# How to auto-set zabbix\_host?

**URL:** <https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961>\
**Category:** Logstash\
**Created:** [January 7, 2020, 1:51am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961 "2020-01-07T01:51:08Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 1:51am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/1 "2020-01-07T01:51:08Z")

</div>

I'm trying to set up a logstash-\> zabbix gateway, that collects inputs from multiple servers running filebeat.

I gather that zabbix\_host is a mandatory field.  
It also seems like it would be set to the ACTUAL generating host, not the one running the logstash server. So that zabbix can fire off alerts about the actual relevant host.

How can I do this?

After much searching, I stumbled across a reference to using

zabbix\_host =\> "%{source\_host}"

but apparently that isnt valid either.  
What can I do here? Kinda in shock that I cant seem to find any working examples of this.

Logstash 7.5

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 7, 2020, 4:08am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/2 "2020-01-07T04:08:23Z")

</div>

Is this for the zabbix output plugin? We don't use that plugin, but we use both ELK and Zabbix. I suspect zabbix\_host would be the case sensitive host name as defined to zabbix. The agent.hostname might work, depending if it is FQDN and if you used that in Zabbix.

I think the syntax would be "%{[agent][hostname]}".

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 4:16am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/3 "2020-01-07T04:16:07Z")

</div>

Hmm... "%{[agent][hostname]}" sounds potentially useful.  
I was also thinking maybe [@metadata][host] ?  
Is there any listof all the predefined @metadata or [agent] type variables somewhere?  
I've had no luck finding those either ☹

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 7, 2020, 4:18am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/4 "2020-01-07T04:18:42Z")

</div>

Ha! I looked for a list of metadata items while I was writing the first reply and couldn't find it either.

You could add a stdout output and print the event in json debug format to see all the available fields.

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 5:18am UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/5 "2020-01-07T05:18:20Z")

</div>

actually i'm not sure stdout shows you metadata fields.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 7, 2020, 1:23pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/6 "2020-01-07T13:23:09Z")

</div>

No, it doesn't. The agent fields are listed in the filebeat modules section under "beats".

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 2:51pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/7 "2020-01-07T14:51:44Z")

</div>

Pardon?  
I looked at  
[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html)  
but didnt see what you mean

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 7, 2020, 3:42pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/8 "2020-01-07T15:42:16Z")

</div>

Oops, it's the section after modules, [this should be it](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-beat-common.html#exported-fields-beat-common).

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 3:45pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/9 "2020-01-07T15:45:11Z")

</div>

Aha.

Filebeat Reference [master] » Exported fields » Beat fields

Thanks.

Might you have any insight into the [@metadata] fields as well?

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 7, 2020, 4:07pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/10 "2020-01-07T16:07:11Z")

</div>

Hmm. Also..  
the doc you referenced, mentioned  
" **`beat.name`**  
type: alias  
alias to: host.name"

where does this "host.name" come from?  
(which is presumably %[host][name] ?)

that sounds like the same thing, but even more standardized. Would be good to understand that I think.

rather important, because when I do a file dump,  
i see  
"beat":{"hostname":

and

"host":{"name":

but I dont see any mention of "agent".

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 7, 2020, 4:14pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/11 "2020-01-07T16:14:28Z")

</div>

```
output { stdout { codec => rubydebug { metadata => true } } }

```

will print the [@metadata] along with the event.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [January 7, 2020, 4:19pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/12 "2020-01-07T16:19:54Z")

</div>

These fields are being renamed for ECS "common schema".... A noble goal but a clear violation of "if it's not broke don't fix it". 🙂

I just thought there were noting that these fields are aliased in the template for used in Elasticsearch, I think you only see one in the document when it hits logstash.

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 8, 2020, 6:17pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/13 "2020-01-08T18:17:18Z")

</div>

Hit some major weirdness.  
I used that very useful ruby debug output thing.  
determine that the metadata is very small. ONLY actually has:  
type  
beat  
ip\_address

So I tried using

zabbix {  
zabbix\_server\_host =\> "x.x.x.x"  
zabbix\_host =\> "%{[@metadata][ip\_address]}"  
zabbix\_key =\> "filebeat.XXXX"  
}

But I get handed  
org.jruby.exceptions.RuntimeError: (RuntimeError) Invalid FieldReference: `%{[@metadata][ip_address]}`

SO I tried using instead,  
zabbix\_host =\> "%{[beat][hostname]}"

but get more or less the same error.

