# Logstash-output-zabbix does not send to zabbix

**URL:** <https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912>\
**Category:** Logstash\
**Created:** [October 5, 2021, 11:53am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912 "2021-10-05T11:53:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 5, 2021, 11:53am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912/1 "2021-10-05T11:53:29Z")

</div>

When sending logs to zabbix, it gives an error.  
[WARN] 2021-10-05 [[main]\>worker1] zabbix - Field referenced by message is missing  
[WARN] 2021-10-05 [[main]\>worker1] zabbix - Zabbix server at [monitoring-server.com](http://monitoring-server.com) rejected all items sent. {:zabbix\_host=\>"Log"}  
My config:

```auto
input {
file {
        path => "/var/log/logstash/test.log"
        start_position => "beginning"
        add_field => ["[@metadata][zabbix_key]" , "trap" ]
        add_field => ["[@metadata][zabbix_host]" , "Log" ]
     }
}
filter {
grok {
match => { "message" => "%{IPORHOST:clientip}%{SPACE}(?:-|(%{WORD}.%{WORD}))%{SPACE}%{USER:id}%{SPACE}\[%{HTTPDATE:timestamp}\]%{SPACE}%{BASE16FLOAT:request_time}%{SPACE}%{BASE16FLOAT:request_time_upstream}%{SPACE}\"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:http_version})?|%{DATA:rawrequest})\"%{SPACE}%{NUMBER:response}%{SPACE}(?:%{NUMBER:bytes}|-)%{SPACE}%{QS:referrer}%{SPACE}%{QS:agent}%{SPACE}%{QS:forwarder}" }
remove_field => "message"
remove_field => "host"
remove_field => "@timestamp"
remove_field => "path"
remove_field => "@version"
}
geoip {
source => "clientip"
target => "geoip"
database => "/etc/logstash/GeoLite2-City.mmdb"
add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
}
      mutate { convert => ["[geoip][coordinates]", "float"] }
}
output {
         stdout { codec => rubydebug }
zabbix {
zabbix_key => "[@metadata][zabbix_key]"
zabbix_host => "[@metadata][zabbix_host]"
zabbix_server_host => "monitoring-server.com"
zabbix_server_port => "10051"
zabbix_value => "message"
  }
}

```

However, if you comment out

```auto
grok {
match 

```

then logs will come to Zabbix but not parsed. It is necessary that the parsed log would come, or only if there is an error status of 500.  
What is wrong with me? Thanks!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 5, 2021, 12:53pm UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912/2 "2021-10-05T12:53:46Z")

</div>

I do not use this plugin, but according to the documentation:

> This plugin will log a warning if a necessary field is missing. It will not attempt to resend if Zabbix is down, but will log an error message.

Which seems to be what you got:

```auto
[WARN] 2021-10-05 [[main]>worker1] zabbix - Field referenced by message is missing

```

In your configuration you are setting `zabbix_value` to `message`, so the value you want to send needs to be in this field. [[documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html#plugins-outputs-zabbix-zabbix_value)].

But before the output block you are removing the `message` field:

```auto
remove_field => "message"

```

So you are making reference to a field that does not exist anymore, this is what is causing your error, try to keep the `message` field and see what happens.

---

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 6, 2021, 5:10am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912/4 "2021-10-06T05:10:56Z")

</div>

The message is sent to zabbix only with this configuration. But accordingly, then the message is not parsed.

> [@Paveltest](#):
>
> ```auto
> input {
> file {
> path => "/var/log/logstash/test.log"
> start_position => "beginning"
> add_field => ["[@metadata][zabbix_key]" , "trap" ]
> add_field => ["[@metadata][zabbix_host]" , "Log" ]
> }
> }
> output {
> stdout { codec => rubydebug }
> zabbix {
> zabbix_key => "[@metadata][zabbix_key]"
> zabbix_host => "[@metadata][zabbix_host]"
> zabbix_server_host => "monitoring-server.com"
> zabbix_server_port => "10051"
> zabbix_value => "message"
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 6, 2021, 5:12am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912/5 "2021-10-06T05:12:42Z")

</div>

Debager shows that the message is now displayed on one line. There are no error messages, but it does not appear in Zabbix.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2021, 5:13am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912/6 "2021-11-03T05:13:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
