Zabbix for Distributed Monitoring (MSP Architecture)
Zabbix is an open-source, enterprise-grade monitoring solution widely used for monitoring network devices, servers, virtual machines, and cloud services. It’s highly scalable and capable of handling complex distributed environments, making it suitable for Managed Service Providers (MSPs) or large organizations with multiple remote locations. This document outlines a Zabbix architecture for distributed monitoring, covering key components and their configuration.
1. Zabbix Components Overview
A typical Zabbix setup involves several interacting components:
- Zabbix Server: The central component that performs monitoring, data collection, and data storage. It processes incoming data, calculates triggers, and sends notifications.
- Zabbix Proxy: An optional but highly recommended component for distributed monitoring. Proxies collect monitoring data on behalf of the Zabbix Server and buffer it locally, reducing the load on the server and ensuring data collection even if connectivity to the server is temporarily lost.
- Zabbix Agent: A small program installed on monitored hosts to actively collect local data (e.g., CPU load, disk space, network usage) and send it to the Zabbix Server or Proxy. Agents can operate in active or passive mode.
- SNMP Devices: Devices that support SNMP (e.g., routers, switches) can be monitored directly by the Zabbix Server or Proxy without an agent.
2. Distributed Monitoring Architecture
This section describes a common setup for MSPs or large distributed environments, often involving Client Zabbix Servers/Proxies reporting to a Central Zabbix Server.
Client Agents
- Mode: Typically configured in active mode (
ZBX_ACTIVESERVERS), meaning they periodically connect to the Zabbix Server/Proxy to fetch items to monitor and then send collected data. - Reporting: Can send data to both a local Client Zabbix Server and a Client Zabbix Proxy for redundancy or specific routing.
Client Zabbix Server (Optional, for local processing)
- Function: Receives data directly from local agents and performs local auto-registration and discovery based on metadata.
Client Zabbix Proxy
- Mode: Can operate in passive mode (
ZBX_PROXYMODE=1), where the Zabbix Server polls the proxy for data, or active mode (ZBX_PROXYMODE=0), where the proxy periodically connects to the server and sends data. Passive mode is often used when the central server initiates communication. - Function: Gathers data from local agents and SNMP devices, buffers it, and then forwards it to the Central Zabbix Server.
Central Zabbix Server
- Function: Acts as the central repository for all monitoring data. It collects data from multiple Zabbix Proxies and potentially directly from some agents.
- Management: Performs global auto-registration and discovery rules based on data received from proxies.
3. Zabbix Configuration Examples (Docker Compose)
Zabbix Proxy (docker-compose.yml snippet)
This example shows a Docker Compose configuration for a Zabbix Proxy in passive mode, connecting to a MySQL database and forwarding data to a Zabbix Server.
version: '3.8'
services:
zabbix-proxy:
image: zabbix/zabbix-proxy-mysql:7.0.8-alpine # Use appropriate Zabbix version
container_name: zabbix-proxy
environment:
- DB_SERVER_HOST=db # MySQL server hostname or IP for proxy's database
- MYSQL_USER=root # MySQL username for the Zabbix proxy's database
- MYSQL_PASSWORD=<MYSQL_ROOT_PASSWORD> # MySQL password for the Zabbix proxy's database
- ZBX_SERVER_HOST=<ZABBIX_SERVER_IP_OR_HOSTNAME> # IPs or hostnames of the Zabbix servers (comma-separated)
- ZBX_SERVER_PORT=10051 # Default Zabbix server port
- ZBX_PROXYMODE=1 # 0 for Active, 1 for Passive. Here, Server pulls from Proxy.
restart: unless-stopped
ports:
- "10052:10051" # Expose proxy's data-gathering port if needed
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"Zabbix Agent (Active Mode docker run command)
This agent sends data to multiple active servers/proxies and uses host metadata for auto-registration.
docker run -d \
--name zabbixagent \
--restart always \
-e ZBX_ACTIVESERVERS=<SERVER_IP_1>:10051,<PROXY_IP_1>:10052 \ # List of servers/proxies to send active checks to
-e ZBX_HOSTNAME="$(hostname)" \ # Hostname reported to Zabbix (dynamic)
-e ZBX_METADATA=linux \ # Host metadata used for auto-registration rules
-v /var/run/docker.sock:/var/run/docker.sock:ro \ # Mount Docker socket for Docker monitoring
--user 0:0 \
zabbix/zabbix-agent2This configures the agent in active mode to send data to both a Zabbix Server (<SERVER_IP_1>:10051) and a Zabbix Proxy (<PROXY_IP_1>:10052). The ZBX_METADATA=linux is crucial for auto-registration actions on the Zabbix Server/Proxy.
4. Zabbix Server Auto-Registration and Discovery
Auto-Registration for Agents
Auto-registration rules define actions to take when a new agent connects to the Zabbix Server/Proxy. This is commonly used to automatically link templates and add hosts.
Steps (Zabbix Web UI: Alerts -> Actions -> Auto-Registration):
- Create a new Action.
- Conditions: Define criteria, e.g.,
Host metadata contains linux. - Operations: Define actions, e.g.,
Add host,Link templates: Docker by Zabbix agent 2,Linux by Zabbix agent active.
Network Discovery for SNMP Devices
Network Discovery rules automatically detect hosts within specified IP ranges and can apply templates based on discovered services (e.g., SNMP responses).
Steps (Zabbix Web UI: Data Collection -> Discovery):
- Create a new Discovery rule.
- IP range: Specify the network range to scan, e.g.,
10.100.200.0/24. - Checks: Configure checks to identify devices. For SNMP,
Check Type: SNMPv2/v3 / Port: 161 / SNMP community / OID: 1.3.6.1.2.1.1.1.0. This OID is generic and returns basic system information. - Discovery Actions (Zabbix Web UI: Alerts -> Actions -> Discovery Actions):
- Conditions: Define criteria, e.g.,
Discovery status equals Up,Received value contains Linux(from OID). - Operations: Define actions, e.g.,
Add host,Link templates: Docker by Zabbix agent 2,Linux by SNMP.
- Conditions: Define criteria, e.g.,
5. Central Zabbix Setup Specifics
When a central Zabbix Server monitors many clients via proxies, additional configurations are needed.
Adding Proxies to Central Zabbix
Steps (Zabbix Web UI: Administration -> Proxies):
- Add a new proxy.
- Configure: Set its name, mode (Passive or Active), and the IP address/DNS name of the proxy.
Central Auto-Registration with Proxies
Auto-registration rules on the central server can also factor in which proxy the agent is reporting through.
Steps (Zabbix Web UI: Alerts -> Actions -> Auto-Registration):
- Conditions:
Host metadata contains linuxANDProxy = <The Proxy Name>. - Operations:
Add host,Link templates: Docker by Zabbix agent 2,Linux by Zabbix agent active.
Central Network Discovery with Proxies
Discovery rules on the central server can leverage proxies to perform scans in remote networks.
Steps (Zabbix Web UI: Data Collection -> Discovery):
- Create a new Discovery rule.
- IP range:
10.100.200.0/24. - Proxy: Select the specific proxy that should perform the discovery.
- Checks: Configure SNMP checks as before.
- Discovery Actions (Zabbix Web UI: Alerts -> Actions -> Discovery Actions):
- Conditions:
Proxy = <The Proxy Name>,Discovery status equals Up,Received value contains Linux. - Operations:
Add host,Link templates: Docker by Zabbix agent 2,Linux by SNMP.
- Conditions: