI, or others) can use it.

The Zabbix community has already embraced this. There are now multiple open source MCP servers for Zabbix available on GitHub. You can request things like:

  • “Show me all unacknowledged problems with severity High or above”
  • “Create a maintenance window for host db-01 for 2 hours”
  • “What changed in the last 24 hours?”

Best of all, you can do it all through natural language and through a standardized protocol.

In my own environment, I set up a WebMCP server that connects a FastAPI backend to the Zabbix API, exposing structured endpoints for hosts, alerts, and problems. The server runs 24/7 alongside my Zabbix instance on a dedicated Proxmox node.

With a simple query to the WebMCP server, I can retrieve the full list of monitored hosts, check active problems, view recent alerts with their severity levels, and get a usage summary – all through clean, structured JSON responses that any AI client can consume.

The WebMCP server exposes structured endpoints for health monitoring, usage tracking, and Zabbix data.
A live query to the WebMCP server returning real Zabbix alerts in structured JSON.

Phase 3: WebMCP becomes the interface

Looking ahead, WebMCP is a proposed browser standard (co-created by engineers at Google and Microsoft) that lets websites declare their capabilities as structured tools that AI agents can call directly in the browser.

Think about what this means for Zabbix. Today, the Zabbix frontend is a web application that humans navigate – click on hosts, drill into triggers, check graphs, acknowledge problems. An AI agent trying to use the Zabbix frontend would have to take screenshots, interpret the UI, and guess where to click slow, fragile, and expensive.

With WebMCP, the Zabbix frontend could declare: “Here is a tool called get_active_problems. It needs a severity filter. Call it and I will return structured results.” The AI agent calls the function, gets clean data, and acts on it. No screenshots, no DOM scraping, no guessing.

The key differences from traditional MCP:

  • WebMCP runs inside the browser tab, not on a separate server. No additional infrastructure to deploy.
  • It inherits the user’s existing session the same SSO, the same cookies, the same role-based permissions. No separate auth layer.
  • Tools are contextual on a problems page, the agent sees problem-related tools. On a host configuration page, it sees host tools.

Chrome 146 already ships WebMCP experimentally. Broader stable release in Chrome is expected by the end of 2026.
To explore this concept in practice, I set up a WebMCP server in my environment, connected to my Zabbix instance.

The server exposes Zabbix data through a browser-based interface, allowing agents to query hosts, alerts, and problems directly from the browser tab.

The server itself is monitored by Zabbix, so I can track its resource consumption and ensure it does not impact the rest of the infrastructure closing the loop between the tool and the platform it extends.

A WebMCP demo page displaying live Zabbix alerts fetched through the browser-based backend.
A large selection of dashboard widgets enable Zabbix users to create Windows dashboards for different use cases

Why this matters for mobile monitoring

Today, if you want AI-assisted Zabbix monitoring on your phone, you need a dedicated app that connects to the Zabbix API, handles authentication, processes data, and presents it through an AI layer. That is what I built. It works, but it requires significant development effort.

WebMCP opens a different path. Imagine opening the Zabbix frontend in your mobile browser and having an AI assistant that can interact with it natively – no app required, no separate server, just the browser and the protocol. The assistant inherits your Zabbix session, sees only what your user role permits, and can help you triage incidents, assign tasks, and generate reports all through the same web interface you already use.

We are not there yet. WebMCP is still in early preview, and the Zabbix frontend needs to implement the protocol. But the architectural direction is clear. The web is becoming agent-ready, and monitoring tools will benefit enormously from this shift.

The practical roadmap

If you work with Zabbix and want to start integrating AI today, here is how I see the progression:

  • Right now: Use MCP servers to connect AI assistants to the Zabbix API. The open-source options are mature, support Zabbix 7.x (and experimentally 8.0), and work with multiple AI clients. Start with read-only mode to explore safely.
  • Near term: Build purpose-specific integrations. Whether it is a mobile app, a chatbot, or a custom dashboard, the Zabbix API combined with models like Gemini or Claude can deliver real value AI-generated weekly reports, intelligent alert triage, natural language infrastructure queries.
  • Coming soon: Keep an eye on WebMCP. As it matures and browsers ship stable support, it will become the lowest-friction way to add AI capabilities to any web-based monitoring tool. The sites that become agent-ready first will have a compounding advantage.

Closing thoughts

The infrastructure monitoring world is at an inflection point. We have been watching dashboards and reading alerts for decades. The protocols are now emerging – MCP for backend integrations, WebMCP for browser-native interactions that will let our infrastructure genuinely talk back to us.

If you are still running Zabbix 7.0 or previous, this is the year to migrate. Older versions are losing support, and the newer API capabilities in 7.0+ are what make these AI integrations possible. Zabbix offers certification programs through Zabbix Academy, and their partner network can assist with migrations.

The post Exploring AI Integration in Zabbix with Gemini and WebMCP appeared first on Zabbix Blog.

Upgrading Fedora with Zabbix and Ansible

Post Syndicated from Michael Kammer original https://blog.zabbix.com/upgrading-fedora-with-zabbix-and-ansible/32915/

Fedora is a global open source project and Linux distribution that provides a platform for innovation and collaboration.

Its infrastructure is managed by a dedicated team of professionals and volunteers who maintain a wide array of services, from build systems to collaboration platforms.

The challenge

For many years, Fedora relied on Nagios for its primary monitoring. While reliable for its time, Nagios presented several significant challenges as the infrastructure grew:

  • Technological debt. The system was very old and lacked the modern features required for complex infrastructure.
  • Simplistic alerting. Nagios was limited to basic “OK,” “Warning,” or “Critical” states, offering no nuance or sophisticated levels of severity.
  • A lack of native trend data. Nagios does not store check history or trend data. To obtain historical insights, the team had to run a separate collectd instance and manually add items to it.
  • Configuration drift. Monitoring was managed via a monolithic Ansible role that wrote out text configuration files. Because application definitions and their monitoring were in different places, new nodes or services were sometimes missed in the monitoring setup.
  • Monolithic complexity. The Ansible code used to drive Nagios was extremely dense, utilizing complex loops that made it difficult to read, follow, or debug, and sometimes limited flexibility in rolling out new checks.

The solution

Fedora chose Zabbix as its next-generation monitoring platform due to its open source nature, active maintenance, ability to self-host, and robust feature set that addressed Nagios’s shortcomings. The transition focused on several key technical improvements:

  • Ansible-driven configuration. Fedora leverages the Zabbix Ansible collection to drive the Zabbix API. This ensures that 100% of the infrastructure configuration – including templates, host definitions, and SAML authentication—is managed as code.
  • Decentralized monitoring definitions. Unlike the monolithic Nagios role, application monitoring is now defined directly within the relevant application’s Ansible role. Adding a node to monitoring typically requires only two Ansible tasks: ensuring the template is up-to-date and adding the host to that template.
  • Sophisticated trigger logic. By moving trigger logic from the agent to the server, Zabbix allows Fedora to use historical trend data (e.g., values over the last hour) rather than just the most recent check result.
  • Versatile data collection. Zabbix’s ability to monitor everything from RAID devices and certificates to database queries and network devices out-of-the-box made it a better fit than more HTTP-focused tools.

The results

The migration to Zabbix has transformed Fedora’s operational visibility in the following ways:

  • Unified visibility. The team now has integrated trend data and monitoring in one place, eliminating the need for separate tools like collectd.
  • Improved reliability. Managing monitoring through the Zabbix API and Ansible roles has reduced the risk of “missing” nodes, as monitoring is now part of the application’s definition of done.
  • Infrastructure as code. The ability to rebuild the entire monitoring configuration from Ansible (even without a database backup) provides high resilience and simplifies upgrades.
  • Community alignment. By adopting Zabbix, Fedora has standardized its operations with CentOS (which already uses Zabbix), allowing for shared expertise across teams.

In conclusion

By moving from Nagios to Zabbix, Fedora has successfully retired significant technical debt and implemented a modern, scalable, and fully automated monitoring system. The flexibility of the Zabbix API combined with the power of Ansible has allowed the project to move monitoring from a centralized “black box” to a core component of every application’s deployment.

To learn more about how Zabbix can modernize large-scale open source infrastructures, get in touch with us.

About Fedora

The Fedora Project is an international partnership of open source and free software developers sponsored by Red Hat. This collaboration combines community led creativity with Red Hat’s resource investment to drive innovation of Linux technologies.

The post Upgrading Fedora with Zabbix and Ansible appeared first on Zabbix Blog.

Zabbix and the Docker API, Part 3: Control

Post Syndicated from Janis Eidaks original https://blog.zabbix.com/zabbix-and-the-docker-api-part-3-control/32961/

In this blog post, you will learn how to add a simple container remote control capability to Zabbix in order to start, stop, or restart containers from within the discovered host.

You might be wondering, why spend the effort to create a host for each template? Well, that’s because we define a manual script to control the container from within the Zabbix frontend. That’s neat, right?  And why stop there? We can also implement a trigger action that automatically restarts the container if it crashes for any reason.

Zabbix server configuration changes

First, we will require global script execution in your Zabbix server configuration:

# nano /etc/zabbix/zabbix_server.conf
EnableGlobalScripts=1
# systemctl restart zabbix-server

Script configuration in frontend

We can create a script in the section Alerts > Scripts. In the script, fill out the specified parameters shown below – the scope, type, and command. Then specify to which hosts this command will apply, as well as the user group that will be able to execute this. This script will take advantage of the user macros and built-in macros to fill the required info in the command to make a correct post request.

● Script
▪ Name: Container action
▪ Scope : Manual host action
▪ Type: Script
▪ Execute on: Zabbix server
▪ Commands: curl -sS -X POST https://{$DOCKER.IP}:{$DOCKER.PORT}/containers{HOST.NAME}/{MANUALINPUT} --cert /etc/zabbix/ssl/certs/client-cert.pem --key /etc/zabbix/ssl/keys/client-key.pem --cacert /etc/zabbix/ssl/ca/ca.pem
▪ Description: Manual action to restart,stop,start container
▪ Host group: Selected: Docker
▪ User group: Zabbix administrators 
▪ Req host perm: Write

● Advanced configuration
▪ Enable user input Check
▪ Input prompt Specify action for container {HOST.NAME}:
▪ Input type: Dropdown 
▪ Dropdown options: restart,stop,start
▪ Enable Confirmation: Check
▪ Confirmation text: Confirm to {MANUALINPUT} container: {HOST.NAME}

Fig 1. The script configuration

Manual host script execution

We can go the Menu section Monitoring > Hosts, select the host, and click on it. In the menu, you will have an additional script available for the Docker hosts group Container action. This manual action is also available in some other frontend sections.

Fig 2. The available scripts for manual execution on the host

Once you click on the Container action, you will have several options available. You can start, restart, or stop the container.

Fig 3. Drop-down menu options for the script

You will have a confirmation window asking if this is the right action you want to perform.

Fig 4. Execution Confirmation window
Fig 5. Script output on successful execution.

The status can also be checked in the host’s latest data menu, once the metric is collected (1 minute for the master item). The item Container /zabbix-agent2: Running shows that this container is not running, and another item displays the exit code 0, which means the process stopped normally with no issue whatsoever.

Fig 6. The latest data for the Zabbix agent 2 container

Some items report the status in numerical format, e.g., 0 , 1 , 2, and so on. To make it human-readable, we use value maps, which display the value in a meaningful, human-friendly way. The screenshot below shows the value map for container health status. So, instead of looking at value 3 for container health (which is meaningless for us and will require reading the documentation) we will be shown value healthy (3).

