Configuration parameters: Zabbix proxy
Overview
Configuration parameters allow customizing Zabbix proxy behavior.
Specify parameter values in the configuration file (zabbix_proxy.conf). All parameters are optional, unless explicitly stated that the parameter is mandatory.
This page is structured as:
- Parameter overview (to see full details of a parameter, click on its name)
- Parameter details
| Parameter | Description |
|---|---|
| AllowRoot | Allow proxy to run as root. |
| AllowUnsupportedDBVersions | Allow proxy to work with unsupported database versions. |
| CacheSize | Set the configuration cache size. |
| ConfigFrequency | This parameter is deprecated (use ProxyConfigFrequency instead). Set the frequency of retrieving configuration data from Zabbix server. |
| DataSenderFrequency | Set the frequency of sending collected data to Zabbix server. |
| DBHost | Specify the database host (or socket directory). |
| DBName | Specify the database name or path to the database file for SQLite3. |
| DBPassword | Specify the database password. |
| DBPort | Specify the port of the Zabbix database host. |
| DBSchema | Specify the database schema name. Used for PostgreSQL. |
| DBSocket | Specify path to the MySQL socket file. |
| DBUser | Specify the database user. |
| DBTLSConnect | Specify a value to enforce a TLS connection to the database. |
| DBTLSCAFile | Specify full pathname of the file containing the top-level CA(s) certificates for database certificate verification. |
| DBTLSCertFile | Specify full pathname of the file containing the Zabbix proxy certificate for authenticating to database. |
| DBTLSKeyFile | Specify full pathname of the file containing the private key for authenticating to database. |
| DBTLSCipher | Specify the list of encryption ciphers that Zabbix proxy permits for TLS protocols up through TLS v1.2. Supported only for MySQL. |
| DBTLSCipher13 | Specify the list of encryption ciphersuites that Zabbix proxy permits for the TLS v1.3 protocol. Supported only for MySQL, starting from version 8.0.16. |
| DebugLevel | Set the debug level. |
| EnableRemoteCommands | Allow remote commands from Zabbix server. |
| ExternalScripts | Specify the external script location. |
| Fping6Location | Specify the fping6 location. |
| FpingLocation | Specify the fping location. |
| HistoryCacheSize | Set the history cache size. |
| HistoryIndexCacheSize | Set the history index cache size. |
| Hostname | Specify the proxy name. |
| HostnameItem | Specify the item used for setting Hostname (if undefined). |
| HousekeepingFrequency | Set the housekeeping procedure frequency (in hours). |
| Include | Specify a directory or individual files to be included in the configuration file. |
| JavaGateway | Specify the Zabbix Java gateway IP address (or hostname). |
| JavaGatewayPort | Specify the Zabbix Java gateway port. |
| ListenBacklog | Set the maximum number of pending connections in the TCP queue. |
| ListenIP | Specify the trapper listen IP address. |
| ListenPort | Specify the trapper listen port. |
| LoadModule | Specify the module to load at proxy startup. |
| LoadModulePath | Specify full path to the location of proxy modules. |
| LogFile | Specify the proxy log file. |
| LogFileSize | Set the maximum log file size. |
| LogRemoteCommands | Enable logging of executed shell commands as warnings. |
| LogSlowQueries | Set the maximum duration a database query may take before being logged (in milliseconds). |
| LogType | Specify the log output type. |
| MaxConcurrentChecksPerPoller | Set the maximum number of asynchronous checks that can be executed at once by each HTTP agent poller, agent poller, or SNMP poller. |
| PidFile | Specify the PID file. |
| ProxyBufferMode | Specify the storage mechanism for history, discovery, and autoregistration data (disk/memory/hybrid). |
| ProxyConfigFrequency | Set the frequency of retrieving configuration data from Zabbix server in seconds. |
| ProxyLocalBuffer | Set the duration of keeping data locally (in hours), even if the data have already been synced with the server. |
| ProxyMemoryBufferAge | Set the maximum age of data in the proxy memory buffer in seconds. |
| ProxyMemoryBufferSize | Set the shared memory cache size for collected history, discovery, and auto registration data. |
| ProxyMode | Set the proxy operating mode (active/passive). |
| ProxyOfflineBuffer | Set the duration of keeping data (in hours) in case of no connectivity with Zabbix server. |
| Server | If ProxyMode is set to active: specify Zabbix server IP address or DNS name (address:port) or cluster (address:port;address2:port) to get configuration data from and send data to.If ProxyMode is set to passive: specify IP addresses or DNS names of Zabbix server. |
| SNMPTrapperFile | Specify the temporary file used for passing data from the SNMP trap daemon to the proxy. |
| SocketDir | Specify the directory for storing IPC sockets used by internal Zabbix services. |
| SourceIP | Specify the source IP address. |
| SSHKeyLocation | Specify the location of public and private keys for SSH checks and actions. |
| SSLCertLocation | Specify the location of SSL-client certificate files for client authentication. |
| SSLKeyLocation | Specify the location of SSL private key files for client authentication. |
| SSLCALocation | Specify the location of certificate authority (CA) files for SSL server certificate verification. |
