# Logstash integration with Zabbix server

**URL:** <https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509>\
**Category:** Logstash\
**Created:** [June 21, 2016, 1:43pm UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509 "2016-06-21T13:43:32Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 21, 2016, 2:55pm UTC](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509/2 "2016-06-21T14:55:29Z")

</div>

The Zabbix output plugin requires the values to be _stored_ in fields, so many of the [associated configuration parameters](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html) reference fields.

The following is a sample of what the Logstash end of the configuration might look like. You need to have Zabbix trapper items already made with the same keys you configure in Logstash.

```auto
input {
  # AWS instance, using nginx
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "/usr/local/etc/openssl/certs/beats.crt"
    ssl_key => "/usr/local/etc/openssl/private/beats.key"
    tags => ["nginx_json"]
  }

  irc {
    channels => ["#logstash", "#elasticsearch", "#zabbix"]
    host => "irc.freenode.org"
    nick => "mynickname"
    port => 6667
    type => "irc"
  }
}

filter {
  if "nginx_json" in [tags] {
    json {
      source => "message"
      remove_field => "message"
    }
  }
  if "_jsonparsefailure" not in [tags] {
    if "nginx_json" in [tags] {
      mutate {
        replace => { "host" => "%{vhost}" }
        remove_field => "vhost"
      }
      geoip { source => "clientip" }
      if [useragent] != "" { useragent { source => "useragent" } }
      if [referrer] == "-" { mutate { remove_field => "referrer" } }
      if [status] >= 400 and [host] != "localhost" {
        mutate {
          add_field => { "[@metadata][status_key]" => "status" }
          add_field => { "[@metadata][clientip_key]" => "clientip" }
          add_field => { "[@metadata][error]" => "error[%{status},]" }
          add_field => { "[@metadata][counter]" => "1" }
        }
      }
    }
  }
  if [type] == "irc" {
    if [message] =~ /^.*TESTING.*$/ {
      mutate {
        add_field => { "[@metadata][irc_key]" => "message" }
        add_field => { "[@metadata][zabbix_host]" => "irc" }
        add_tag => "testing"
      }
    }
  }
}
output {
      if "nginx_json" in [tags] {
        if [status] >= 400 {
          zabbix {
            zabbix_server_host => "127.0.0.1"
            zabbix_host => "host"
            zabbix_key => "[@metadata][error]"
            zabbix_value => "[@metadata][counter]"
          }

          zabbix {
            zabbix_server_host => "127.0.0.1"
            zabbix_host => "host"
            multi_value => ["[@metadata][status_key]", "status", "[@metadata][clientip_key]", "clientip" ]
          }

        }
      }
      if [type] == "irc" and "testing" in [tags] {
        zabbix {
          zabbix_server_host => "172.19.73.9"
          zabbix_host => "[@metadata][zabbix_host]"
          zabbix_key => "[@metadata][irc_key]"
          zabbix_value => "message"
        }
      }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-integration-with-zabbix-server/53509)._