Fig 7. Predefined value mapping on the template

Automating the container crash recovery

What if your container crashes for some reason? Well, you will get a problem event, which you can use to receive notifications about issues with containers. You can also automate the container recovery process. For example, create a trigger action that will restart the container 3 times with an interval of 2 minutes.

If it does not resolve the issue, only then send a message to the admin. There is no reason to repeatedly restart the service until the end of time – if a few attempts did not work, most likely it will require human intervention to solve the issue.

So here are the script parameters for the action operation:

● Script
▪ Name: Restart container
▪ Scope: Action operation
▪ Type: Script
▪ Execute on: Zabbix server
▪ Commands: curl -sS -X POST https://{$DOCKER.IP}:{$DOCKER.PORT}/containers{HOST.NAME}/restart --cert /etc/zabbix/ssl/certs/client-cert.pem --key /etc/zabbix/ssl/keys/client-key.pem --cacert /etc/zabbix/ssl/ca/ca.pem
▪ Description: Restart container
▪ Host group: Selected: Docker
Fig 8. Script action parameters

Now we have to define a trigger action in order to make use of this script and send a notification to admin if that fails.

Let’s create a new trigger action:

● Action tab
▪ Name: Automatic container restart
▪ Type of calc: And (A and B)
▪ condition: Host group equals Docker
▪ condition: Event name contains Container has been stopped with error code
▪ Enabled: Check

● Operations tab
▪ Default operation step duration: 2m

Add operation
▪ Operation: Current host: Check
▪ Steps: 1 -3
Add operation
▪ Operation: Send message
▪ Steps: 4 – 4
▪ Custom message: Check
▪ Subject: Automated restart failed to bring container up: {HOST.NAME}
▪ Message: <b>Host: {HOST.NAME}<br>
           <b>Problem started at {EVENT.TIME} on {EVENT.DATE}<br>
           <b>Operational data: {EVENT.OPDATA}<br>
           <b>Original problem ID: {EVENT.ID}<br>
Fig 9. New action tab
Fig 10. Action operation tab: new Operation step 1-3
Fig 11. Action operation tab: new step 4-4

The action should look like the screenshot below. Save it.

Fig 12. Defined action operations

Testing container crash automatic recovery

I will stop the container with the command docker kill zabbix-agent2. The container has been stopped with an exit code different from 0, so when the item receives the data (in my case, after 1 minute) I get a problem event. The trigger action executes the script Container restart immediately, after 2 minutes, and after 4 minutes if the problem event has not been resolved.

Fig 13. Problem event about stopped container exit code 137

This script successfully restarted the container. The container is running again, and the problem event is resolved.

Fig 14. Resolved event with remote script execution

Let’s see if I am quick enough to kill the west proxy container repeatedly, before the item collects the data with the container running state. Well, I managed to be faster, so now you will see what happens when it “fails” to bring the container back to running state. Here in the Actions, we can see that Zabbix executed the script three times (I also stopped the container 3 times fast enough!) after which the action sent a notification to the admin about a failure to bring the container up with restarts.

Fig 15. Problem event about stopped container exit code 137

I have received the message that the container restart was unable to bring the container to a running state and requires human interaction to fix this.

Fig 16. Problem event notification in email

Summary

Now you know how to plan ahead and make use of the built-in capabilities of Zabbix to solve the issue without human intervention (where possible) and only get notifications when the automatic remediation attempt fails.

 

The post Zabbix and the Docker API, Part 3: Control appeared first on Zabbix Blog.

Zabbix and the Docker API, Part 2: Adapt

Post Syndicated from Janis Eidaks original https://blog.zabbix.com/zabbix-and-the-docker-api-part-2-adapt/32912/

In this blog post, I will show you how to create a template for monitoring your Docker server with only API calls (without the Zabbix agent 2). Instead of creating a template, templated items, LLD rules, and trigger prototypes from scratch, we will adapt them from the existing template “Docker by Zabbix agent 2.”

How does the Zabbix agent 2 do it?

If you are wondering how the Zabbix agent 2 collects the data, you can look into the source code and see the magic behind the scenes: https://github.com/zabbix/zabbix/blob/master/src/go/plugins/docker/metrics.go.

In short, it uses a Unix non-TCP socket, makes the Docker API requests on the host, and returns JSON objects. Hey, we already know how to use it ourselves from the previous blog post, right?

For the Zabbix agent 2 to work with the Docker template, it needs access to the Unix socket, either by adding the user Zabbix to the group: Docker or running the Zabbix-agent2 as root.

Fig 1. The Zabbix agent 2 Docker plugin source code

How we will do it

I can adapt this template, improvise whenever I encounter a non-existing metric, and overcome any technical challenge with effort! For the most part, in the template we have a few Zabbix agent items that collect data in bulk and a lot of dependent items (and dependent item prototypes from the LLD rules).

The path forward is quite straightforward – we will clone the template and replace the Zabbix agent item type with the HTTP agent type item and add additional parameters shown below. I will also add additional user macros on the template, including the Docker server IP address, port, CA, SSL certificate, and key file names so that these can be adjusted on the host level.

Fig 2. The workflow of the template modifications

Cloning the template and changing the item type

First, clone the template “Docker by Zabbix agent 2” and give it a new name: “Docker stats by HTTP.” Next, modify the Templated Zabbix agent type item configuration with the following parameters:

Fig 3. The modification of the templated item configuration

Modify “Docker by HTTP” template items:

● Modify item: Get containers
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/containers/json?all=true     
  ▪ Type of inf: Text
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
● Modify item: Get data_usage
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/system/df
  ▪ Type of inf: Text
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
● Modify item: Get images
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/images/json
  ▪ Type of inf: Text
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
●Modify item: Get info
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/info
  ▪ Type of inf: Text
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
● Modify item: Ping
  ▪ Type HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/_ping
  ▪ Type of inf: Text
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
♯ Preprocessing (additional first step)
  ▪ Boolean to Decimals

We also need to modify the LLD rule configuration. Change item type from Zabbix agent type to HTTP agent type:

Fig 4. The modification of LLD discovery rule: containers discovery
Modify LLD rule: Containers discovery
● Discovery rule
  ▪ Type: HTTP agent
  ▪ Key: docker.containers.discovery[true]
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/containers/json?all=true     
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
  ▪ Update interval: 1h
● LLD macros
  ▪ {#ID}   $.Id
  ▪ {#NAME} $.Names.first()
Modify LLD rule: Images discovery
● Discovery rule
  ▪ Type: Dependent item
  ▪ Master item: item> Get images
● LLD macros
  ▪ {#ID}   $.Id
  ▪ {#NAME} $.RepoTags

After that, we will also make changes in the LLD rule “Containers discovery” by modifying a few existing item prototypes (Zabbix agent type) and adding a new item. Below are the item prototypes that require modification:

● In LLD rule Containers discovery, modify parameters for item prototype: Container {#NAME}: Get info
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/containers{#NAME}/json       
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
● In LLD rule Containers discovery, modify item prototype: Container {#NAME}: Get stats
  ▪ Type: HTTP agent
  ▪ URL: https://{$DOCKER.IP}:{$DOCKER.PORT}/containers{#NAME}/stats?stream=false  
  ▪ SSL verify peer: Checked
  ▪ SSL verify host: Checked
  ▪ SSL certificate file: {$SSL.CERTIFICATE.FILE}
  ▪ SSL key file: {$SSL.KEY.FILE}
  ▪ SSL key password: {$SSL.KEY.PASSWORD}
● In LLD rule Containers discovery, modify parameters for item prototype: Container {#NAME}: CPU percent usage
  ▪ Type: Calculated
  ▪ Formula: last(//docker.container_stats.cpu_usage.total.rate["{#NAME}"])/last(//docker.container_stats.system_cpu_usage.total.rate["{#NAME}"])*last(//docker.container_stats.online_cpus["{#NAME}"])*100
♯ Preprocessing (delete preprocessing step JSONPath)
● In LLD rule Containers discovery, add new item prototype: Container {#NAME}: System CPU total usage per second
  ▪ Name: Container {#NAME}: System CPU total usage per second
  ▪ Type: Dependent item
  ▪ Key: docker.container_stats.system_cpu_usage.total.rate["{#NAME}"]
  ▪ Type of information Numeric (float)
  ▪ Master item    prototype > Container {#NAME}: Get stats

♦ Tags (name:value)        
  ▪ component:cpu
  ▪ container:{#NAME}      

♯ Preprocessing

  ▪ JSONPath       $.cpu_stats.system_cpu_usage
  ▪ Change per second
  ▪ Custom multiplier: 1.0E-9

Cloning the template (again) and making minor modifications

Next, I will clone the template “Docker statistics by HTTP” and give the copy a new name  – “Docker containers by HTTP.” In the template “Docker containers by HTTP,” delete the LLD rule Images discovery; delete templated items; from the LLD rule “Containers discovery” rule, delete all prototype entities (item prototypes), and add a filter in the LLD rule (shown below):

In LLD rule Containers discovery rule, in Filter tab: add additional filter option
Filters [type of calculation: A and B and C]
   ▪ {#ID} matches {HOST.HOST}

I have also created a host group “Docker” where the discovered container hosts will be added. In the template “Docker statistics by HTTP” delete all item prototypes in the LLD rule “Containers discovery.” We will create a Host prototype in the LLD discovery rule “Containers discovery” – the parameters are shown below:

Host prototype in LLD rule: Containers discovery
  ▪ Host name:     {#ID}
  ▪ Visible name:  {#NAME}
  ▪ Templates:     Docker containers by HTTP
Fig 5. Host prototype settings in LLD rule: Containers discovery
Fig 6. The cloned and modified templates

Creating a host and linking the template

Now all that is left is to create a host and link a template: “Docker statistics by HTTP.” Do not forget to add the correct Docker IP address or DNS name in the user macro.

I have created a new host “Docker server,” linked a template, and modified the user macro for the Docker IP address. This host will collect Docker overall statistics. After the LLD discovery execution, the container names will be automatically discovered and container hosts will be created with a linked template.

Fig 7. The Discovered container hosts with linked templates

If for some reason you are monitoring multiple Docker instances, you could have the same container names discovered, which will lead to LLD errors, as there can’t be hosts with the same name (container ID) or visible name (container name). Quick solution – for each Docker instance, add a prefix to each container name. Another solution – don’t split the template into two parts, then the items will be discovered under the same host, and you will not have this issue.

The Docker server host shows general information about the Docker server’s overall state and status:

Fig 8. Docker server hosts the latest data

A host will be created automatically for each discovered container and will collect the container-specific performance metrics:

Fig 9. The container: zabbix-agent2 latest data

Summary

Now you and I know a little bit more about how Zabbix agent2 is collecting Docker metrics. This blog post has shown you how to improvise and adapt existing templates with different data collection methods. Zabbix is a very versatile tool that you can use in multiple ways to get the data if you have some technical constraints. The included template can also be used as is, or you can modify it to suit your needs.

The post Zabbix and the Docker API, Part 2: Adapt appeared first on Zabbix Blog.

Optimized Monitoring for Hybrid Environments with ICT Solutions

Post Syndicated from Michael Kammer original https://blog.zabbix.com/optimized-monitoring-for-hybrid-environments-with-ict-solutions/32839/

ICT Solutions is a managed service provider (MSP) specializing in fully managed IT Support, cloud, cybersecurity and more. Based in Liverpool, they offer IT support across the UK.

They work together with Zabbix Premium Delivery Partner Opensource ICT Solutions to make sure that their customers get solid insights into their environments.

The challenge

While a lot of companies realize the potential of hybrid environments as opposed to full-cloud environments, on-premise equipment (including local network and server equipment) is still a big part of what they do. It’s relatively easy to monitor cloud equipment with Zabbix proxies in the cloud, but not every customer has what it takes to run a Zabbix proxy on site.

