Saturday, January 6, 2018

How To Install and Configure Zabbix to Securely Monitor Remote Servers on CentOS 7

Step 1  Installing the Zabbix Server

First, we need to install the Zabbix Server on our server with MySQL, Apache, and PHP. We'll refer to this machine as the Zabbix server. Log into this machine as your non-root user:

  • ssh sammy@your_zabbix_server_ip_address

Zabbix isn't available in our package manager by default, so we will install a repository configuration package using the official Zabbix repository for CentOS,

  • sudo rpm -ivh

You will see the following output:


warning: /var/tmp/rpm-tmp.qLbOPP: Header V4 DSA/SHA1 Signature, key ID 79ea5ed4: NOKEY
Preparing... ################################# [100%]
Updating / installing...
1:zabbix-release-3.0-1.el7 ################################# [100%]
Now you can run the following command to install the Zabbix server and web frontend with MySQL database support:

  • sudo yum install zabbix-server-mysql zabbix-web-mysql

During the installation process you will be asked about importing a GPG key. Confirm it so the installation can complete.
Let's also install the Zabbix agent, which will let us collect data about the Zabbix server itself.

  • sudo yum install zabbix-agent

Before we can use Zabbix, we have to set up a database to hold the data that the Zabbix server will collect from its agents.

Step 2 — Configuring the MySQL Database For Zabbix

We need to create a new MySQL database and populate it with some basic information in order to make it suitable for Zabbix. We'll also create a specific user for this database so Zabbix isn't logging into MySQL with the root account.
Log into MySQL as the root user using the root password that you set up during the MySQL server installation:

  • mysql -uroot -p

First, create the Zabbix database with UTF-8 character support:

  • create database zabbix character set utf8;

Next, create a user that the Zabbix server will use, give it access to the new database, and set the password:

  • grant all privileges on zabbix.* to zabbix@localhost identified by 'your_password';

Then apply these new permissions:

  • flush privileges;

That takes care of the user and the database. Exit out of the database console.

  • quit;

Next we have to import the initial schema and data. The Zabbix installation provided us with a file that sets this up for us. We just have to import it. Navigate to the directory:

  • cd /usr/share/doc/zabbix-server-mysql-3.0.4/

Run the following command to set up the schema and import the data into the zabbix database. We'll use zcat since the data in the file is compressed.

  • zcat create.sql.gz | mysql -uzabbix -p zabbix

Enter the password for the zabbix user that you configured when prompted.
This command will not output any errors if it was successful. If you see the error ERROR 1045 (28000): Access denied for user 'zabbix'@'localhost' (using password: YES) then make sure you used the password for the zabbix user and not the root user.
In order for the Zabbix server to use this database, you need to set the database password in the Zabbix server configuration file.

  • sudo vi /etc/zabbix/zabbix_server.conf

Look for the following section of the file:
### Option: DBPassword                           
# Database password. Ignored for SQLite.
# Comment this line if no password is used.
# Mandatory: no
# Default:
# DBPassword=
These comments in the file explain how to connect to the database. We need to set the DBPasswordvalue in the file to the password for our database user. Add this line below those comments to configure the database:
That takes care of the Zabbix server configuration, but we have to make some modifications to our PHP setup in order for the Zabbix web interface to work properly.

Step 3 — Configuring PHP For Zabbix

The Zabbix web interface is written in PHP and requires some special PHP server settings. The Zabbix installation process created an Apache configuration file that contains these settings. It is located in the directory /etc/httpd/conf.d/ and is loaded automatically by Apache. We need to make a small change to this file, so open it up.

  • sudo vi /etc/httpd/conf.d/zabbix.conf

The file contains PHP settings that meet the necessary requirements for the Zabbix web interface. The only change you need to make is to set the appropriate timezone, which is commented out by default.
<IfModule mod_php5.c>
php_value max_execution_time 300
php_value memory_limit 128M
php_value post_max_size 16M
php_value upload_max_filesize 2M
php_value max_input_time 300
php_value always_populate_raw_post_data -1
# php_value date.timezone Europe/Riga
Uncomment the timezone line, highlighted above, and change it to your time zone. You can use this list of supported time zones to find the right one for you. Then save and close the file.
Now restart Apache to apply these new settings.

  • sudo systemctl restart httpd

You can now start the Zabbix server.

