# Logstash with zabbix output ISSUE

**URL:** <https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434>\
**Category:** Logstash\
**Created:** [May 28, 2015, 12:21am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434 "2015-05-28T00:21:49Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [May 28, 2015, 12:21am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/1 "2015-05-28T00:21:50Z")

</div>

Hello!

I have problem, my zabbix output just don't work and i can't find reason why.

For example, i've created simple logstash conf file:

input {  
tcp {  
port =\> 6000  
type =\> syslog  
}  
udp {  
port =\> 6000  
type =\> syslog  
}  
}  
filter {  
grep {  
type =\> "linux-syslog"  
match =\> ["@message", "(error|ERROR|CRITICAL)"]  
add\_tag =\> ["zabbix-sender"]  
add\_field =\> [  
"zabbix\_host", "%{@test01}",  
"zabbix\_item", "Test.broj"  
]  
}  
}

output {  
stdout { codec =\> rubydebug }  
zabbix {  
tags =\> "zabbix-sender"  
zabbix\_sender =\> "/usr/local/bin/zabbix\_sender"  
}  
}

Then i created Host in zabbix named re01os01.net.ot.hr, zabbix trapper item named "Test" with key "broj" and type of information as "TEXT".

1. I start logstash (it started well with no errors)
2. I telnet to localhost port 6000 and type "CRITICAL"  
Logstash return me parsed log:  
{  
"message" =\> "CRITICAL\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-05-28T00:08:34.282Z",  
"host" =\> "0:0:0:0:0:0:0:1:50210",  
"type" =\> "syslog"  
}

So it works great!

After that, i go to zabbix and check trapper item and it just don't get any value.

Please help!

Best Regards,

Marko

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 28, 2015, 12:34am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/2 "2015-05-28T00:34:55Z")

</div>

What version of Logstash are you using? The configuration you're using here seems to indicate you're using Logstash 1.4.x or older. If you're using Logstash 1.5, the Zabbix output plugin is totally changed.

See [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html)

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [May 28, 2015, 5:38am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/3 "2015-05-28T05:38:08Z")

</div>

I am using logstash-1.4.2

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [May 29, 2015, 7:12pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/4 "2015-05-29T19:12:06Z")

</div>

Do I have right configuration of zabbix output plugin, as I use logstasth 1.4.2 or i need something to change?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 29, 2015, 7:28pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/5 "2015-05-29T19:28:17Z")

</div>

I'm not sure. I rewrote the plugin to use native Ruby for Logstash 1.5.0 because the dependency on zabbix\_sender was extremely slow. The old plugin was also not extensible. The pre-1.5 version of the plugin was not terrific. I recommend upgrading Logstash and using the new version of the zabbix plugin.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [May 29, 2015, 8:24pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/6 "2015-05-29T20:24:12Z")

</div>

I will upgrade then to logstash 1.5. Could you give me simple conf example of zabbix output plugin for 1.5?  
Also do i have to change any other syntax in conf file?

Thanks in advance, I appreciate your help!

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [May 29, 2015, 9:54pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/7 "2015-05-29T21:54:30Z")

</div>

[quote]I have upgraded to Logstash 1.5  
Now my zabbix output looks like:

zabbix {  
zabbix\_host =\> "re01os01.net.ot.hr",  
zabbix\_key =\> "broj",  
zabbix\_value =\> "message"  
}  
}

but when i start logstash i got error:

Error: Expected one of #, {, } at line 35, column 36 (byte 784) after output {  
stdout { codec =\> rubydebug }

zabbix {  
zabbix\_host =\> "re01os01.net.ot.hr"  
You may be interested in the '--configtest' flag which you can  
use to validate logstash's configuration before you choose  
to restart a running system.