| StartAgentPollers | Set the number of pre-forked instances of asynchronous Zabbix agent pollers. |
| StartBrowserPollers | Set the number of pre-forked instances of browser item pollers. |
| StartDBSyncers | Set the number of pre-forked instances of history syncers. |
| StartDiscoverers | Set the number of pre-forked instances of discovery workers. |
| StartHTTPAgentPollers | Set the number of pre-forked instances of asynchronous HTTP agent pollers. |
| StartHTTPPollers | Set the number of pre-forked instances of HTTP pollers. |
| StartIPMIPollers | Set the number of pre-forked instances of IPMI pollers. |
| StartJavaPollers | Set the number of pre-forked instances of Java pollers. |
| StartODBCPollers | Set the number of pre-forked instances of ODBC pollers. |
| StartPingers | Set the number of pre-forked instances of ICMP pingers. |
| StartPollersUnreachable | Set the number of pre-forked instances of pollers for unreachable hosts (including IPMI and Java). |
| StartPollers | Set the number of pre-forked instances of pollers. |
| StartPreprocessors | Set the number of pre-started instances of preprocessing workers. |
| StartSNMPPollers | Set the number of pre-forked instances of asynchronous SNMP pollers. |
| StartSNMPTrapper | Set to "1" to start an SNMP trapper process. |
| StartTrappers | Set the number of pre-forked instances of trappers. |
| StartVMwareCollectors | Set the number of pre-forked VMware collector instances. |
| StatsAllowedIP | Specify IP addresses or DNS names of external Zabbix instances that are allowed to request stats. |
| Timeout | Specify how long to wait (in seconds) for establishing connection and exchanging data with Zabbix proxy, agent, web service, and for SNMP checks (except SNMP walk[OID] and get[OID] items). |
| TLSAccept | Specify the level of encryption required for incoming connections from Zabbix server. |
| TLSCAFile | Specify full pathname of the file containing the top-level CA(s) certificates for peer certificate verification, used for encrypted communications between Zabbix components. |
| TLSCertFile | Specify full pathname of the file containing the server certificate or certificate chain, used for encrypted communications between Zabbix components. |
| TLSCipherAll | Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for certificate- and PSK-based encryption. |
| TLSCipherAll13 | Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for certificate- and PSK-based encryption. |
| TLSCipherCert | Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for certificate-based encryption. |
| TLSCipherCert13 | Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for certificate-based encryption. |
| TLSCipherPSK | Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for PSK-based encryption. |
| TLSCipherPSK13 | Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for PSK-based encryption. |
| TLSConnect | Specify the level of encryption required for connections to Zabbix server. |
| TLSCRLFile | Specify full pathname of the file containing revoked certificates. This parameter is used for encrypted communications between Zabbix components. |
| TLSKeyFile | Specify full pathname of the file containing the proxy private key, used for encrypted communications between Zabbix components. |
| TLSListen | Require TLS-only connections on the trapper socket. |
| TLSPSKFile | Specify full pathname of the file containing the proxy pre-shared key, used for encrypted communications with Zabbix server. |
| TLSPSKIdentity | Specify the pre-shared key identity string, used for encrypted communications with Zabbix server. |
| TLSServerCertIssuer | Specify the allowed server certificate issuer. |
| TLSServerCertSubject | Specify the allowed server certificate subject. |
| TmpDir | Specify the temporary directory. |
| TrapperTimeout | Specify timeout in seconds for: - retrieval of configuration data from the Zabbix server; - global script execution or remote command execution. |
| UnavailableDelay | Set the frequency of checking host availability during the unavailability period. |
| UnreachableDelay | Set the frequency of checking host availability during the unreachability period. |
| UnreachablePeriod | Set after how many seconds of unreachability treat host as unavailable. |
| User | Drop privileges to a specific, existing user on the system. |
| Vault | Specify the vault provider. |
| VaultDBPath | Specify the location for retrieving database credentials by keys. |
| VaultPrefix | Specify custom prefix for the vault path or query. |
| VaultTLSCertFile | Specify the name of the SSL certificate file used for client authentication. |
| VaultTLSKeyFile | Specify the name of the SSL private key file used for client authentication. |
| VaultToken | Specify the HashiCorp vault authentication token. |
| VaultURL | Specify the vault server URL. |
| VMwareCacheSize | Set the shared memory size for storing VMware data. |
| VMwareFrequency | Set the frequency of data gathering from a single VMware service in seconds. |
| VMwarePerfFrequency | Set the frequency of retrieving performance counter statistics from a single VMware service in seconds. |
| VMwareTimeout | Set the maximum number of seconds a vmware collector will wait for a response from VMware service. |
| WebDriverURL | Specify the WebDriver interface URL. |
Note that:
- The default values reflect daemon defaults, not the values in the shipped configuration files.