ICT Solutions offers fully managed hybrid environments that include monitoring, so their customers have never had to worry about Zabbix proxies. As such, ICT Solutions has been running Raspberry PI 3 devices for years. Environments grow, however, and managing tens or hundreds of Zabbix proxies is something that can take time when not properly set up.

As an MSP, ICT Solutions looks after approximately 160 clients, 3,000 workstations and 1,300 network devices. These include firewalls, switches, access points, on-premise and hosted servers, network attached storage, CCTV, and door access – just to name a few. They have clients that they fully support, and clients that use them as an extension of their own IT teams.

The company also has a wide variety of templates and scripts set up in Zabbix, along with many dashboards so that when issues arise, they can see straight away where an issue exists or provide a more targeted fault-finding process. They also provide their clients’ IT departments with access to their Zabbix environment so they can visually display this on screens for purposes of working together.

The solution

With Zabbix environments growing over the years, Ansible was deployed and Semaphore was harnessed to keep things simple and manageable. This makes proxy management a breeze, as all the ICT team needs to do to deploy a proxy is have a field engineer install it and then push a button to install all the required software, which leads to the proxy being fully secured and automated into Zabbix.

Unfortunately, proxy performance was dropping over time. As monitoring needs got more extensive, the Raspberry PI 3 was showing its age, which led to Raspberry PI 5 devices being ordered and installed.

Another problem often attributed to Raspberry PI devices is their reliance on SD cards. SD cards are prone to failure when overloaded, which can become a problem as Zabbix stores its proxy database on the SD card.

Fortunately, Zabbix 7.0 introduced the “ProxyBufferMode=hybrid”, which allowed the ICT Solutions team to use the RAM of the Raspberry PIs instead of SD cards for the database. They now write the history metrics to the database on the SD card only in the case of a longer outage.

The results

The end result is a manageable and highly scalable setup that provides ICT Solutions and their customers with valuable insights into their hybrid environments as well as improved flexibility and enhanced security.

The post Optimized Monitoring for Hybrid Environments with ICT Solutions appeared first on Zabbix Blog.

Staying Secure: An Inside Look at Zabbix Security Advisories

Post Syndicated from Michael Kammer original https://blog.zabbix.com/staying-secure-an-inside-look-at-zabbix-security-advisories/32831/

Security has always been a core priority for us at Zabbix. As part of our ongoing commitment to delivering a reliable and secure monitoring platform, we regularly publish security advisories that reflect both newly discovered vulnerabilities and the improvements we’ve made to address them.

These advisories are not just a list of issues – they are a direct result of continuous internal efforts to analyze, test, and strengthen every aspect of our product.

More than just fixes

Every vulnerability we disclose represents a deeper process behind the scenes. It involves:

  • Careful investigation and validation
  • Improvements to internal tooling and detection methods
  • Reevaluation of development and testing processes
  • Retesting to ensure robustness and prevent regressions

For us, security is not a one-time fix – it’s an ongoing cycle of improvement.

Decoding severity scores

We understand that some of the published severity scores may appear alarming at first glance. It’s important to note that these scores are based on worst-case scenario evaluations. In real-world deployments, the actual risk often depends on system configuration, network exposure, access controls, usage patterns, and more.

For many typical Zabbix installations, the effective risk level may be significantly lower than the maximum theoretical score suggests.

Stay updated – it matters

Keeping your Zabbix installation up to date is one of the most effective ways to maintain a secure environment.
Each update includes not only bug fixes, but also: security enhancements, hardening improvements, and stability and performance updates. By applying updates regularly, you make sure that your systems benefit from the latest protections. In short, staying up to date is a shared responsibility and the best defense.

Open communication

We are aware that security advisories can sometimes lead to external reports that frame vulnerabilities without full context. We want to be clear that:

  • Publishing advisories is a sign of maturity and transparency, not weakness
  • Proactively identifying and fixing issues is a core strength
  • Our goal is not to avoid disclosure, but to handle it responsibly and openly

Security is not about the absence of vulnerabilities. It’s about how quickly and effectively they are identified, addressed, and communicated.

Going forward

We believe that transparency builds trust. If you have any questions about Zabbix security advisories or best practices, we encourage you to reach out to us. Our team is always ready to clarify, assist, and provide guidance. We remain fully committed to improving Zabbix security at every level – from code to processes to communication.

Your trust is important to us, and we will continue to invest in making Zabbix a secure and dependable platform for your infrastructure.

The post Staying Secure: An Inside Look at Zabbix Security Advisories appeared first on Zabbix Blog.

Showcasing Our Potential at Europol Industry and Research Days

Post Syndicated from Michael Kammer original https://blog.zabbix.com/showcasing-our-potential-at-europol-industry-and-research-days/32733/

On February 24-26, Europol, the official law enforcement agency of the European Union. welcomed leading innovators, researchers, and law enforcement representatives to its headquarters in The Hague for the third edition of Europol Industry and Research Days.

This year marked the first time Zabbix met the criteria for event participation, an achievement that allowed us to showcase the benefits of Zabbix for law enforcement. Let’s take a look at the event, explore why Zabbix’s participation was a true milestone, and dive into the solutions Zabbix can provide for this rapidly growing vertical.

Onstage at Europol Industry and Research Days

The three-day event brought together Europol staff, representatives from law enforcement agencies in EU member states and Schengen-associated countries, private sector innovators, and research organizations. In total, 40 companies and eight EU-funded research projects were selected to present leading-edge technical solutions designed to address the evolving needs of European law enforcement.

Participants explored practical tools and emerging technologies via keynote speeches, short pitches, and in-depth live demonstrations. The event also served as a collaborative platform to strengthen the bond between law enforcement and the private sector, making sure that innovation keeps pace with increasingly complex security challenges.

Tops among 120 applicants

Zabbix’s participation in the event marks a significant achievement, as we were chosen from a group of more than 120 applicants to showcase our technology. It’s a strong public endorsement of our expertise and relevance in supporting mission-critical environments.

Our team demonstrated how robust IT infrastructure monitoring with Zabbix can enhance operational resilience, situational awareness, and system reliability — all essential components for modern law enforcement agencies.

A first for Zabbix – and Latvia

Zabbix’s presence at the Industry and Research Days also represents a milestone for Latvia. We are the first Latvian organization ever selected to participate in the event, highlighting both our technical leadership and Latvia’s growing role in the European cybersecurity and IT innovation landscape.

By contributing to discussions and live demonstrations, we reinforced our commitment to supporting secure and resilient digital infrastructures across Europe and highlighted the increasing importance of cross-sector collaboration in safeguarding Europe’s digital and operational environments.

Zabbix for law enforcement

By providing real-time monitoring and visualization of critical IT infrastructure, Zabbix allows law enforcement agencies to maintain full visibility over servers, networks, databases, and applications. At the same time, customizable dashboards and alerts allow operators to quickly identify performance issues, service outages, or abnormal behavior across complex environments.

When it comes to surveillance systems, Zabbix can monitor cameras, video management systems, storage devices, and network connectivity, making sure that surveillance infrastructure remains continuously operational and immediately alerting key personnel when cameras go offline, storage capacity is low, or network latency affects video streams.

Zabbix is also well suited for air-gapped environments, which are common in sensitive law enforcement and security infrastructures. Because it can be deployed entirely on-premise without relying on external cloud services, it enables secure monitoring of isolated networks while still delivering comprehensive metrics, alerts, and reporting.

Thanks to proactive incident detection and mitigation, Zabbix analyzes system metrics and triggers alerts when thresholds are exceeded or anomalies are detected. Automated notifications and integrations with response tools allow IT teams to react quickly and resolve issues before they disrupt operations.

Zabbix also supports compliance efforts (including requirements aligned with frameworks such as NIS2) by providing audit trails, monitoring logs, availability reports, and security-related metrics. These capabilities help agencies demonstrate operational oversight, risk management, and system reliability.

What’s more, APIs and webhooks allow Zabbix to easily integrate with existing law enforcement IT ecosystems, including ticketing systems, incident response platforms, SIEM solutions, and custom internal tools. This makes it a flexible component within a broader operational workflow, helping agencies centralize monitoring, automate responses, and maintain the reliability of mission-critical services.

Conclusion

Our participation in Europol Industry and Research Days marked an important step in expanding our collaboration with the European law enforcement community. By demonstrating how reliable, secure, and flexible infrastructure monitoring can support mission-critical operations, we highlighted the growing role of Zabbix in strengthening digital resilience.

The connections established and ideas exchanged during the event open the door to promising new collaborations, and we look forward to building on this momentum in the near future.

The post Showcasing Our Potential at Europol Industry and Research Days appeared first on Zabbix Blog.

Improving Efficiency with a Zabbix Technical Subscription

Post Syndicated from Michael Kammer original https://blog.zabbix.com/improving-efficiency-with-a-zabbix-technical-subscription/32597/

Affidea, a pan-European provider of diagnostic imaging, community-based polyclinic, and specialist healthcare services, operates in 391 centers across 15 countries. Within its growing network, the company ensures that patients receive appropriate and personalized care from leading medical experts.

The challenge

Affidea faced significant limitations in managing its monitoring environment. The entire system was maintained by a single administrator, which restricted scalability and increased operational risk as the organization continued to grow.

The company was using Zabbix version 5.2, which had reached the end of support and no longer met evolving performance and stability requirements. Therefore, an upgrade and HA implementation were needed to ensure continuity of services for millions of patients across Europe.

With a package-based environment, the goal was to perform a complete migration to a containerized installation, making the infrastructure more modern, stable, and easier to maintain.

Another critical point was team development. Affidea needed to train new professionals in Zabbix and optimize system performance, all without increasing infrastructure costs and maintaining the efficiency and reliability expected from a mission-critical healthcare environment.

The solution

After a detailed assessment conducted jointly by Zabbix and Affidea, the following objectives were defined:

• Upgrade the Zabbix platform version
• Migrate 2 separate Zabbix environments into one
• Migrate the environment from packages to containers
• Implement high availability (HA)
• Train the technical team and end users (up to 48 people)
• Optimize system performance without increasing costs
• Get 24/7 support directly from Zabbix Support Team

During the evaluation, Zabbix identified that all these needs could be met through the Enterprise-level technical subscription, a package that combined all required services while reducing costs by 50% when compared to separate contracts.

The applied services included the upgrade from version 5.2 to 7.0, migration to containers, technical consulting, official training with 48 certified employees, a complete environment review, and 24/7 technical support with emergency response.

The implementation followed four main phases:

1. Joint planning: A detailed upgrade and migration plan was created with Zabbix engineers to ensure a safe and predictable process.

2. Execution: The migration was completed successfully on the first attempt, including the simultaneous upgrade of the PostgreSQL database (version 13 with Timescale). The process also incorporated simplified VRF (Virtual Routing and Forwarding) integration, crucial for multi-network environments.

3. Training: A total of 48 employees were trained and certified, including users and specialists. Junior engineers began performing upgrades and maintenance independently, with remote support from Zabbix experts.

4. Environment review and optimization: A joint analysis identified and resolved critical issues. As a result, the system operated stably and without internal alerts for six consecutive months, proving the effectiveness of the improvements.