I don't get it, help!  
[/quote]

Continuing the discussion from [Logstash with zabbix output ISSUE](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/7):

> [@Cenzoooo](#):
>
> I have upgraded to Logstash 1.5  
> Now my zabbix output looks like:
> 
> zabbix {  
> zabbix\_host =\> "re01os01.net.ot.hr",  
> zabbix\_key =\> "broj",  
> zabbix\_value =\> "message"  
> }  
> }
> 
> but when i start logstash i got error:
> 
> Error: Expected one of #, {, } at line 35, column 36 (byte 784) after output {  
> stdout { codec =\> rubydebug }
> 
> zabbix {  
> zabbix\_host =\> "re01os01.net.ot.hr"  
> You may be interested in the '--configtest' flag which you can  
> use to validate logstash's configuration before you choose  
> to restart a running system.
> 
> I don't get it, help!

I found error, it was about ","  
Now I start logstash and it says "Logstash startup completed", and when i input example of Log i got message :"Skipping zabbix output; field referenced by re01os01.net.ot.hr is missing {:level=\>:warn}"

I have configured re01os01.net.ot.hr as Hostname in Zabbix, and my conf looks like:

output {  
zabbix {  
zabbix\_host =\> "re01os01.net.ot.hr"  
zabbix\_key =\> "broj"  
zabbix\_value =\> "message"  
}  
}

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 1, 2015, 5:04pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/8 "2015-06-01T17:04:51Z")

</div>

I can't see your entire output block, but it appears that you have an extra closing curly brace there.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 3, 2015, 5:52am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/9 "2015-06-03T05:52:16Z")

</div>

Here is my complete .conf

input {  
tcp {  
port =\> 6000  
type =\> syslog  
}  
udp {  
port =\> 6000  
type =\> syslog  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:  
syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDA  
TA:syslog\_message}" }  
add\_tag =\> ["zabbix-sender"]  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{@host}"]  
add\_field =\> ["send\_field", "%{@message}"]  
add\_field =\> ["zabbix\_host", "%{test01}"]  
}  
syslog\_pri { }

date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {

stdout { codec =\> rubydebug }

zabbix {  
zabbix\_host =\> "test01"  
zabbix\_key =\> "Logstash"  
zabbix\_value =\> "message"  
zabbix\_server\_host =\> "10.1.14.205"  
}  
}

When I telnet to port 6000 and put log message i get:

{  
"message" =\> "Apr 30 01:51:56 test01 3795: Apr 30 01:51:55.941: %BGP-5-ADJCHANGE: neighbor 10.10.1.33 Up \r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-04-29T23:51:56.000Z",  
"host" =\> "0:0:0:0:0:0:0:1",  
"type" =\> "syslog",  
"syslog\_timestamp" =\> "Apr 30 01:51:56",  
"syslog\_hostname" =\> "test01",  
"syslog\_program" =\> "3795",  
"syslog\_message" =\> "Apr 30 01:51:55.941: %BGP-5-ADJCHANGE: neighbor 10.10.1.33 Up \r",  
"received\_at" =\> "2015-06-03T03:30:02.183Z",  
"received\_from" =\> "%{@host}",  
"send\_field" =\> "%{@message}",  
"zabbix\_host" =\> "%{test01}",  
"tags" =\> [  
[0] "zabbix-sender"  
],  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"  
}  
Skipping zabbix output; field referenced by test01 is missing {:level=\>:warn}

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 3, 2015, 5:49pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/10 "2015-06-03T17:49:37Z")

</div>

Which version of Logstash are you using? The "send\_field" reference suggests 1.4.2 or older.

The version that ships with 1.5 requires you to have certain configuration values in fields, rather than as strings in the config. The config option "zabbix\_host" must refer to a field name whose value will be sent as the the zabbix host in the sender packet. The same is true of the zabbix\_key and zabbix\_value directives.

With the configuration you provided, that implies that field "test01" will contain the value of the zabbix host, the field "Logstash" will contain the zabbix key, and the field "message" will contain the value to send associated with that key and host. Please see the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-zabbix.html) for more details.