- Values support environment variables.
- Zabbix supports configuration files only in UTF-8 encoding without BOM.
- Comments starting with "#" are only supported in the beginning of the line.
Parameter details
AllowRoot
Allow proxy to run as root.
If disabled and the proxy is started by root, the proxy will try to switch to the zabbix user instead.
Has no effect if started under a regular user.
Default: 0
Values: 0 - do not allow; 1 - allow
AllowUnsupportedDBVersions
Allow proxy to work with unsupported database versions.
Default: 0
Values: 0 - do not allow; 1 - allow
CacheSize
Set the configuration cache size, in bytes. The shared memory size for storing host and item data.
Default: 32M
Range: 128K-64G
ConfigFrequency
This parameter is deprecated (use ProxyConfigFrequency instead).
Set the frequency of retrieving configuration data from Zabbix server (in seconds).
Active proxy parameter.
Ignored for passive proxies (see ProxyMode parameter).
Default: 3600
Range: 1-604800
DataSenderFrequency
Set the frequency of sending collected data from proxy to Zabbix server.
Note that an active proxy will still poll Zabbix server every second for remote command tasks.
Active proxy parameter.
Ignored for passive proxies (see ProxyMode parameter).
Default: 1
Range: 1-3600
DBHost
Specify the database host (or socket directory).
For MySQL:
localhostor an empty string uses the default UNIX-domain socket.
For PostgreSQL:
localhostis resolved via DNS (typically to 127.0.0.1).- An empty string uses the default UNIX-domain socket.
- A path (for example,
/var/run/pgbouncer) results in using the UNIX socket at that path. - A comma-separated list can contain multiple
host:portvalues. Each host is tried in order until a read-write connection is established. Example:DBHost=localhost:5431,127.0.0.1:20051,zabbix.domain,[::1]:30051,[12fc::1]
Default: localhost
DBName
Specify the database name or path to the database file for SQLite3 (the multi-process architecture of Zabbix does not allow to use in-memory database, e.g. :memory:, file::memory:?cache=shared or file:memdb1?mode=memory&cache=shared).
Warning: Do not attempt to use the same database the Zabbix server is using.
Mandatory: Yes
DBPassword
Specify the database password. Comment this line if no password is used. Ignored for SQLite.
DBPort
Specify the port of the Zabbix database host (see DBHost). Ignored for SQLite.
DBSocket and DBPort are mutually exclusive in proxy configuration. Specify only one, or leave both undefined.
Default for MySQL: 3306
Default for PostgreSQL: 5432
Range: 1024-65535
DBSchema
Specify the database schema name. Used for PostgreSQL.
DBSocket
Specify path to the MySQL socket file.
DBSocket and DBPort are mutually exclusive in proxy configuration. Specify only one, or leave both undefined.
DBUser
Specify the database user. Ignored for SQLite.
DBTLSConnect
Specify a value to enforce a TLS connection to the database:
required - connect using TLS
verify_ca - connect using TLS and verify certificate
verify_full - connect using TLS, verify certificate and verify that database identity specified by DBHost matches its certificate
On MySQL starting from 5.7.11 and PostgreSQL the following values are supported: "required", "verify", "verify_full".
On MariaDB starting from version 10.2.6 "required" and "verify_full" values are supported.
By default not set to any option and the behavior depends on database configuration.