The results

Having access to a Zabbix technical subscription delivered measurable improvements in performance, stability, and technical maturity. The migration to containers, version upgrade, and specialized support enhanced efficiency without expanding infrastructure or operational costs. Other benefits included:

• A 116% growth in data processing capacity, from approximately 3,000 to 6,500 new values per second
• An increase from about 3,000 to 4,500 monitored hosts, with no performance degradation
• Six consecutive months without internal alerts after optimization
• Total cost of ownership (TCO) maintained despite a doubling of system capacity
• 48 certified employees, which strengthened team autonomy and expertise
• Successful first-attempt execution of the migration and upgrade process

Conclusion

By utilizing the Enterprise support subscription, which includes upgrades, consulting, environment reviews, and training service, Affidea achieved cost savings of up to 50% when compared to purchasing these services individually.

 

The post Improving Efficiency with a Zabbix Technical Subscription appeared first on Zabbix Blog.

Modernizing Public Service Monitoring with Zabbix and Prodemge

Post Syndicated from Michael Kammer original https://blog.zabbix.com/modernizing-public-service-monitoring-with-zabbix-and-prodemge/32612/

Prodemge is the public IT company responsible for supporting the digital systems and services that drive the Government of Minas Gerais in Brazil. Its operations cover essential areas such as healthcare, education, public safety, finance, and infrastructure, ensuring that public policies reach citizens quickly, securely, and efficiently.

The challenge

Monitoring such a wide variety of IT environments and systems was becoming increasingly complex for Prodemge. The lack of a single source of information and real-time visibility made it difficult for teams to respond quickly to demands for innovation and improvements in digital services. This was an untenable situation, as public service monitoring supports strategic processes such as:

  • Contract tracking and supplier billing
  • Direct capacity monitoring by clients
  • Availability monitoring of telecom operator links
  • Measurement of system downtime integrated with third-party applications

The complexity increased with the adoption of hybrid cloud architecture, integration with government blockchain, relationships with critical service providers, and the role of telecommunications operators that connect the entire state infrastructure.

Given this context, it became necessary to reposition monitoring as a central element of the company’s technology governance, aligning processes, service performance, and institutional strategy.

The solution

The decision to adopt Zabbix for public service monitoring was made in 2023, when the tool was already present in part of the company’s infrastructure. In December of the same year, Target Solutions, a Zabbix Certified Delivery Partner, won the public bid and was contracted to begin the project. The implementation was structured around five main pillars:

Assessment and architecture. Integrations with cloud systems, container environments, legacy networks, and external services all needed to be mapped in order to guarantee security and compliance with public sector regulations.

Installation and configuration. More than 7,000 assets began being monitored, with around 20,000 items collected in real time. A total of 29 dashboards were developed, organized by technical areas, service layers, and criticality.

Internal training. Teams underwent training throughout 2024, focused on daily use of Zabbix, environment administration, and indicator analysis.

Integrations. Zabbix was integrated with data visualization tools, databases via ODBC, authentication systems, LDAP, corporate email, CMDB, service desk manager, the government network portal, service ticketing systems, change management modules, inconsistency detection tools, and internal APIs. Alerts began being sent via email, Telegram, and SMS, ensuring fast and traceable responses.

IT service management. One of the main advancements was IT service monitoring, especially the national identity card (CIN) service. This included:

  • Monitoring the application URL
  • Monitoring hosting servers
  • Integration with Federal Revenue Service and TSE data
  • Blockchain monitoring
  • Supervision of the supplier responsible for data processing

This model was also applied to other critical state services, including public safety and education.

The results

By monitoring more than 7,300 assets and collecting 865,000 items in real time with Zabbix, Prodemge repositioned monitoring as a pillar of IT governance, reducing incidents by 20%, strengthening contractual oversight, and consolidating a management model based on data and operational efficiency.

Currently, Prodemge’s production environment is 100% covered by Zabbix and includes the following:

  • 7,301 monitored hosts
  • 865,000 collected items
  • 159 customized templates

The developed dashboards now directly support both technical and administrative management, providing views such as SLA monitoring for the administrative city complex, government network monitoring with visualization of the consumption of 2,284 links across more than 60 agencies, as well as dashboards dedicated to IT services, control of 635 active SSL certificates, and the data lake environment operated with the Cloudera platform.

As a result, there was an approximate 20% reduction in the number of opened incidents, mainly due to the mitigation of false positives, in addition to significant time savings in incident handling and event visualization by analysts and technicians.

Another concrete example occurred in the digital identity card service, where Zabbix identified connectivity failures in external integrations. After architectural adjustments, availability increased from 34% to 99% within one month.

Conclusion

With greater system integration and consistent data usage, Zabbix’s suitability for public service monitoring has made it a central part of Prodemge’s technical and administrative routine, modernizing infrastructure and ensuring greater system availability for the population.

 

The post Modernizing Public Service Monitoring with Zabbix and Prodemge appeared first on Zabbix Blog.

Monitoring the Stars with Zabbix and VIRAC

Post Syndicated from Michael Kammer original https://blog.zabbix.com/monitoring-the-stars-with-zabbix-and-virac/32578/

The Ventspils International Radio Astronomy Center (VIRAC / VSRC) is a radio astronomy installation belonging to the Latvian Academy of Sciences.

It observes a wide variety of near-Earth and deep-space objects in the radio-wave spectrum, using RT-32 and RT-16 telescopes, which are parabolic antennas with diameters of 32m and 16m as well as a LOFAR phased antenna array.

Among its most notable ongoing projects is the establishment of cooperation with the Swedish Space Corporation (SSC) and participation in the European VLBI Network (EVN), where VIRAC performs joint simultaneous observations with similar stations worldwide.

We spoke with Arturs Orbidans, Head of the Engineering and Technical Operation Group at VIRAC, and Software Engineer Kristaps Blumbergs to find out how Zabbix keeps millions of Euros worth of high-tech equipment up and running.

What are the main tasks, objectives, and problems addressed by monitoring tools at VIRAC?

The main objective of our monitoring is to obtain values from the equipment used in radio-astronomical observations, such as the antenna control system, receivers (including cryogenic ones), a stable frequency source (active hydrogen maser), digitizers, and data recorders.

If any of these values deviate from the defined norm, or if a device reports an error state, engineers are notified via email so the issue can be resolved. In addition, the availability of all servers and computers located in Irbene is monitored and their parameters are tracked.

Why Zabbix? Was there a migration from another tool?

Previously, there was no single monitoring tool that did everything in one place – there were only methods for retrieving the required values or tools intended to monitor a specific server. This meant that extending or expanding the tooling was too complex, if not impossible.

We needed a solution that could monitor values from the required equipment in one place and notify engineers about errors. We chose Zabbix because it was already used in the VSRC High-Performance Computing (HPC) department, and Zabbix itself had been recommended to that department by the ITML department of the Ventspils University of Applied Sciences.

We’d like to ask about some Zabbix infrastructure specifics at VIRAC. How are the following used?

Zabbix proxy. There are plans to introduce a Zabbix proxy to reduce the load on the Zabbix server, as it is currently the only system collecting all data.

High availability. Not implemented at the moment, but we definitely have services where it would be necessary, for example the maser–GPS PPS signal delay reader, which determines the delay between the two signals with microsecond precision. This is important for defining an accurate time reference for observations.

Reports (Scheduled reports). One weekly scheduled report is used, which graphically shows changes over time in important parameters of the active hydrogen maser.

Scripts. None have been created yet, because for now the provided templates and the use of system.run() for obtaining other values are sufficient.

Overview of items (what is collected and how). Most items come from standard Linux/Windows server templates. Custom items very often use system.run(), which executes custom scripts for data collection. In addition, .json files are read and then split into multiple items.

Problem detection (what type of triggers are used and how complex they are). The created triggers are quite basic, since the obtained data is already closely tied to the actual equipment. Therefore, for most triggers associated with the created items, we check to see whether the value is equal to a specific value or whether a numeric value falls within a defined range.

Visualization (widgets and maps). From the built-in widgets, the graph and problems widgets are used. Shortly before the release of Zabbix 7.0, custom Zabbix widgets were developed, one of which is used to navigate Zabbix dashboards. This widget consists of two buttons with links to other dashboards.

The main widget displays the radio telescopes, with additional buttons placed at specific locations that indicate whether there are any problems with equipment in that particular area. For example, the laboratory button is placed on the radio telescope schematic at the location where the laboratory is located. It is shown in green when everything is fine and in red when a problem has occurred with one of the servers in that room.

This widget functions as a custom map, and when one of the buttons is clicked, another widget displays the values associated with the selected location. At the moment, all settings for the created widgets use constant values, so they cannot yet be dynamically applied to other use cases.

The described widgets can be seen in the image shown below, where Telescope Information is the above-mentioned “map,” and the Information Display widget shows the related items/values when one of the available buttons is pressed. Meanwhile, in the top-right corner, all key values are displayed for cases where there is no desire to click on specific buttons.

Is there a specific scheme for user roles or permissions?

There is no special user scheme, because our team is very small. It consists only of an admin user and guest users, who can view the custom widgets and see whether there are any problems.

What are your impressions after working with Zabbix?

So far, we have not encountered any problems and are very satisfied with Zabbix. In fact, Zabbix has saved several important scientific observations!

The post Monitoring the Stars with Zabbix and VIRAC appeared first on Zabbix Blog.

Distributed Monitoring with Zabbix and Entelgy

Post Syndicated from Michael Kammer original https://blog.zabbix.com/distributed-monitoring-with-zabbix-and-entelgy/32566/

Entelgy is an international consulting and technology firm specializing in cybersecurity, digital transformation, and advanced IT operations.

By leveraging tools like Zabbix, Entelgy helps organizations implement scalable and distributed monitoring architectures that ensure reliability, visibility, and performance across complex infrastructures.

The challenge

Since 2018, Entelgy has relied on Zabbix as its primary monitoring tool to provide large multinational clients with full visibility into the health and performance of their services and infrastructure. As both the infrastructure and the management of the monitoring platform itself grew in complexity, the need emerged for a unified, centralized view capable of integrating the monitoring of all customer environments.

These customers span a wide range of industries and represent some of the most prestigious global organizations, covering everything from a leading video streaming platform operating across South America to mining corporations, global financial services providers, major chemical and construction firms, the stock exchange of one of the world’s largest financial centers, and Spain’s largest internet service provider.

To meet this growing challenge, Entelgy turned once again to Zabbix — this time to build a centralized monitoring layer on top of its distributed infrastructure.

The solution

For each client, Entelgy deploys a dedicated Zabbix server with its own database and built-in redundancy to ensure reliability and scalability. When necessary, Zabbix proxies are also installed directly within the client’s infrastructure, securely reporting back to the central server using encrypted communications.

On average, each monitored environment tracks over 50,000 individual metrics, covering everything from service availability to infrastructure performance. When any of these metrics indicates a potential issue, a Zabbix action is automatically triggered to notify the operations team responsible for that specific client environment, ensuring rapid incident resolution.

To maintain full visibility and ensure that every monitoring platform across is operating correctly, Entelgy leverages several key features of Zabbix:

  • Remote monitoring capabilities. All client-side Zabbix servers and proxies report to a centralized Zabbix instance that collects internal monitoring data for the entire infrastructure. Thanks to Zabbix’s prioritization of remote metrics, Entelgy’s operations team can observe the status of all monitoring environments in real time and effectively prioritize their response efforts.
  • Automated alerts and incident management. Every metric is tied to a corresponding trigger and alarm. When a problem is detected, Zabbix not only logs the issue but also automatically creates a support ticket, updates SLA tracking, and sends real-time notifications directly to platform administrators via their smartphones.
  • An open source ecosystem. By relying entirely on open source technologies for internal monitoring, Entelgy can adopt the latest features and improvements from the Zabbix ecosystem as soon as they are released. This allows both clients and operations teams to benefit from continuous innovation and the most up-to-date monitoring capabilities.
  • Secure access and client segmentation. Thanks to the integration of LDAP, SAML, and Zabbix’s native role-based access control (RBAC), Entelgy can easily onboard administrators, operators, and client users while ensuring fast, simple, and secure access to the platform. Data visibility is carefully segmented to separate client views from internal operational dashboards, guaranteeing both security and clarity.
  • Custom branding for client environments. Zabbix’s flexibility also allows for full client-specific branding of each monitoring environment. This has proven to be a key differentiator for Entelgy’s clients, who value maintaining a consistent corporate identity across platforms without compromising any of the capabilities offered by Zabbix.