  • sudo systemctl start zabbix-server

Then check whether the Zabbix server is running properly:

  • sudo systemctl status zabbix-server

You will see the following status:


● zabbix-server.service - Zabbix Server
Loaded: loaded (/usr/lib/systemd/system/zabbix-server.service; disabled; vendor preset: disabled)
Active: :active (running) since Fri 2016-08-05 07:16:35 UTC; 2s ago
Process: 10033 ExecStart=/usr/sbin/zabbix_server -c $CONFFILE (code=exited, status=0/SUCCESS)
Finally, enable the Zabbix server to start at boot time:

  • sudo systemctl enable zabbix-server

The server is set up and connected to the database. Now let's set up the web frontend.

Step 4 — Configuring Settings for the Zabbix Web Interface

The web interface lets us see reports and add hosts that we want to monitor, but it needs some initial setup before we can use it. Launch your browser and go to the address http://your_zabbix_server_ip_address/zabbix/. On the first screen, you will see a welcome message. Click Next step to continue.
On the next screen, you will see the table that lists all of the prerequisites to run Zabbix.
All of the values in this table must show OK, so verify that they do. Be sure to scroll down and look at all of the prerequisites. Once you've verified that everything is ready to go, click Next step to proceed.
The next screen asks for database connection information.
DB Connection
We told the Zabbix server about our database, but the Zabbix web interface also needs access to the database to manage hosts and read data so it can display it to us. Enter the MySQL credentials you configured in Step 2 and click Next step to proceed.
On the next screen, you can leave the options at their default values.
Zabbix Server Details
The Name is optional; it is used in the web interface to distinguish one server from another in case you have several monitoring servers. Click Next step to proceed.
The next screen will show the pre-installation summary so you can confirm everything is correct.
Click Next step to proceed to the final screen.
The web interface setup is complete! This process creates the configuration file /etc/zabbix/web/zabbix.conf.php which you could back up and use in the future. Click Finish to proceed to the login screen. The default user is admin and the password is zabbix.
Before we log in, let's set up the Zabbix agent on our other server.

Step 5 — Installing and Configuring the Zabbix Agent

Now we need to configure the agent software that will send monitoring data to the Zabbix server.
Login to the second server, which we'll call the “monitored server”.

  • ssh sammy@your_monitored_server_ip_address

Then, just like on the Zabbix server, run the following command to install the repository configuration package:

  • sudo rpm -ivh

You will see the following output:


warning: /var/tmp/rpm-tmp.jnLROO: Header V4 DSA/SHA1 Signature, key ID 79ea5ed4: NOKEY
Preparing... ################################# [100%]
Updating / installing...
1:zabbix-release-3.0-1.el7 ################################# [100%]
Then install the Zabbix agent:

  • sudo yum install zabbix-agent

Confirm that you want to import the GPG key when asked.
While Zabbix supports certificate-based encryption, setting up a certificate authority is beyond the scope of this tutorial, but we can use pre-shared keys (PSK) to secure the connection between the server and agent.
So first, generate a PSK:

  • sudo sh -c "openssl rand -hex 32 > /etc/zabbix/zabbix_agentd.psk"

Show the key so you can copy it somewhere. You will need it to configure the host.

  • cat /etc/zabbix/zabbix_agentd.psk

The key will look something like this:


Now you have to edit the Zabbix agent settings to set up its secure connection to the Zabbix server. Open the agent configuration file:

  • sudo vi /etc/zabbix/zabbix_agentd.conf

Each setting within this file is documented via informative comments throughout the file, but you only need to edit some of them.
First, you must edit the IP address of the Zabbix server. Find the following section:
### Option: Server
# List of comma delimited IP addresses (or hostnames) of Zabbix servers.
# Incoming connections will be accepted only from the hosts listed here.
# If IPv6 support is enabled then '', '::', '::ffff:' are treated equally.
# Mandatory: no
# Default:
# Server=

Change the default value to the IP of your Zabbix server:
Next, find the section that configures the secure connection to the Zabbix server and enable pre-shared key support. Find the
TSLConnect section, which looks like this:

### Option: TLSConnect
# How the agent should connect to server or proxy. Used for active checks.
# Only one value can be specified:
# unencrypted - connect without encryption
# psk - connect using TLS and a pre-shared key
# cert - connect using TLS and a certificate
# Mandatory: yes, if TLS certificate or PSK parameters are defined (even for 'unencrypted' connection)
# Default:
# TLSConnect=unencrypted
Then add this line to configure pre-shared key support:
Next, locate the TLSAccept section, which looks like this:
### Option: TLSAccept
# What incoming connections to accept.
# Multiple values can be specified, separated by comma:
# unencrypted - accept connections without encryption
# psk - accept connections secured with TLS and a pre-shared key
# cert - accept connections secured with TLS and a certificate
# Mandatory: yes, if TLS certificate or PSK parameters are defined (even for 'unencrypted' connection)
# Default:
# TLSAccept=unencrypted

Configure incoming connections to support pre-shared keys by adding this line:
Next, find the TLSPSKIdentity section, which looks like this:
### Option: TLSPSKIdentity
# Unique, case sensitive string used to identify the pre-shared key.
# Mandatory: no
# Default:
# TLSPSKIdentity=
Choose a unique name to identify your pre-shared key by adding this line:
TLSPSKIdentity=PSK 001
You'll use this as the PSK ID when you add your host through the Zabbix web interface.
Then set the option which points to your previously created pre-shared key. Locate the TLSPSKFileoption:
### Option: TLSPSKFile
# Full pathname of a file containing the pre-shared key.
# Mandatory: no
# Default:
Add this line to point the Zabbix agent to your PSK file you created:
Save and close the file. Now you can start the Zabbix agent and set it to start at boot time:

  • sudo systemctl start zabbix-agent

  • sudo systemctl enable zabbix-agent

For good measure, check that the Zabbix agent is running properly:

  • sudo systemctl status zabbix-agent

You will see the following status, indicating the agent is running:


● zabbix-agent.service - Zabbix Agent
Loaded: loaded (/usr/lib/systemd/system/zabbix-agent.service; disabled; vendor preset: disabled)
Active: active (running) since Fri 2016-08-05 08:17:07 UTC; 5s ago
Process: 9507 ExecStart=/usr/sbin/zabbix_agentd -c $CONFFILE (code=exited, status=0/SUCCESS)
Our agent is now ready to send data to the Zabbix server. But in order to use it, we have to link to it from the server's web console.

Step 6 — Adding the New Host to the Zabbix Server

Installing an agent on a server we want to monitor is only half of the process. Each host we want to monitor needs to be registered on the Zabbix server, which we can do through the web interface.
Log in to the Zabbix Server web interface by navigating to the address http://your_zabbix_server_ip_address/zabbix/.
The Zabbix login screen
When you have logged in, click on the Configuration, and then Hosts in the top navigation bar. Then click Create host button in the top right corner of the screen. This will open the host configuration page.
Creating a host
Adjust the Host name and IP ADDRESS to reflect the host name and IP address of your client machine. Then add the host to a group by selecting one of the groups from the list, or by creating your own group. The host can be in multiple groups. The Linux Servers group is a good default choice. Once you've added the group, click the Templates tab.
Adding a template to the host
Type Template OS Linux in the Search field and then click Add to add this template to the host.
Next, navigate to Encryption tab. Select PSK for both Connections to host and Connections from host. Then set PSK identity to PSK 001, which is the value of the TLSPSKIdentity setting of the Zabbix agent we configured previously. Then set
PSK value to the key you generated for the Zabbix agent. It's the one stored in the file /etc/zabbix/zabbix_agentd.psk on the agent machine.
Setting up the encryption.
Finally, click the Add button at the bottom of the form to create the host.
You will see your new host with green labels indicating that everything is working fine and the connection is encrypted.
Zabbix shows your new host.
After several seconds you can navigate to Monitoring and then Latest data to see the data from your agent.
To ensure things are working, shut down your monitored server so you can see how Zabbix alerts you to problems. Once your monitored server is offline you will see the warning on the main dashboard:
Zabbix shows you a warning about the host that's offline.
If you have additional servers you need to monitor, log in to each host, install the Zabbix agent, generate a PSK, configure the agent, and add the host to the web interface following the same steps you followed to add your first host.

No comments:

Post a Comment

TicTic v2.2 - Android media app for creating and sharing short videos

Facebook Twitter Tiktik – Android app for creating and sharing short videos. The customizable social video application to build ...

Popular Posts