DBTLSCAFile
Specify full pathname of the file containing the top-level CA(s) certificates for database certificate verification.
Mandatory: no (yes, if DBTLSConnect set to verify_ca or verify_full)
DBTLSCertFile
Specify full pathname of the file containing the Zabbix proxy certificate for authenticating to database.
DBTLSKeyFile
Specify full pathname of the file containing the private key for authenticating to the database.
DBTLSCipher
Specify the list of encryption ciphers that Zabbix proxy permits for TLS protocols up through TLS v1.2. Supported only for MySQL.
DBTLSCipher13
Specify the list of encryption ciphersuites that Zabbix proxy permits for the TLS v1.3 protocol. Supported only for MySQL, starting from version 8.0.16.
DebugLevel
Set the debug level:
0 - basic information about starting and stopping of Zabbix processes
1 - critical information;
2 - error information;
3 - warnings;
4 - for debugging (produces lots of information);
5 - extended debugging (produces even more information).
Default: 3
Range: 0-5
EnableRemoteCommands
Allow remote commands from Zabbix server.
Default: 0
Values: 0 - do not allow; 1 - allow
ExternalScripts
Specify the external script location (depends on the datadir compile-time installation variable).
Default: /usr/local/share/zabbix/externalscripts
Fping6Location
Specify the fping6 location. Make sure that the fping6 binary has root ownership and the SUID flag set. Make empty ("Fping6Location=") if your fping utility is capable to process IPv6 addresses.
Default: /usr/sbin/fping6
FpingLocation
Specify the fping location. Make sure that the fping binary has root ownership and the SUID flag set.
Default: /usr/sbin/fping
HistoryCacheSize
Set the history cache size, in bytes. The shared memory size for storing history data.
Default: 16M
Range: 128K-16G
HistoryIndexCacheSize
Set the history index cache size, in bytes. The shared memory size for indexing the history data stored in history cache. The index cache size needs roughly 100 bytes to cache one item.
Default: 4M
Range: 128K-16G
Hostname
Specify a unique, case-sensitive proxy name.
Make sure the proxy name is known to the server.
Allowed characters: alphanumeric, '.', ' ', '_' and '-'.
Maximum length: 128
Default: Set by HostnameItem
HostnameItem
Specify an item for setting Hostname (if undefined).
This item will be run on the proxy similarly as on an agent.
Ignored if Hostname is set.
Does not support user parameters, performance counters, or aliases; does support system.run[].
Default: system.hostname
HousekeepingFrequency
Set the housekeeping procedure frequency (in hours).
Housekeeping is removing outdated information from the database.
Note: To lower load on proxy startup housekeeping is postponed for 30 minutes after proxy start.
Thus, if HousekeepingFrequency is 1, the very first housekeeping procedure after proxy start will run after 30 minutes, and will repeat every hour thereafter.
It is possible to disable automatic housekeeping by setting HousekeepingFrequency to 0.
In this case the housekeeping procedure can only be started by housekeeper_execute runtime control option.
See also runtime control options and details on the housekeeping procedure.
Default: 1
Range: 0-24
Include
Specify a directory or individual files to be included in the configuration file.
To only include relevant files in the specified directory, the asterisk wildcard character is supported for pattern matching.
See special notes about limitations.
Example:
Include=/absolute/path/to/config/files/*.conf
JavaGateway
Specify the IP address or hostname of Zabbix Java gateway. Only required if Java pollers are started.
JavaGatewayPort
Specify the Zabbix Java gateway port.
Default: 10052
Range: 1024-32767
ListenBacklog
Set the maximum number of pending connections in the TCP queue.
The default value is a hard-coded constant, which depends on the system.
The maximum supported value depends on the system, too high values may be silently truncated to the 'implementation-specified maximum'.
Default: SOMAXCONN
Range: 0 - INT_MAX
ListenIP
Specify the trapper listen IP address. A comma-delimited list.
Trapper will listen on all network interfaces if this parameter is not specified.
Default: 0.0.0.0
ListenPort
Specify the trapper listen port.
Default: 10051
Range: 1024-32767
LoadModule
Specify the module to load at proxy startup.
Modules are used to extend the functionality of the proxy.
The module must be located in the directory specified by LoadModulePath or the path must precede the module name.
If the preceding path is absolute (starts with '/') then LoadModulePath is ignored.