Zabbix provides Entelgy with a unified, fully open source monitoring solution that covers both client environments and internal systems — enabling faster response times, reduced operational complexity, and full control across distributed infrastructures.

The results

“With Zabbix as a core part of our operations, we have full confidence in the monitoring and control of every client environment — no matter how complex or distributed it may be. This allows us to focus on delivering value to our customers, ensuring stability, visibility, and continuous improvement in their infrastructure operations.” – José García, Zabbix Certified Expert at Entelgy

By leveraging Zabbix for distributed monitoring, Entelgy and its clients have achieved significant operational and strategic benefits, including:

  • Improved reliability and service continuity, enabled by proactive detection of infrastructure issues across multiple client environments, ensuring uninterrupted operations for global companies.
  • Increased operational efficiency, driven by automated alerts, ticket creation, SLA tracking, and real-time mobile notifications, allowing faster incident resolution and improved team coordination.
  • High monitoring granularity, with a one-minute update interval for most collected metrics, enabling near real-time incident detection and resolution.
  • More than 1,000 automated tickets generated monthly, fully integrated with ticketing systems using native Zabbix capabilities combined with Python and Bash scripting, eliminating the need for expensive third-party licenses.
  • A comprehensive backup system for both client devices as well as Zabbix databases and configurations, enabling disaster recovery in just a few minutes.
  • Centralized visibility across all platforms through a unified monitoring layer that aggregates hundreds of thousands of metrics from isolated client environments.
  • Secure and segmented access, enabled by LDAP and SAML integrations and role-based access control, ensuring that clients, administrators, and operators can safely access the platform with clearly defined permissions.
  • Enhanced client experience and branding, with each Zabbix instance customized to reflect the client’s corporate identity, maintaining brand consistency without compromising functionality.
  • Continuous innovation supported by a fully open-source ecosystem, allowing Entelgy to rapidly adopt the latest Zabbix features and improvements as soon as they become available.
  • Proven scalability and flexibility, thanks to the ability of Zabbix to adapt to complex, multi-tenant enterprise environments while maintaining high performance, cost efficiency, and long-term sustainability.

Conclusion

At Entelgy, Zabbix is not just the tool of choice — it’s a single, unified platform used to monitor the infrastructure of every client, as well as internal Entelgy systems. By standardizing on Zabbix across all layers of operation, they have eliminated the need for additional monitoring tools, significantly reducing complexity, operational overhead, and costs.

This unified approach allows Entelgy’s teams to work more efficiently, respond faster to incidents, and continuously improve service quality — all while maintaining full visibility and control over distributed environments. With Zabbix at the core, Entelgy delivers reliable, scalable, and cost-effective monitoring at every level.

Entelgy is transforming how large multinational organizations manage and monitor their critical infrastructure by delivering secure, scalable, and highly customized monitoring solutions. By trusting Zabbix as the foundation of its distributed monitoring strategy, Entelgy ensures early detection of issues, seamless integration across diverse environments, and continuous service improvement — helping clients stay focused on their business while maintaining full operational control.

The post Distributed Monitoring with Zabbix and Entelgy appeared first on Zabbix Blog.

Decoding Zabbix Proxy Traffic for Faster Troubleshooting

Post Syndicated from Kaspars Mednis original https://blog.zabbix.com/decoding-zabbix-proxy-traffic-for-faster-troubleshooting/31898/

Usually, it is enough to simply look at the Zabbix proxy administration page or proxy health metrics to perform basic proxy troubleshooting. However, there are situations when a deeper look is required.

Today, we will examine the Zabbix server ↔ proxy communication and learn how to interpret the internal communication protocol.

Understanding the protocol

Zabbix communication protocol

Zabbix components use TCP for communication, and information is encoded in JSON. How do you distinguish Zabbix communication packets? There are a few main filters you need to apply:

  • Protocol: TCP

  • Port: 10051 or 10050 (depending on whether components are active or passive)

  • Packet: Starts with ZBXD or 5A 42 58 44 in HEX

On older versions, it was simple to capture and read Zabbix packets in plain text. Starting with Zabbix 4.0.0, mandatory traffic compression was implemented. This greatly reduces network traffic – roughly by 10× with negligible CPU overhead, but it also makes the traffic unreadable to humans.

A modern Zabbix communication packet looks like this:

5a425844038200000097000000789c2dcccb0e83201085e15731b33606b90a8fe20ec631256da4056a6c9abe7be965fb7f27e709996e772a151c5c733a1edde2ab871e4ee9db661f423cba1f79ac71a786854a89696bbe7223e5b2326b75e01c199368510b42cf68f2eaf3b453fe8fcdc0063eb68497846770a3d1c25a698cea612be0b43642a9c9b2d71b6c5d2cfd

Not very human-friendly, right? In the following sections we will capture and decompress this communication packet step by step.

Capturing traffic

There are multiple tools available for this purpose, but we will use Wireshark – one of the most popular and widely used packet analysis tools. It provides a nice graphical interface for Windows and Linux, but we will use the command-line version, since most troubleshooting is performed over an SSH session. The system used in this example is CentOS Stream 9, but the commands should work on other Linux distributions with only minor syntax adjustments.

First, install the tool:

dnf install wireshark-cli

This installs the tshark command-line utility. After that, change your working directory to a location where you can write files. In this example, we will use /tmp:

cd /tmp

Next, let’s capture some traffic between the Zabbix server and an active proxy:

tshark -i eth0 -f "host <ZABBIX SERVER IP> and host <ZABBIX PROXY IP> \
and tcp port 10051" -w zabbix_stream.pcap

Explanation of parameters:

  • -i eth0 – listen on interface eth0 (specify a different interface if needed)

  • <ZABBIX SERVER IP> – replace with the Zabbix server IP address

  • <ZABBIX PROXY IP> – replace with the Zabbix proxy IP address

  • tcp port 10051 – capture TCP packets on port 10051 (Zabbix trapper)

  • -w zabbix_stream.pcap – write captured output to a file

Let this run for a couple of minutes to collect some raw traffic data. Press CTRL + C to stop the capture.

Analyzing capture file

Now we have captured a *.pcap file that contains multiple TCP streams. A TCP stream represents a single TCP connection. Since Zabbix proxies do not keep persistent connections and instead open a new connection whenever needed, a Zabbix active proxy typically produces the following streams:

  • Data sender – sends collected values every second (by default)

  • Configuration syncer – downloads configuration updates every 10 seconds (by default)

To view the contents of the *.pcap file, run:

tshark -r zabbix_stream.pcap -q -z conv,tcp

Example output:

TCP Conversations
Filter:<No Filter>
                                   |      <-    ||      ->    ||     Total   |Relative|
                                   |Frames Bytes||Frames Bytes||Frames Bytes |Start   |       
10.10.0.2:57850 <-> 10.20.0.5:10051 5 2,512bytes  6 547bytes    11 3,059bytes 0.0000   
10.10.0.2:57860 <-> 10.20.0.5:10051 5 399bytes    5 516bytes    10 915bytes   0.4700  
10.10.0.2:57864 <-> 10.20.0.5:10051 5 399bytes    5 521bytes    10 920bytes   1.4768  
10.10.0.2:57876 <-> 10.20.0.5:10051 5 399bytes    5 570bytes    10 969bytes   2.4829   
10.10.0.2:57878 <-> 10.20.0.5:10051 5 399bytes    5 522bytes    10 921bytes   3.4882   
10.10.0.2:46628 <-> 10.20.0.5:10051 5 399bytes    5 527bytes    10 926bytes   4.4935   
10.10.0.2:46642 <-> 10.20.0.5:10051 4 333bytes    6 590bytes    10 923bytes   5.4992   
10.10.0.2:46648 <-> 10.20.0.5:10051 5 399bytes    5 478bytes    10 877bytes   6.5047   
10.10.0.2:46662 <-> 10.20.0.5:10051 5 399bytes    5 480bytes    10 879bytes   7.5097
We can print packets in chronological order, including stream numbers:
tshark -r zabbix_stream.pcap -T fields \
-e tcp.stream -e frame.number -e frame.time_relative -e frame.len
Column meaning in example output:
  1. Stream number

  2. Frame number

  3. Relative timestamp from the start of capture

  4. Frame size in bytes

0 1  0.000000000 76
0 2  0.000005109 76
0 3  0.000078403 68
0 4  0.000079579 68
0 5  0.000280946 209
0 6  0.000283835 209
0 7  0.001188322 68
0 8  0.001189912 68
0 9  0.001421210 68
0 10 0.001422856 68
1 11 1.003582601 76
1 12 1.003588266 76
1 13 1.003646494 68
1 14 1.003647585 68
1 15 1.003741654 256
1 16 1.003758183 256
1 17 1.004531106 68
1 18 1.004532827 68
1 19 1.004973531 68
.....

To include the payload (Zabbix communication), add the -e tcp.payload field:

tshark -r zabbix_stream.pcap -T fields \
-e tcp.stream -e frame.number -e frame.time_relative -e frame.len -e tcp.payload

Example (truncated for readability):

0 1  0.000000000 76
0 2  0.000005109 76
0 3  0.000078403 68
0 4  0.000079579 68
0 5  0.000280946 209 5a425844038000000096000000789c2dca4d0e82301040e1ab90591352fb3703477137d3d6483454692518e3dd6dd4edfbde0bd6747fa4526182db9af76717b932f470cedf76649179ef7ec4a1ce5b6a585229735e9a2bf12aa2481c89299032c2ceb21754a44fda609bb7b4fe671cece05a09d71c2e301dd05b4548daf4b014984667b52734f6fd013eac2c96
0 6  0.000283835 209 5a425844038000000096000000789c2dca4d0e82301040e1ab90591352fb3703477137d3d6483454692518e3dd6dd4edfbde0bd6747fa4526182db9af76717b932f470cedf76649179ef7ec4a1ce5b6a585229735e9a2bf12aa2481c89299032c2ceb21754a44fda609bb7b4fe671cece05a09d71c2e301dd05b4548daf4b014984667b52734f6fd013eac2c96
0 7  0.001188322 68
0 8  0.001189912 68
0 9  0.001421210 68
0 10 0.001422856 68
......

Not all frames contain payload — the empty ones represent TCP handshakes and other control packets. We are interested only in frames containing payload, because this is where Zabbix data lives.

Analyzing payload

If you take a closer look, each payload starts with a sequence of 5a 42 58 44 – or “ZBXD” in ASCII. This is the Zabbix packet signature and confirms that we have captured the correct traffic.

Example:

5a42584403af000000f0000000789c658ecb0e823014447f85dc3521853e6edb4fd1b868a1c646b44a0bc110fedd22ec5cce9ce4cc2c30b8f7e862020daf21cc9fa233c94009b7f0eb4ec65a3f173b326df293cb30ba187d78664eac201d5adb2969642b09b58633232c12d95c1b8a9bc9c7148643accf0bf80e34150d2bc127f7d812278cd312da3eb477d0350a4624ca2657cf081a15e74cd588254ca61f5d9ead61bde4e486e30656ace2f06f60bb417154825056af5fed34456b
The full Zabbix header is the first 13 bytes of each packet: 5a 42 58 44 03 af 00 00 00 f0 00 00 00 
  • 5a 42 58 44 – Zabbix packet signature ZBXD

  • 03 – Flags (0x01 Zabbix protocol + 0x02 compression)

  • af 00 00 00 – Data length

  • f0 00 00 00 – Length of uncompressed data

The next header is: 78 9c  which indicates zlib compression. After this comes the compressed JSON data we are interested in. More information can be found within Zabbix documentation here.

