# Logstash integration with Zabbix server

**URL:** <https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509>\
**Category:** Logstash\
**Created:** [June 21, 2016, 1:43pm UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509 "2016-06-21T13:43:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alan\_John](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@Alan\_John](https://discuss.elastic.co/u/Alan_John)\
**Post date:** [June 21, 2016, 1:43pm UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509/1 "2016-06-21T13:43:32Z")

</div>

Hi,

I am working on with ELK and Zabbix recently. I'm stuck now with the  
integration of Logstash with Zabbix server. I couldn't find a good  
documentation to follow other than the slides provided by you and some  
public forum posts. I already setup Zabbix server for monitoring my  
openstack cluster. I have getting all the logs in Kibana Dashboard.

Could you please enlighten me, how to integrate Logstash with Zabbix server?  
The path for configuration files and the steps to integrate would be  
enough.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 21, 2016, 2:55pm UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509/2 "2016-06-21T14:55:29Z")

</div>

The Zabbix output plugin requires the values to be _stored_ in fields, so many of the [associated configuration parameters](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html) reference fields.

The following is a sample of what the Logstash end of the configuration might look like. You need to have Zabbix trapper items already made with the same keys you configure in Logstash.

```auto
input {
  # AWS instance, using nginx
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/usr/local/etc/openssl/certs/beats.crt"
    ssl_key => "/usr/local/etc/openssl/private/beats.key"
    tags => ["nginx_json"]
  }

  irc {
    channels => ["#logstash", "#elasticsearch", "#zabbix"]
    host => "irc.freenode.org"
    nick => "mynickname"
    port => 6667
    type => "irc"
  }
}

filter {
  if "nginx_json" in [tags] {
    json {
      source => "message"
      remove_field => "message"
    }
  }
  if "_jsonparsefailure" not in [tags] {
    if "nginx_json" in [tags] {
      mutate {
        replace => { "host" => "%{vhost}" }
        remove_field => "vhost"
      }
      geoip { source => "clientip" }
      if [useragent] != "" { useragent { source => "useragent" } }
      if [referrer] == "-" { mutate { remove_field => "referrer" } }
      if [status] >= 400 and [host] != "localhost" {
        mutate {
          add_field => { "[@metadata][status_key]" => "status" }
          add_field => { "[@metadata][clientip_key]" => "clientip" }
          add_field => { "[@metadata][error]" => "error[%{status},]" }
          add_field => { "[@metadata][counter]" => "1" }
        }
      }
    }
  }
  if [type] == "irc" {
    if [message] =~ /^.*TESTING.*$/ {
      mutate {
        add_field => { "[@metadata][irc_key]" => "message" }
        add_field => { "[@metadata][zabbix_host]" => "irc" }
        add_tag => "testing"
      }
    }
  }
}
output {
      if "nginx_json" in [tags] {
        if [status] >= 400 {
          zabbix {
            zabbix_server_host => "127.0.0.1"
            zabbix_host => "host"
            zabbix_key => "[@metadata][error]"
            zabbix_value => "[@metadata][counter]"
          }

          zabbix {
            zabbix_server_host => "127.0.0.1"
            zabbix_host => "host"
            multi_value => ["[@metadata][status_key]", "status", "[@metadata][clientip_key]", "clientip" ]
          }

        }
      }
      if [type] == "irc" and "testing" in [tags] {
        zabbix {
          zabbix_server_host => "172.19.73.9"
          zabbix_host => "[@metadata][zabbix_host]"
          zabbix_key => "[@metadata][irc_key]"
          zabbix_value => "message"
        }
      }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:51am UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509/3 "2017-07-06T04:51:27Z")

</div>