Formats:
LoadModule=<module.so>
LoadModule=<path/module.so>
LoadModule=</abs_path/module.so>
It is allowed to include multiple LoadModule parameters.
LoadModulePath
The full path to the location of proxy modules. The default depends on compilation options.
LogFile
Specify the proxy log file.
Mandatory: Yes, if LogType is set to file; otherwise no
LogFileSize
Set the maximum log file size (in MB).
0 - disable automatic log rotation.
Note: If the log file size limit is reached and file rotation fails, for whatever reason, the existing log file is truncated and started anew.
Default: 1
Range: 0-1024
LogRemoteCommands
Enable the logging of executed shell commands as warnings.
Default: 0
Values: 0 - disabled, 1 - enabled
LogSlowQueries
Set the maximum duration a database query may take before being logged (in milliseconds).
0 - don't log slow queries.
This option becomes enabled starting with DebugLevel=3.
Default: 0
Range: 0-3600000
LogType
Specify the log output type:
file - write log to the file specified by LogFile parameter;
system - write log to syslog;
console - write log to standard output.
Default: file
MaxConcurrentChecksPerPoller
Set the maximum number of asynchronous checks that can be executed at once by each HTTP agent poller, agent poller, or SNMP poller. See StartHTTPAgentPollers, StartAgentPollers, and StartSNMPPollers.
Default: 1000
Range: 1-1000
PidFile
Specify the PID file.
Default: /tmp/zabbix_proxy.pid
ProxyBufferMode
Specify the storage mechanism for history, discovery, and autoregistration data:
disk - data is stored in database and uploaded from database;
memory - data is stored in memory and uploaded from memory.
If buffer runs out of memory the old data will be discarded.
On shutdown the buffer is discarded.
hybrid - the proxy buffer normally works like in the memory mode until it runs out of memory or the oldest record exceeds the configured age.
If that happens the buffer is flushed to database and it works like in disk mode until all data have been uploaded and it starts working with memory again.
On shutdown the memory buffer is flushed to database.
See also: Proxy memory buffer.
Default: disk
Values: disk; memory; hybrid
ProxyConfigFrequency
Set the frequency of retrieving configuration data from Zabbix server in seconds.
Active proxy parameter.
Ignored for passive proxies (see ProxyMode parameter).
Default: 10
Range: 1-604800
ProxyLocalBuffer
Set the duration of keeping data locally (in hours), even if the data have already been synced with the server..
This parameter may be used if local data will be used by third-party applications.
Default: 0
Range: 0-720
ProxyMemoryBufferAge
Set the maximum age of data in the proxy memory buffer in seconds.
When enabled (not zero) and records in proxy memory buffer are older, then it forces proxy buffer to switch to database mode until all records are uploaded to server.
This parameter must be less or equal to ProxyOfflineBuffer parameter.
Default: 0
Range: 0;600-864000
ProxyMemoryBufferSize
Set the shared memory cache size for collected history, discovery, and auto registration data (in bytes). If enabled (not zero) proxy will keep history discovery and autoregistration data in memory unless cache is full or stored records are older than defined ProxyMemoryBufferAge. This parameter cannot be used together with ProxyLocalBuffer parameter.
Default: 0
Range: 0;128K-2G
ProxyMode
Set the proxy operating mode.
0 - proxy in the active mode
1 - proxy in the passive mode
Note that (sensitive) proxy configuration data may become available to parties having access to the Zabbix server trapper port when using an active proxy.
This is possible because anyone may pretend to be an active proxy and request configuration data; authentication does not take place.
Default: 0
Range: 0-1
ProxyOfflineBuffer
Set the duration of keeping data (in hours) in case of no connectivity with Zabbix server.
Older data will be lost.
Default: 1
Range: 1-720
Server
If ProxyMode is set to active: specify Zabbix server IP address or DNS name (address:port) or cluster (address:port;address2:port) to get configuration data from and send data to.
If port is not specified, the default port is used.
Cluster nodes must be separated by a semicolon.
If ProxyMode is set to passive: specify IP addresses, optionally in CIDR notation, or DNS names of Zabbix server. A comma-delimited list.
Incoming connections will be accepted only from the addresses listed here.
If IPv6 support is enabled then '127.0.0.1', '::127.0.0.1', '::ffff:127.0.0.1' are treated equally.
'::/0' will allow any IPv4 or IPv6 address.
'0.0.0.0/0' can be used to allow any IPv4 address.