Which is really wierd, because I CAN use

```
            file {
                    path => "/var/log/logstash/beattest-%{[beat][hostname]}.debug"
                    flush_interval => 1
            }

```

whats the difference??

Dont think it will help any, but here is the FULL trace from the logfile

[2020-01-08T10:12:50,489][FATAL][logstash.runner] An unexpected error occurred! {:error=\>java.lang.IllegalStateException: org.jruby.exceptions.RuntimeError: (RuntimeError) Invalid FieldReference: `%{[beat][hostname]}`, :backtrace=\>["org.logstash.execution.WorkerLoop.run(org/logstash/execution/WorkerLoop.java:85)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:498)", "org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:440)", "org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:304)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.start\_workers(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:251)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:295)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:274)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:270)", "java.lang.Thread.run(java/lang/Thread.java:745)"]}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 8, 2020, 7:44pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/14 "2020-01-08T19:44:00Z")

</div>

Loooking at the [code](https://github.com/logstash-plugins/logstash-output-zabbix/blob/e27187690327116a086fe38127fdaa61be8fe1a7/lib/logstash/outputs/zabbix.rb#L145), it is not using event.sprintf, as any normal plugin would. It is just doing an event.get on it. So you might find that

```
zabbix_host => "[@metadata][ip_address]"

```

works.

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 8, 2020, 8:11pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/15 "2020-01-08T20:11:08Z")

</div>

I think I tried that.  
or at least, I tried "[beat][hostname]"

here's the really weird thing:  
Neither of

```
                      zabbix_host => "[beat][hostname]"
  or
                      zabbix_host => "%{[beat][hostname]}"

```

seemed to work. but

```
 filter {
    mutate {
            add_field => { "[@metadata][zabbix_host]" => "%{[beat][hostname]}" }
    }
 }

 zabbix {
            zabbix_host => "[@metadata][zabbix_host]"
 }

```

kinda worked.

the ONE thing that is now stopping me from having a fully working zabbix output, is

[2020-01-08T11:20:17,173][WARN][logstash.outputs.zabbix][main] Field referenced by filebeat.XXXX is missing  
[2020-01-08T11:20:17,431][WARN][logstash.outputs.zabbix][main] Zabbix server at x.x.x.x rejected all items sent. {:zabbix\_host=\>"xxxxxxx"}

Is this saying that I cant just do  
zabbix\_key =\> "filebeat.XXXX"

I have to do another stupid indirect reference for [@metadata][zabbix\_key] or something??  
What kind of whackjob plugin is this??  
:-/

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 8, 2020, 9:09pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/16 "2020-01-08T21:09:20Z")

</div>

> [@Philip\_Brown](#):
>
> here's the really weird thing

That is weird. Is it possible you have removed the [beat] field by the time the event gets to the output?

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 8, 2020, 9:11pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/17 "2020-01-08T21:11:58Z")

</div>

This is how I got it to work all the way to zabbix.  
Ugh, stupid buggy zabbix module.

```
filter {
    mutate {
        add_field => { "[@metadata][zabbix_host]" => "%{[beat][hostname]}" }
    }
    if "magic-string-we-care-about" in [message] {
            mutate {
                    add_field => { "[@metadata][zabbix_key]" => "filebeat.OUR_UNIQUEKEYHERE" }
                    add_field => { "[@metadata][sendtozabbix]" => "yes" }
            }
    }
}
output {
    if [@metadata][sendtozabbix] == "yes" {
            zabbix {
                    zabbix_server_host => "x.x.x.x"
                    zabbix_host => "[@metadata][zabbix_host]"
                    zabbix_key => "[@metadata][zabbix_key]"
            }
    }
}
```

---

<div class="post-metadata">

**Author:** ![Philip\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philip_brown/32/49853_2.png) [@Philip\_Brown](https://discuss.elastic.co/u/Philip_Brown)\
**Post date:** [January 8, 2020, 9:13pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/18 "2020-01-08T21:13:01Z")

</div>

> Is it possible you have removed the [beat] field by the time the event gets to the output?

PS to badger: no. I checked by doing a dump-to-file of the message in parallel in the output section, after the attempt to send to zabbix.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2020, 9:13pm UTC](https://discuss.elastic.co/t/how-to-auto-set-zabbix-host/213961/19 "2020-02-05T21:13:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