Let’s extract only the payload with command:

tshark -r zabbix_stream.pcap -T fields -e tcp.payload -E occurrence=f \
| grep -v '^$'
  • -T fields: output only selected fields

  • -e tcp.payload: get the payload of each TCP frame

  • -E occurrence=f: include all occurrences per frame

  • grep -v ‘^$’: remove empty lines (frames with no payload)

Output example:

5a425844038000000096000000789c2dca4d0e82301040e1ab90591352fb3703477137d3d6483454692518e3dd6dd4edfbde0bd6747fa4526182db9af76717b932f470cedf76649179ef7ec4a1ce5b6a585229735e9a2bf12aa2481c89299032c2ceb21754a44fda609bb7b4fe671cece05a09d71c2e301dd05b4548daf4b014984667b52734f6fd013eac2c96                                                                                5a425844038000000096000000789c2dca4d0e82301040e1ab90591352fb3703477137d3d6483454692518e3dd6dd4edfbde0bd6747fa4526182db9af76717b932f470cedf76649179ef7ec4a1ce5b6a585229735e9a2bf12aa2481c89299032c2ceb21754a44fda609bb7b4fe671cece05a09d71c2e301dd05b4548daf4b014984667b52734f6fd013eac2c96                                                                                5a42584403af000000f0000000789c658ecb0e823014447f85dc3521853e6edb4fd1b868a1c646b44a0bc110fedd22ec5cce9ce4cc2c30b8f7e862020daf21cc9fa233c94009b7f0eb4ec65a3f173b326df293cb30ba187d78664eac201d5adb2969642b09b58633232c12d95c1b8a9bc9c7148643a

Decompressing payload

First, let’s save the payload to a file:

tshark -r zabbix_stream.pcap -T fields -e tcp.payload -E occurrence=f \
| grep -v '^$'  > zabbix_payload.hex

Next, create a python script named decompress.py.

#!/usr/bin/python3
import zlib

hex_file = "zabbix_payload.hex"
ZBXD_HEADER_LEN = 26 # 13 bytes * 2 hex chars per byte

with open(hex_file, "r") as f:
  for line_number, line in enumerate(f, 1):
    line = line.strip()
    if not line:
      continue

    # Remove Zabbix header
    if line.startswith("5a425844"):
      payload_hex = line[ZBXD_HEADER_LEN:]
    else:
      payload_hex = line

    # Convert hex to bytes
    try:
      payload_bytes = bytes.fromhex(payload_hex)
    except ValueError as e:
      print(f"Line {line_number}: Invalid hex, skipping ({e})")
      continue

    # Decompress using zlib
    try:
      decompressed = zlib.decompress(payload_bytes)
    except zlib.error as e:
      print(f"Line {line_number}: Decompression error ({e})")
      continue
  
    print(f"Line {line_number}: {decompressed}")

Make the file executable:

chmod +x decompress.py

Execute the file:

./decompress.py

The script will output decompressed Zabbix traffic:

Line 59: b'{"request":"proxy data","host":"Zabbix proxy active","session":"fbdb545d8250bb4c9b2341cc8ca055f1","history data":[{"id":13,"itemid":50454,"clock":1764172374,"ns":946257883,"value":"[{\\"{#IFNAME}\\":\\"lo\\"},{\\"{#IFNAME}\\":\\"eth0\\"}]"}],"version":"7.4.5","clock":1764172375,"ns":432069960}'
Line 60: b'{"upload":"enabled","response":"success","tasks":[{"type":6,"clock":1764172373,"ttl":3600,"itemid":50454}]}'
Line 61: b'{"request":"proxy data","host":"Zabbix proxy active","session":"fbdb545d8250bb4c9b2341cc8ca055f1","version":"7.4.5","clock":1764172375,"ns":438122213}'
Line 62: b'{"upload":"enabled","response":"success"}'
Line 63: b'{"request":"proxy config","host":"Zabbix proxy active","version":"7.4.5","session":"fbdb545d8250bb4c9b2341cc8ca055f1", "config_revision":18611,"proxy_secrets_provider":0}'
Line 64: b'{"data":{},"config_revision":18613}'

Here every line represents a request from a Zabbix active proxy or Zabbix server response. It is easy to distinguish two communication types:

  • Request proxy data – Proxy sends collected values
  • Request proxy config – Proxy checks its configuration revision and downloads configuration changes if required
Recap

It is required to run only three commands in this setup to read uncompressed communications:

tshark -i eth0 -f "host <ZABBIX SERVER IP> and host <ZABBIX PROXY IP> \
and tcp port 10051" -w zabbix_stream.pcap

tshark -r zabbix_stream.pcap -T fields -e tcp.payload -E occurrence=f \
| grep -v '^$' > zabbix_payload.hex

./decompress.py

A more human-readable format

Can we improve it? Absolutely! Let’s pair requests with their corresponding responses for easier parsing, and then output the data as formatted JSON. First, capture the data:

tshark -i eth0 -f "host <ZABBIX SERVER IP> and host <ZABBIX PROXY IP> \
and tcp port 10051" -w zabbix_stream.pcap

Next, extract the data into a CSV while keeping the stream number:

tshark -r zabbix_stream.pcap -T fields -e tcp.stream -e tcp.payload \
-E occurrence=f -E separator=, -E quote=d, -Y 'tcp.payload && tcp.payload != ""' \
> zabbix_payload.csv

Now, the CSV contains both the stream number and the payload for each packet.

"2","5a42584403aa000000dd000000789c458d410e83201444af62fe9a1814a896a3b4e9e283df9494480bd4688c772f694dba9d37336f8348af37a50c1a9e312c6b35604660700fdfec82c6b8a5fa21b4d9cd5460a2945c980a1fcd60945443df2a6e8cb467d30ad958db5be44a8d4d29bb29531cd15285333a8fc6799757d0d7ed8fdc005a080647c31368ce80620cb14860bf3198291eceae96b52ac7d607fb00dd7427d974ad506531a5f2c3c599ab9ecbfd038a0944ee" "2","5a425844033000000029000000789cab562a2dc8c94f4c51b2524acd4b4cca494d51d2512a4a2d2ec8cf2b4e050a16972627a716172bd502002b010e61" "3","5a42584403db0000003d010000789c658fdd6ac3300c855f25e8da143bb6f2e317196cecc23f0a33f3e2cd76434be9bbcf4d03bbd89584bea3a3a31b64fa3953a9a0e13ba7cbb5f3a61a60f091f6d9abb1365cba2732ae868d1a2c544a486be38bf51615faa9476ead72b3eda512ce4dce70c4453471582be5c538eacc66423436c450afa0df6e7f2878d05232381491400b069473caed08dcdf5ba0506aca47be7dd9efa250e9ebd12257c819b898dc6703e3a0c4d8cbc7682da06735e1340e02196c269e9b3fbc90ed0ae58df2eedfeaf1d378522784ff56e2692545afe6990fc3fd17684060c8" "3","5a425844033000000029000000789cab562a2dc8c94f4c51b2524acd4b4cca494d51d2512a4a2d2ec8cf2b4e050a16972627a716172bd502002b010e61"

Next, let’s create a slightly modified Python script to display the entries per stream. Name it streams.py:

#!/usr/bin/python3

import csv
import zlib
import json

csv_file = "zabbix_payload.csv"
ZBXD_HEADER_LEN = 26 # 13 bytes * 2 hex chars per byte
streams = {}
with open(csv_file, "r") as f:
  reader = csv.reader(f)
  for row_number, row in enumerate(reader, 1):
    if len(row) < 2:
       continue

    stream_id = row[0].strip().strip('"')
    hexdata = row[1].strip().strip('"')

    if not hexdata:
      continue

    # Remove Zabbix header
    if hexdata.startswith("5a425844"):
      hex_payload = hexdata[ZBXD_HEADER_LEN:]
    else:
      hex_payload = hexdata

    # Convert hex to bytes
    try:
      payload_bytes = bytes.fromhex(hex_payload)
    except ValueError as e:
      print(f"[Line {row_number}] Invalid hex: {e}")
      continue

    # Decompress
    try:
      decompressed = zlib.decompress(payload_bytes)
    except zlib.error as e:
      print(f"[Line {row_number}] Decompression error: {e}")
      continue

    # Store in the stream bucket
    streams.setdefault(stream_id, []).append(decompressed)

# ---- OUTPUT SECTION ----

print("\n===== STREAM PAIRS =====\n")

for stream_id, messages in streams.items():
  print(f"=== Stream {stream_id} ===")
  for i, msg in enumerate(messages):
    label = (
      "Request:" if i == 0
      else "Response:" if i == 1
      else f"Extra message #{i+1}:"
    )
    print(label)
    text = msg.decode("utf-8")

    # Try to pretty-print JSON
    try:
      parsed = json.loads(text)
      pretty_json = json.dumps(parsed, indent=4, ensure_ascii=False)
      print(pretty_json)
    except json.JSONDecodeError:
    # fallback: print raw text
      print(text)
    print()

Make the file executable:

chmod +x streams.py

Execute the file:

./streams.py

The script will output decompressed Zabbix traffic in a parsed JSON format:

=== Stream 0 ===
Request:
{
  "request": "proxy data",
  "host": "Zabbix proxy active",
  "session": "fbdb545d8250bb4c9b2341cc8ca055f1",
  "interface availability": [
    {
      "interfaceid": 33,
      "available": 0,
      "error": ""
    }
  ],
  "version": "7.4.5",
  "clock": 1764172350,
  "ns": 303905804
}
Response:
{
  "upload": "enabled",
  "response": "success"
}

=== Stream 1 ===
Request:
.......

You’ll notice that typical communication produces two entries per stream – one request from the Zabbix proxy and one response from the Zabbix server. With this approach, it’s much easier to understand and troubleshoot the communication – all traffic is now grouped into request-response pairs and presented in a clean, formatted way.

Live data

And finally — can we make all of this run live? Absolutely, with a little help from our third Python script. The previous two examples walked through the workflow step by step: capture → extract payload → decompress. Now everything comes together in a single script that handles the entire process for you.

Create a new file named live.py:

#!/usr/bin/python3

import subprocess
import zlib
import json
from datetime import datetime

ZBXD_HEADER_LEN = 26 # 13 bytes * 2 hex chars

# === Configurable parameters ===
SRC_IP = "161.35.217.186"
DST_IP = "134.209.233.72"
TCP_PORT = "10051"
INTERFACE = "eth0"

tshark_cmd = [
  "tshark",
  "-i", INTERFACE,
  "-l",
  "-f", f"host {SRC_IP} and host {DST_IP} and tcp port {TCP_PORT}",
  "-T", "fields",
  "-e", "tcp.stream",
  "-e", "tcp.payload",
  "-E", "separator=,",
  "-E", "quote=d",
  "-E", "occurrence=f",
  "-Y", "tcp.payload && tcp.payload != \"\""
]

proc = subprocess.Popen(
  tshark_cmd,
  stdout=subprocess.PIPE,
  stderr=subprocess.DEVNULL,
  text=True
)

seen_streams = set() # track streams we've already printed

for line in proc.stdout:
  line = line.strip()
  if not line:
    continue

  # Split CSV (stream_number, payload_hex)
  try:
    stream_num, payload_hex = line.split(",", 1)
    payload_hex = payload_hex.strip('"')
  except ValueError:
    continue

  # Only print timestamp once per stream
  if stream_num not in seen_streams:
    timestamp = datetime.now().strftime("%Y-%m-%d %H:%M:%S.%f")[:-3]
    print(f"\n=== [{timestamp}] Stream {stream_num} ===")
    seen_streams.add(stream_num)

  # Remove Zabbix header
  if payload_hex.startswith("5a425844"):
    payload_hex = payload_hex[ZBXD_HEADER_LEN:]

  # Convert hex to bytes
  try:
    payload_bytes = bytes.fromhex(payload_hex)
  except ValueError:
    continue

  # Decompress
  try:
    decompressed = zlib.decompress(payload_bytes)
  except zlib.error:
    continue

  # Pretty print JSON if possible
  try:
    json_obj = json.loads(decompressed)
    pretty = json.dumps(json_obj, indent=2)
    print(pretty)
  except json.JSONDecodeError:
    print(decompressed)

Make the file executable:

chmod +x live.py

Execute the file:

./live.py

And that’s it – your script now watches live proxy traffic and streams the output as JSON. Pretty cool, right?

=== [2025-11-27 16:59:31.593] Stream "0" ===
{
  "request": "proxy data",
  "host": "Zabbix proxy active",
  "session": "fbdb545d8250bb4c9b2341cc8ca055f1",
  "history data": [
    {
      "id": 73726,
      "itemid": 50459,
      "clock": 1764262769,
      "ns": 947018320,
      "value": "0"
    },
    {
      "id": 73727,
      "itemid": 50450,
      "clock": 1764262770,
      "ns": 947145177
    }
  ],
  "version": "7.4.5",
  "clock": 1764262770,
  "ns": 961735298
}
{
  "upload": "enabled",
"  response": "success"
}
.....

Final notes

The example scripts provided here are for demonstration purposes only, tested in a small demo environment. While the same principles apply to larger setups, keep in mind that proxies in production can handle hundreds or even thousands of new values per second (NVPS), which significantly increases the payload volume. Also, all examples assume a Zabbix proxy running in active mode – passive proxies communicate slightly differently. A similar approach can be used to monitor Zabbix Agent communications.

So, what valuable information can you actually gather from Zabbix proxy ⇄ Zabbix Server communication?

  • The types of data sent from proxy to server

  • Configuration updates and their contents

  • Test and Execute Now tasks

  • Discovery and Autoregistration data

If you’re interested in exploring discovery, autoregistration, encryption, or other aspects of Zabbix’s internal communication, feel free to leave a comment!

The post Decoding Zabbix Proxy Traffic for Faster Troubleshooting appeared first on Zabbix Blog.

Zabbix in 2025: A Year of Growth, Community, and Innovation

Post Syndicated from Michael Kammer original https://blog.zabbix.com/zabbix-in-2025-a-year-of-growth-community-and-innovation/32470/

2025 has been a dynamic and crucial year for Zabbix — marked not just by global events and major releases, but also by meaningful community engagement, an important milestone in our history, new ways of sharing expertise, and headcount growth around the world – all while making sure our product evolves to provide even more value for our valued customers and partners. Let’s dig in!

Celebrating 20 years in business

On April 12, Zabbix officially celebrated its 20th anniversary as a company. It was a time for our entire community to step back, take stock, and imagine what the future might bring as our offices threw some amazing birthday parties to celebrate two decades of growing (and monitoring) together!

“I’m very satisfied with the results we’ve achieved as a company and I’m extremely grateful for our community, customers, and partners – they make everything we do possible.” – Alexei Vladishev, Zabbix Founder and CEO

A new path toward Zabbix expertise

In October, we launched Zabbix Academy, an online learning platform that offers a comprehensive library of interactive courses that are designed to help users master every aspect of Zabbix, on their own time and at their own speed.

Zabbix Academy includes everything from an introduction to open-source monitoring to advanced Zabbix security administration. There’s no need for any prior certification or training, and Zabbix Academy offers certifications and skill assessments aligned with Zabbix standards as well as a flexible pricing model that includes both free and paid courses and webinars, plus the ability to choose either a single standalone course or a yearly subscription.

“Our community is our greatest asset, and we believe that continuous learning is essential for long-term success, and Zabbix Academy is proof of that commitment.” – Kristine Lamberte, Head of Training at Zabbix

Nous sommes Zabbix!

In addition to all the other positive news, 2025 will be remembered as the year we announced the acquisition of our long-term partner IZI-IT and the establishment of Zabbix France, a new regional office dedicated to providing localized support and closer collaboration with French users and enterprises.

Headed by IZI-IT Founder and CEO Steve Destivelle, Zabbix France will leverage France’s strong technology ecosystem, skilled workforce, and strategic location to build a new European hub that will enable faster response times, support compliance with regional business and regulatory expectations, and ultimately boost our brand visibility across Europe.

Home sweet home

2025 also happened to be the year in which Zabbix finally outgrew our long-time Riga location. In September, our search for new premises led us to make the move to a larger and more suitable office space. The new office is spacious, flexible, easily accessible by bicycle or public transport, and features a modern infrastructure that can help us continue growing and competing in the global marketplace.

Building a better product

The big news on the product development front was the release of Zabbix 7.4 in July. Zabbix 7.4 introduces a wide variety of new features that users have requested, while delivering significant UI/UX improvements that make monitoring with Zabbix even more accessible and efficient. Looking forward, our teams are also working hard to bring the next generation of Zabbix features to life, with the following projects in the works:

  • Zabbix 8.0 LTS, which will introduce leading-edge technical features as well as a redesigned user interface with enhanced visualizations for a more intuitive and user-friendly experience.
  • Zabbix Mobile, an official Zabbix Mobile App for iOS and Android that will put instant push notifications, incident management, and seamless collaboration at your fingertips.
  • Zabbix Marketplace, a global platform designed to connect users, partners, and vendors in order to help them exchange information and discover new solutions together.

Growing our community

From major conferences to local meetups and knowledge-sharing events, the global Zabbix ecosystem came together like never before in 2025! Everything we do at Zabbix happens with the knowledge that our community is what sets us apart, which is why we’ll always meet our members wherever they happen to be.

Our global events gave monitoring professionals, partners, and enthusiasts a valuable forum to share their real-world expertise, helping our users keep pace with evolving technologies, strengthening their professional networks, and making sure that community feedback continues to shape our offerings. Some of the highlights included:

  • 12 Zabbix Labs across Latin America, designed to foster vocational education and train specialized professionals who are ready for the professional challenges of the future.
  • 1 regional forum in Mexico City that brought together regional experts to discuss trends, share experiences, and explore how open source tools are changing the technology landscape.
  • 5 conferences (Benelux, Germany, China, Japan, and Latin America) that delivered a unique mix of practical knowledge, direct access to experts, and networking opportunities.
  • Innumerable exhibitions, trade fairs, and expos, which boosted our brand and built relationships.
  • One incredible Zabbix Summit in Riga that brought together hundreds of professionals, developers, partners, and users to share insights, learn from expert talks and workshops, and explore real-world case studies on effective Zabbix use.

Meanwhile, 2025 saw our headcount grow in every one of our global offices, as more and more talented individuals got wind of what we’re doing and chose to be a part of it.

Not to be outdone, our partners team also added 16 Resellers and 16 Certified Partners to our roster of global associates, all while revising and updating our Partner Program to bring Zabbix services to new users in more locations and in additional languages.

Staying safe

Security is not a one-time milestone for Zabbix, but a continuous process. In 2025, we focused on making our security practices more proactive, transparent, and deeply embedded into how we build and operate our products and services.

In 2025 we successfully recertified our ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certifications for another 3 year period. At the same time, our HackerOne bug bounty program continued to be a solid line of defense, as 2025 brought 24 valid submissions that netted $16,700 in bounties.

Furthermore, as Latvia’s only CNA, Zabbix continued to refine its CVE workflows with faster triage and publication timelines, as well as improved vulnerability severity assessment and documentation.

Giving back

During the 2025 holiday season, we continued what may be the most important Zabbix tradition at all – lending our support to local organizations that make a real difference in our communities, including those that provided family support, food relief, access to healthcare and rehabilitation services, and simple holiday joy to senior citizens.

Due in large part to efforts like these, in November Zabbix was named “Enterprise of Riga 2025” in the ICT category – a recognition awarded to the most successful and impactful companies in Riga’s priority sectors. The award highlights not only business results but also contributions to innovation, sustainability, employee well-being, and the growth of the local tech ecosystem.

Looking ahead to 2026

In keeping with our new slogan “Your business works – you know it,” the plan for 2026 and beyond is to evolve from a traditional monitoring tool to a full observability platform, as our Founder and CEO laid out in his keynote speech during Zabbix Summit 2025.

We’re also planning to up our game when it comes to community engagement and training, meaning conferences, meetups, trainings, online events, and global expos that take into account feedback from our community and are increasingly tailored to provide members with what they need most.

With that in mind, we’d like to take this opportunity to thank our amazing global community for everything they did to make 2025 such a success. Whether it was in the form of blog contributions translating documentation, or creating templates and widgets, our community showed up in a big way all throughout the year.

It also goes without saying that we couldn’t have made 2025 the year that it was without our customers, whose trust, collaboration, and commitment to excellence continued to inspire us, drive innovation across everything we do, and allow us to stay open source and innovative.

“Looking ahead, I am genuinely excited about what is coming next in 2026. We have ambitious goals, but I have no doubt whatsoever that together, as one strong, amazing team, we will deliver, grow and continue building something we can all be proud of.” – Alexei Vladishev

The post Zabbix in 2025: A Year of Growth, Community, and Innovation appeared first on Zabbix Blog.

Stronger Together: Succeeding with the Zabbix Partner Program

Post Syndicated from Michael Kammer original https://blog.zabbix.com/stronger-together-succeeding-with-the-zabbix-partner-program/32425/

Ready to scale faster and grow smarter in 2026? If so, it might just be time to take a fresh look at the Zabbix Partner Program.

As we’ve mentioned before on this blog, the Partner Program is a lot more than just an extra layer on top of the software. It’s an invitation to be part of a community, a chance to gain access to advanced Zabbix training and certifications, an opportunity to dramatically expand your business reach, and a way to level up from skilled Zabbix practitioners to globally recognized experts.

What’s new in the Zabbix Partner Program?

In 2025, we made a good thing even better by revising and updating our Partner Program in order to bring Zabbix services to new users, in more locations, and in additional languages. Some of these changes include:

  • Granting more freedom to the Premium partners and supporting their business in cases outside their original territory.
  • Giving outstanding partners the visibility they deserve.
  • Engaging partners in a wider variety of activities and leveraging their expertise.
  • Sharing more business with partners.
  • Communicating better with partners about expectations and how to work with Zabbix.

As evidence of how becoming a Zabbix Partner can give your business a boost, here are a few success stories from five of our top partners.

Somone

Specialists in IT supervision and observability, Somone offers their clients strategic management of services and business indicators. Their experience with a variety of monitoring tools and track record of success with major accounts makes them a key player in the surveillance and observability spheres.

When the Paris-based company became a Zabbix Partner in 2023, they immediately took advantage of Zabbix Certified training and got all their employees certified as Zabbix users. This gave every employee a personal stake in the partnership and quickly brought everyone from the sales team to technical experts up to speed on Zabbix.

The company also notably encouraged its employees to speak at Zabbix events, which strengthened the relationship with Zabbix and encouraged a free exchange of ideas, which in turn helped Somone’s employees bring new ideas to life and improve processes.