Example:
Server=127.0.0.1,192.168.1.0/24,::1,2001:db8::/32,zabbix.example.com
Mandatory: yes
SNMPTrapperFile
Specify the temporary file used for passing data from the SNMP trap daemon to the proxy.
Must be the same as in zabbix_trap_receiver.pl or SNMPTT configuration file.
Default: /tmp/zabbix_traps.tmp
SocketDir
Specify the directory for storing IPC sockets used by internal Zabbix services.
Default: /tmp
SourceIP
Specify the source IP address for:
- outgoing connections to Zabbix server
- agentless connections (VMware, SSH, JMX, SNMP, Telnet and simple checks)
- HTTP agent connections
- script item JavaScript HTTP requests
- preprocessing JavaScript HTTP requests
- connections to the Vault
SSHKeyLocation
Specify the location of public and private keys for SSH checks and actions.
SSLCertLocation
Specify the location of SSL-client certificate files for client authentication.
This parameter is used in web monitoring only.
SSLKeyLocation
Specify the location of SSL private key files for client authentication.
This parameter is used in web monitoring only.
SSLCALocation
Specify the location of certificate authority (CA) files for SSL server certificate verification.
Note that the value of this parameter will be set as the CURLOPT_CAPATH libcurl option.
For libcurl versions before 7.42.0, this only has effect if libcurl was compiled to use OpenSSL.
For more information see the cURL web page.
This parameter is used in web monitoring and in SMTP authentication.
StartAgentPollers
Set the number of pre-forked instances of Zabbix agent pollers.
See MaxConcurrentChecksPerPoller.
Default: 1
Range: 0-1000
StartBrowserPollers
Set the number of pre-forked instances of browser item pollers.
Default: 1
Range: 0-1000
StartDBSyncers
Set the number of pre-forked instances of history syncers.
Note: Be careful when changing this value, increasing it may do more harm than good.
Default: 4
Range: 1-100
StartDiscoverers
Set the number of pre-forked instances of discovery workers.
Default: 5
Range: 0-1000
StartHTTPAgentPollers
Set the number of pre-forked instances of HTTP agent pollers.
See MaxConcurrentChecksPerPoller.
Default: 1
Range: 0-1000
StartHTTPPollers
Set the number of pre-forked instances of HTTP pollers.
Default: 1
Range: 0-1000
StartIPMIPollers
Set the number of pre-forked instances of IPMI pollers.
Default: 0
Range: 0-1000
StartJavaPollers
Set the number of pre-forked instances of Java pollers.
Default: 0
Range: 0-1000
StartODBCPollers
Set the number of pre-forked instances of ODBC pollers.
Default: 1
Range: 0-1000
StartPingers
Set the number of pre-forked instances of ICMP pingers.
Default: 1
Range: 0-1000
StartPollersUnreachable
Set the number of pre-forked instances of pollers for unreachable hosts (including IPMI and Java). At least one poller for unreachable hosts must be running if regular, IPMI or Java pollers are started.
Default: 1
Range: 0-1000
StartPollers
Set the number of pre-forked instances of pollers.
Default: 5
Range: 0-1000
StartPreprocessors
Set the number of pre-started instances of preprocessing worker threads should be set to no less than the available CPU core count.
More workers should be set if preprocessing is not CPU-bound and has lots of network requests.
Default: 16
Range: 1-1000
StartSNMPPollers
Set the number of pre-forked instances of SNMP pollers.
See MaxConcurrentChecksPerPoller.
Default: 1
Range: 0-1000
StartSNMPTrapper
Set to "1" to start an SNMP trapper process.
Default: 0
Range: 0-1
StartTrappers
Set the number of pre-forked instances of trappers.
Trappers accept incoming connections from Zabbix sender and active agents.
Default: 5
Range: 0-1000
StartVMwareCollectors
Set the number of pre-forked vmware collector instances.
Default: 0
Range: 0-250
StatsAllowedIP
Specify IP addresses (optionally in CIDR notation) or DNS names of external Zabbix instances that are allowed to request stats. A comma-delimited list.
If this parameter is not set no stats requests will be accepted.
If IPv6 support is enabled then '127.0.0.1', '::127.0.0.1', '::ffff:127.0.0.1' are treated equally and '::/0' will allow any IPv4 or IPv6 address.
'0.0.0.0/0' can be used to allow any IPv4 address.