The version of the plugin I am working on right now will support multiple fields per event.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 5, 2015, 5:49am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/11 "2015-06-05T05:49:25Z")

</div>

I am using version 1.5, i deleted send\_field as i did not know it's unnecesarry.  
You are right, i want to send vaule from field "message" to host "test01", i made zabbix trapper item callet "Logstash" and key is also "Logstash".  
So what do i do wrong when i get "Skipping zabbix output; field referenced by test01 is missing {:level=\>:warn}"?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 5, 2015, 6:52pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/12 "2015-06-05T18:52:06Z")

</div>

The value "test01" must be in a field. In your case, it appears in "syslog\_hostname." So your zabbix output block should have:

```
zabbix {
  zabbix_host => "syslog_hostname"
  ...
}

```

In this way, the keys are provided programmatically instead of manually.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 7, 2015, 5:43am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/13 "2015-06-07T05:43:46Z")

</div>

Thanks! Now i modified conf and i think it's OK now, but i still have issues, when i put log i got message:  
"Zabbix server at 10.1.14.205 rejected all items sent. "

---

<div class="post-metadata">

**Author:** ![MrAV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrav/32/557_2.png) [@MrAV](https://discuss.elastic.co/u/MrAV)\
**Post date:** [June 8, 2015, 7:33am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/14 "2015-06-08T07:33:42Z")

</div>

@Marko,

have you added "allowed host" to your zabbix item?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 8, 2015, 5:31pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/15 "2015-06-08T17:31:48Z")

</div>

Indeed, this suggests that item (zabbix\_key) does not exist in "host" in zabbix. Logstash will not create the items for you. You need to do this yourself before the item will "arrive" in Zabbix.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 9, 2015, 11:38am UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/16 "2015-06-09T11:38:21Z")

</div>

I did create zabbix trapper item, and that item is applied on my host "test01", and i still get this error.  
What should i put into "allowed host" field? My zabbix is on localhost, port is default too...

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 9, 2015, 3:42pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/17 "2015-06-09T15:42:06Z")

</div>

I don't know what to tell you. That error can _only_ occur if the host & key do not match up. It's the equivalent of using zabbix\_sender and seeing:

```
"response"=>"success", "info"=>"processed 0; Failed 1; Total 1; seconds spent: 0.000018" 

```

(Okay, that's the ruby version, but it's very close). You sent one item, but it failed to be recognized by the Zabbix server.

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 9, 2015, 4:53pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/18 "2015-06-09T16:53:33Z")

</div>

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSIN$  
add\_tag =\> ["zabbix-sender"]  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
add\_field =\> ["send\_field", "%{message}"]  
add\_field =\> ["zabbix\_host", "test01"]  
add\_field =\> ["zabbix\_key", "Logstash"] }  
syslog\_pri { }

date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

And output:

zabbix {  
zabbix\_host =\> "zabbix\_host"  
zabbix\_key =\> "zabbix\_key"  
zabbix\_value =\> "syslog\_message"  
zabbix\_server\_host =\> "10.1.14.205"  
}  
}

 ![](https://us1.discourse-cdn.com/elastic/original/1X/507c0f9a64152f5e647e486c2bc3950a0c4d752d.JPG)

I really don't understand what's wrong... I even tried to send mannually to trapper:  
zabbix\_sender -z 10.1.14.205 -p 10051 -s "test01" -k Logstash -o "test value" and i got "test value" message into zabbix...

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 9, 2015, 5:08pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/19 "2015-06-09T17:08:52Z")

</div>

I don't see a field called syslog\_message. Is it there?

---

<div class="post-metadata">

**Author:** ![Cenzoooo](https://avatars.discourse-cdn.com/v4/letter/c/85f322/32.png) [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Post date:** [June 9, 2015, 5:39pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434/20 "2015-06-09T17:39:04Z")

</div>

Yes, i fixed that, it should not be "syslog\_message", it should have been "send\_field".  
Now i corrected that and WHOA! No error when i put log message, BUT i still got nothing in zabbix!  
Im gonna kill myself!!! ☹

[Next page](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434.md?page=2)