As a result, Somone’s own Zabbix training offer has brought a host of new customers and increased their credibility in a crowded and competitive marketplace. In addition, having their own Zabbix team has been an enormous benefit – they have gone from having no real Zabbix strategy to building a dedicated team with their own sales and project leads.

Metricio

A Zabbix Partner for 5 years, Metricio is a Swedish IT services and consulting company that provides professional services and monitoring solutions for the Nordic market. They rely on Zabbix to deliver a cost-efficient and reliable monitoring solution that strengthens their portfolio and helps their customers achieve a higher level of efficiency.

When Metricio first became a Zabbix Partner, they found the Zabbix Partner team’s guidance to be invaluable. They have since advised other partners that they should not hesitate to reach out in the event of questions or concerns. In addition, they have organized several Zabbix-related meetings and events in Sweden, all of which have been more effective thanks to the presence of Zabbix team members.

Metricio worked hard during their first year to strengthen their position and set a goal to become Zabbix Premium Partners by their second year. Today, more than 70% of their leads come from the Zabbix Partner page or joint events. Teaming up with Zabbix has become the foundation of Metricio’s growth, their brand, and their success in the Swedish market.

ASPL Info

ASPL Info is a technology enterprise that aims to revolutionize businesses with best-in-class IT services and digital transformations. They boast a track record of success with global enterprises from a wide variety of sectors and geographies, including HP, Titan, Karnataka Bank, Trust Bank, Tata Sky, William Penn, Bajaj, Maruti, Emirates, Marico, Lupin, Dhanalaxmi Bank, HPE (Ministry of Home Affairs – MHA), Alstom, Birlasoft, Sify Digital, Tamilnad Mercantile Bank, Bank of Baroda, Union Bank of India, Tata-Elxsi, and Airtel.

As a Zabbix Premium Zabbix Partner, ASPL Info has broadened their horizons by working closely with the Zabbix OEM team, engaging early in joint opportunity planning, solution design and roadmap discussions. This has enabled faster project delivery and stronger customer outcomes. Meanwhile, building a highly skilled and certified team via Zabbix Certified trainings has guaranteed consistent delivery quality, better customer confidence, and a deeper understanding of enterprise-scale deployments.

The team at ASPL Info has also greatly benefited from active participation in Zabbix community and partner initiatives, including webinars, regional events, and marketing collaborations. These interactions not only enhance technical expertise but create valuable networking opportunities and visibility, while leveraging Zabbix’s cobranding, marketing and joint engagement initiatives have amplified ASPL Info’s credibility and supported business growth across new markets.

By getting the most out of their Zabbix partnership, ASPL Info has been able to rapidly streamline solution design, accelerate deployment, and strengthen customer confidence, while encouraging their engineers to pursue Zabbix certifications and continuous learning has built deeper in-house expertise, which in turn has allowed them to deliver more value and greater flexibility to their clients.

Since teaming up with Zabbix, ASPL Info have grown around 30–35% in service delivery engagements, maintained a consistent 97% resolution rate for customer queries and complaints related to Zabbix, and achieved 98% customer retention by continuing high-quality services and support throughout and even after the renewal process.

The ATS Group

As the sole Premium Zabbix Partner in North America, the ATS Group has seen strong growth by combining deep technical expertise with Zabbix’s proven monitoring platform and building a practical, collaborative relationship that’s based on accessibility, responsiveness, and mutual trust.

Their team has benefited greatly by engaging directly with the Zabbix team, finding out time and time again that open communication and quick access to the right people make a meaningful difference when delivering results for clients. Another key takeaway they have noted is the benefits of aligning Zabbix with a broader service conversation. Rather than leading with product features, they instead focus on outcomes, highlighting the ways in which Zabbix supports automation, observability, and operational excellence within modern IT environments.

The ATS Group’s partnership with Zabbix has led to new enterprise engagements and an increased awareness of Zabbix in North America through joint marketing activities and technical enablement efforts. The flexibility and support provided by the Zabbix team have been instrumental in helping their team tailor solutions to client needs while growing their monitoring and automation services.

OpenSource ICT Solutions

With a truly global footprint and Zabbix Premium Partner status, OpenSource ICT Solutions serves as a great example of how far being a Zabbix partner can take a business. In many regions they hold the status of “Certified Partner” or “Premium Delivery Partner.” They also operate as an official Zabbix reseller — meaning they can sell Zabbix support and services to customers while offering Zabbix consultancy and implementation services, providing official Zabbix training, and supplying support and managed services.

Their Premium Partner status and close relationship with the Zabbix team has taught them a few very important lessons – first and foremost of which is that Zabbix simply isn’t for everyone. It’s a great fit for many customers, but not all. Their policy is to always be honest about that and to never try to sell something that doesn’t make sense for the client.

They also recommend solving a problem rather than selling a product – in their view, the focus should be on delivering solutions that address real customer needs instead of pushing features. When in doubt, they always reach out to Partners team at Zabbix, who are always there to support them and who have access to valuable internal resources that let them come up with insights and materials that can make a real difference.

The team at OpenSource ICT Solutions also stresses the merits of participating in Zabbix meetings consistently, with every event they’ve attended leading to new customer relationships and strengthening existing ones. Additionally, they have found that blog posts and webinars have been highly effective, as they build visibility and showcase expertise, ultimately strengthening the team’s reputation and customer trust.

Lessons learned

The companies mentioned above are all very different and have used their status as members of the Zabbix Partner Program to achieve different goals, but there are a number of strategies for success and common best practices that apply to all of them, including:

  • Participation. Every partner mentioned above gained significant advantages by participating in Zabbix conferences and meetings, including better visibility and brand recognition, direct access to new leads and business opportunities, early insights Into the Zabbix roadmap and upcoming features, the opportunity to share expertise, and a strengthened relationship with the Zabbix team.
  • Engagement. Working more closely with the Zabbix Partner team provides tangible benefits in the form of more leads and co-selling opportunities, access to exclusive resources (like sales kits, marketing materials, and campaign support), direct access to Zabbix engineers (for architectural guidance, complex deployments, and troubleshooting), and strategic influence via feedback on product roadmaps and participation in advisory discussions.
  • Knowledge acquisition. Up-skilling and cross-skilling teams via Zabbix Certified trainings and our new Zabbix Academy courses benefits partners by ensuring that partner teams have the best possible understanding of Zabbix architecture, deployment, tuning, and troubleshooting, resulting in more efficient and stable deployments, faster problem resolution, and the ability to handle more complex customer environments. Partners can also use Zabbix certification to demonstrate competence during pre-sales, differentiate themselves from non-certified competitors, and build overall customer confidence in their services.

In conclusion

If your company provides IT services, system integration, managed services, or consulting, joining the Zabbix Partner Program is not just an extra benefit or a nice-to-have — it can become a core pillar of business growth. Reach out to our team and get started on the road to greater opportunity today!

The post Stronger Together: Succeeding with the Zabbix Partner Program appeared first on Zabbix Blog.

Building an “Academy of Uptime” with Kristine Lamberte

Post Syndicated from Michael Kammer original https://blog.zabbix.com/building-an-academy-of-uptime-with-kristine-lamberte/31773/

If you’ve been working with Zabbix (or are planning to), you’re in luck – we’ve recently launched Zabbix Academy, a new learning platform designed to empower IT professionals and monitoring enthusiasts with self-paced, expert-led training.

Zabbix Academy is the brainchild of Kristine Lamberte, Head of Training at Zabbix. Kristine was gracious enough to participate in a short interview where she shares the vision behind it, goes into detail about who it’s targeted at (spoiler alert – everyone!), and ruminates about the future of learning and development at Zabbix.

In the beginning: The vision behind Zabbix Academy

Was there anything in particular that inspired the creation of Zabbix Academy, and how does it fit into Zabbix’s long-term vision for community and professional development?

Zabbix itself is an extremely flexible tool, so we want to offer the same level of flexibility in our professional services. At that moment, we had enough variety in the training offer in terms of different courses for different experience levels, and we no doubt had (and still have) a great level of quality as well as theory and hands-on balance, so this was a natural next step in how we can offer even more for our users.

As for the long-term vision, Zabbix Academy supports the growth of the Zabbix ecosystem, it strengthens our training portfolio without replacing live courses, and it also demonstrates our ongoing investment in the community.

Do you see a primary audience for Zabbix Academy (beginners, professionals, enterprise clients, etc.) or is it meant to be universal?

We are ready to meet you at any stage of your Zabbix journey. The Academy has free quick-start guides in the form of free courses and webinars for those who are just starting, as well as a variety of courses on different levels – introduction, fundamental, intermediate, and advanced. And we will add new paid and free material on a regular basis for all levels.

The Zabbix Academy learning experience

How does Zabbix Academy go about keeping learning hands-on and practical for complicated monitoring scenarios?

All the people involved in the creation of training materials are Zabbix Certified Trainers and Zabbix Certified Experts with multiple years of experience. We have a deep understanding that no training material is complete without good-quality real-life use cases and practical tasks. So, it is natural that in Zabbix Academy, for all the paid courses, you will get not only high-quality theory, but also an option to do labs. Learners can experiment in a safe sandbox setting — so they’re not just reading about Zabbix, they’re actually using it.

Instructors and expertise

How do you ensure consistency and quality across so many different topics and courses?

Practice makes perfect, doesn’t it? It all comes down to the people who are behind the course creation. As I already mentioned, they are experienced Zabbix trainers and experts, but most importantly, they have hands-on experience with Zabbix.

But it is not only about our training content creators; we have close collaboration with other teams, for example, internally, support, developers, integrators, etc., and we also have extremely knowledgeable training partners who are very much involved in the review of new courses and suggestions for what’s coming.

Additionally, learner feedback plays a key role — we continuously refine and update materials based on real-world experience and community input.

Career impact

Can you give a hypothetical scenario of how Zabbix Academy could help an IT professional advance their career or an organization strengthen their monitoring practices?

Personally, I put more emphasis on what knowledge brings to the company. Knowing how to work smarter, more efficiently, use effective automations, troubleshoot faster, and come up with new ways of what and how to monitor is something that everyone should want for their business, and these things come with knowledge. What we offer is structured knowledge, packed and passed down to Zabbix users in the most effective way.

The future

What are your goals for the first year of Zabbix Academy, and how will you measure its success?

In the first year, it is crucial to continuously grow and shape Zabbix Academy. The measure of success? I mean, we created this platform for our users, so the measure of success is based on their satisfaction, engagement, and the impact this platform will have on their day-to-day tasks.

What future expansions or features can learners expect?

We aim to continuously expand the course catalogue, both free and paid content, and establish Zabbix Academy as a trusted source of knowledge for both new and existing users. In short, our goal is for Zabbix Academy to evolve into a dynamic, living resource that grows alongside Zabbix itself.

A final thought

From your perspective as Head of Training, what has been the most rewarding or challenging part of launching Zabbix Academy?

There were no challenges worth mentioning, but when it comes to the most rewarding thing, I can name a few.
First thing is that we established right from the beginning that Zabbix Academy will have all kinds of content, including free content. This once again supports our effort in strengthening our community.

Secondly, we did not compromise on the course quality; we took our classroom-quality courses and transformed them for the self-paced training.

But the most rewarding part has been seeing how excited our community is about Zabbix Academy. The feedback from early users and our partners has been overwhelmingly positive. That shows me that we are on the right track, and now we just need to keep on delivering things we are good at – great quality, hands-on content that allows Zabbix users to reach and exceed their monitoring goals.

Continue reading Building an “Academy of Uptime” with Kristine Lamberte