Example:
StatsAllowedIP=127.0.0.1,192.168.1.0/24,::1,2001:db8::/32,zabbix.example.com
Timeout
Specify how long to wait (in seconds) for establishing connection and exchanging data with Zabbix server, agent, web service, and legacy SNMP checks (single OID number or string).
This parameter defines the duration for various communication operations:
- Remote command execution on Zabbix agent
- SSH / Telnet command execution
- Rescheduling of items when IPMI interface becomes unavailable
- Sending response to Zabbix server when failing to exchange data due to rights or encryption issues
- Deadline for IPC asynchronous sockets and runtime control options
- Asynchronous poller DNS requests
- Response for active check heartbeat
- Retrieval of Zabbix agent data (values) from active agents
- Retrieval of data from Zabbix sender
- Sending active check list to Zabbix agent
This timeout will not be used for those checks that have flexible timeout settings configured in the frontend (on global, proxy, or per-item level).
For example, SNMP walk[OID] and get[OID] items use the configured timeout from the frontend; legacy SNMP checks still use the server timeout value.
Default: 3
Range: 1-30
TLSAccept
Specify the level of encryption required for incoming connections from Zabbix server.
Used for a passive proxy, ignored on an active proxy.
Multiple values can be specified, separated by comma:
unencrypted - accept connections without encryption (default)
psk - accept connections with TLS and a pre-shared key (PSK)
cert - accept connections with TLS and a certificate
Mandatory: yes for passive proxy, if TLS certificate or PSK parameters are defined (even for unencrypted connection); otherwise no
TLSCAFile
Specify full pathname of the file containing the top-level CA(s) certificates for peer certificate verification, used for encrypted communications between Zabbix components.
TLSCertFile
Specify full pathname of the file containing the proxy certificate or certificate chain, used for encrypted communications between Zabbix components.
TLSCipherAll
Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for certificate- and PSK-based encryption.
Example:
TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
TLSCipherAll13
Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for certificate- and PSK-based encryption.
Example for GnuTLS:
NONE:+VERS-TLS1.2:+ECDHE-RSA:+RSA:+ECDHE-PSK:+PSK:+AES-128-GCM:+AES-128-CBC:+AEAD:+SHA256:+SHA1:+CURVE-ALL:+COMP-NULL::+SIGN-ALL:+CTYPE-X.509
Example for OpenSSL:
EECDH+aRSA+AES128:RSA+aRSA+AES128:kECDHEPSK+AES128:kPSK+AES128
TLSCipherCert
Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for certificate-based encryption.
Example for GnuTLS:
NONE:+VERS-TLS1.2:+ECDHE-RSA:+RSA:+AES-128-GCM:+AES-128-CBC:+AEAD:+SHA256:+SHA1:+CURVE-ALL:+COMP-NULL:+SIGN-ALL:+CTYPE-X.509
Example for OpenSSL:
EECDH+aRSA+AES128:RSA+aRSA+AES128
TLSCipherCert13
Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for certificate-based encryption.
TLSCipherPSK
Specify the GnuTLS priority string or OpenSSL (TLS 1.2) cipher string. Override the default ciphersuite selection criteria for PSK-based encryption.
Example for GnuTLS:
NONE:+VERS-TLS1.2:+ECDHE-PSK:+PSK:+AES-128-GCM:+AES-128-CBC:+AEAD:+SHA256:+SHA1:+CURVE-ALL:+COMP-NULL:+SIGN-ALL
Example for OpenSSL:
kECDHEPSK+AES128:kPSK+AES128
TLSCipherPSK13
Specify the cipher string for OpenSSL 1.1.1 or newer in TLS 1.3. Override the default ciphersuite selection criteria for PSK-based encryption.
Example:
TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
TLSConnect
Specify the level of encryption required for proxy connections to Zabbix server.
Used for an active proxy, ignored on a passive proxy.
Only one value can be specified:
unencrypted - connect without encryption (default)
psk - connect using TLS and a pre-shared key (PSK)
cert - connect using TLS and a certificate
Mandatory: yes for active proxy, if TLS certificate or PSK parameters are defined (even for unencrypted connection); otherwise no
TLSCRLFile
Specify full pathname of the file containing revoked certificates. This parameter is used for encrypted communications between Zabbix components.
TLSKeyFile
Specify full pathname of the file containing the proxy private key, used for encrypted communications between Zabbix components.
TLSListen
Require TLS-only connections on the trapper socket.
Supported values:
- required - accept only TLS connections
TLSPSKFile
Specify full pathname of the file containing the proxy pre-shared key, used for encrypted communications with Zabbix server.
TLSPSKIdentity
Specify the pre-shared key identity string, used for encrypted communications with Zabbix server.
TLSServerCertIssuer
Specify the allowed server certificate issuer.
TLSServerCertSubject
Specify the allowed server certificate subject.
TmpDir
Specify the temporary directory.
Default: /tmp
TrapperTimeout
Specify timeout in seconds for:
- retrieval of configuration data from the Zabbix server;
- global script execution or remote command execution.
Default: 300
Range: 1-300
UnavailableDelay
Set the frequency of checking host availability during the unavailability period in seconds.
Default: 60
Range: 1-3600
UnreachableDelay
Set the frequency of checking host availability during the unreachability period in seconds.
Default: 15
Range: 1-3600
UnreachablePeriod
Set after how many seconds of unreachability treat host as unavailable.
Default: 45
Range: 1-3600
User
Drop privileges to a specific, existing user on the system.
Only has effect if run as root and AllowRoot is disabled.
Default: zabbix
Vault
Specify the vault provider:
HashiCorp - HashiCorp KV Secrets Engine version 2
CyberArk - CyberArk Central Credential Provider
Must match the vault provider set in the frontend.
Default: HashiCorp
VaultDBPath
Specify the location for retrieving database credentials by keys. It is a Vault path or query, depending on the Vault.
The keys used for HashiCorp are 'password' and 'username'.
Example path with VaultPrefix=/v1/secret/data/zabbix/:
database
Example path without VaultPrefix:
secret/zabbix/database
The keys used for CyberArk are 'Content' and 'UserName'.
Example:
AppID=zabbix_server&Query=Safe=passwordSafe;Object=zabbix_proxy_database
This option can only be used if DBUser and DBPassword are not specified.
VaultPrefix
Specify custom prefix for the vault path or query, depending on the Vault.
The most suitable defaults will be used if not specified.
Note that 'data' is automatically appended after mountpoint for HashiCorp if VaultPrefix is not specified.
Note that 'data' is automatically appended after mountpoint for HashiCorp if VaultPrefix is not specified.
Example prefix for Hashicorp:
v1/secret/data/zabbix/
Example prefix for Cyberark:
/AIMWebService/api/Accounts?
VaultTLSCertFile
Specify the name of the SSL certificate file used for client authentication.
The certificate file must be in PEM1 format.
If the certificate file contains also the private key, leave the SSL key file field empty.
The directory containing this file is specified by the SSLCertLocation configuration parameter.
This option can be omitted, but is recommended for CyberArkCCP vault.
VaultTLSKeyFile
Specify the name of the SSL private key file used for client authentication.
The private key file must be in PEM1 format.
The directory containing this file is specified by the SSLKeyLocation configuration parameter.
This option can be omitted, but is recommended for CyberArkCCP vault.
VaultToken
Specify the HashiCorp vault authentication token that should have been generated exclusively for Zabbix proxy with read-only permission to the path specified in the optional VaultDBPath configuration parameter.
It is an error if VaultToken and the VAULT_TOKEN environment variable are defined at the same time.
Mandatory: Yes, if Vault is set to HashiCorp; otherwise no
VaultURL
Specify the vault server URL. The system-wide CA certificates directory will be used if SSLCALocation is not specified.
Default: https://127.0.0.1:8200
VMwareCacheSize
Set the shared memory size for storing VMware data.
A VMware internal check zabbix[vmware,buffer,...] can be used to monitor the VMware cache usage (see Internal checks).
Note that shared memory is not allocated if there are no vmware collector instances configured to start.
Default: 8M
Range: 256K-2G
VMwareFrequency
Set the frequency of data gathering from a single VMware service (in seconds).
This frequency should be set to the least update interval of any VMware monitoring item.
Default: 60
Range: 10-86400
VMwarePerfFrequency
Set the frequency of retrieving performance counter statistics from a single VMware service (in seconds).
This frequency should be set to the least update interval of any VMware monitoring item that uses VMware performance counters.
Default: 60
Range: 10-86400
VMwareTimeout
Set the maximum number of seconds a vmware collector will wait for a response from VMware service (vCenter or ESX hypervisor).
Default: 10
Range: 1-300
WebDriverURL
Specify the WebDriver interface URL.
Example (used with Selenium WebDriver standalone server):
WebDriverURL=http://localhost:4444