Configuration parameters: Zabbix bridge adapter
Overview
Configuration parameters allow customizing Zabbix bridge adapter behavior.
Specify parameter values in the configuration file (zabbix_bridge_adapter.conf).
All parameters are optional, unless explicitly stated that the parameter is mandatory.
This page is structured as:
- Parameter overview (to see full details of a parameter, click its name)
- Parameter details
| Parameter | Description |
|---|---|
| AllowedAPIMethods | Specify which Zabbix API methods can be called through Zabbix bridge adapter. |
| DataDir | Specify the directory where the bridge adapter state file and encryption keys are created and stored. |
| DebugLevel | Set the debug level. |
| Include | Specify a directory or individual files to be included in the configuration file. |
| ListenIP | Specify the bridge adapter listen IP address for incoming HTTP[S] connections from Zabbix server. |
| ListenHealthPort | Specify the bridge adapter listen port for incoming HTTP health-check connections. |
| ListenPort | Specify the bridge adapter listen port for incoming HTTP[S] connections from Zabbix server. |
| LogFile | Specify the full path to the bridge adapter log file. |
| LogFileSize | Set the maximum log file size (in MB). |
| LogType | Specify the log output type. |
| PidFile | Specify the PID file. |
| TLSConfig.AllowedCN | Specify a comma-separated list of permitted client Common Names (mTLS only). |
| TLSConfig.CAFile | Specify the full path to a file containing the top-level CA certificate(s) used to verify client certificates in mTLS mode. |
| TLSConfig.CertFile | Specify the full path to a file containing the certificate or certificate chain. |
| TLSConfig.KeyFile | Specify the full path to a file containing the private key. |
| TLSConfig.Mode | Set the TLS mode for incoming connections on ListenPort. |
| ServerId | Specify the unique identifier of Zabbix server. Mandatory. |
| ZabbixAPITLSCAFile | Specify the full pathname of a file containing the top-level CA certificate(s) used by the bridge adapter to verify the Zabbix API certificate. |
| ZabbixAPITLSConnect | Set the TLS mode for outbound connections to the Zabbix API. |
| ZabbixAPIURL | Specify the URL of the Zabbix API endpoint. Mandatory. |
| ZabbixBridgeURL | Specify Zabbix Bridge URL for Zabbix Bridge configuration retrieval (retrieved when the bridge adapter starts). |
Note that:
- The default values reflect process defaults, not the values in the shipped configuration files.
- Values support environment variables.
- Zabbix supports configuration files only in UTF-8 encoding without BOM;
- Comments starting with
#are only supported at the beginning of the line.
Parameter details
AllowedAPIMethods
Specify which Zabbix API methods can be called through Zabbix bridge adapter.
For several methods, repeat the parameter, one method per line.
Each parameter value must be either an exact method name (e.g., problem.get) or a wildcard pattern that replaces only the whole API name (e.g., *.get) or the whole method name (e.g., problem.*).
Any other value is invalid and prevents Zabbix bridge adapter from starting.
This includes a lone wildcard (*), a partial wildcard pattern (host* or host*.*), or an empty value (AllowedAPIMethods=).
Example:
AllowedAPIMethods=apiinfo.version
AllowedAPIMethods=problem.*
AllowedAPIMethods=*.get
The minimal set of methods that Zabbix mobile app requires:
AllowedAPIMethods=apiinfo.version
AllowedAPIMethods=device.onboard
AllowedAPIMethods=device.offboard
AllowedAPIMethods=user.get
AllowedAPIMethods=role.get
AllowedAPIMethods=problem.get
AllowedAPIMethods=event.get
AllowedAPIMethods=event.acknowledge
AllowedAPIMethods=trigger.get
AllowedAPIMethods=alert.get
AllowedAPIMethods=host.get
AllowedAPIMethods=hostgroup.get
Default: not set (all Zabbix API methods are denied)
DataDir
Specify the directory where the bridge adapter state file and encryption keys are created and stored.
The directory must have 0700 permissions, and all files stored in it must have 0600 permissions.
Default: /var/lib/zabbix-bridge-adapter
DebugLevel
Set the debug level:
0- basic information about starting and stopping of Zabbix processes1- critical information2- error information3- warnings4- for debugging (produces lots of information)5- extended debugging (produces even more information)
Default: 3
Range: 0-5
Include
Specify a directory or individual files to be included in the configuration file.
During Zabbix installation, this parameter is set to /usr/local/etc, unless you change this during compile time.
General rules for the Include parameter:
- The path can be relative to the
zabbix_bridge_adapter.conffile location. - You can specify multiple
Includeparameters in one configuration file. - Zabbix processes the
Includeparameter as soon as it reads it, so consider placing it at the end of the configuration file.
Rules for included files:
- Each file must be readable.
- Each file must have correct syntax. Otherwise, the component will not start.
Rules for including directories or file patterns:
- Do not assume any order of inclusion (e.g., files are not included in alphabetical order).
- Do not define the same parameter in more than one included file (e.g., to override a general setting with a specific one), since you cannot predict which value will be used.
- Watch out for backup copies that some text editors create automatically (e.g., editing
include/my_specific.confmay createinclude/my_specific.conf.BAK), since both files will be included.
To include only relevant files from a directory, use the wildcard (*) for pattern matching.
Example:
Include=/absolute/path/to/config/files/*.conf
ListenIP
Specify the bridge adapter listen IP address for incoming HTTP[S] connections from Zabbix server.
If not specified, the bridge adapter listens on all IP addresses.
ListenHealthPort
Specify the bridge adapter listen port for incoming HTTP health-check connections.
Serves the /health and /ready endpoints.
If not specified, the health service is not started.
Default: 8081
Range: 1024-32767
ListenPort
Specify the bridge adapter listen port for incoming HTTP[S] connections from Zabbix server.
Default: 10005
Range: 1024-32767
LogFile
Specify the full path to the bridge adapter log file.
Mandatory: Yes if LogType is set to file
Default: /tmp/zabbix_bridge_adapter.log
LogFileSize
Set the maximum log file size (in MB).
0 - disable automatic log rotation.
Default: 1
Range: 0-1024
LogType
Specify the log output type:
file- write log to file specified byLogFileparameter.system- write log to syslog.console- write log to standard output.
Default: file
PidFile
Specify the PID file.
Default: /tmp/zabbix_bridge_adapter.pid
ServerId
Specify the unique identifier of Zabbix server.
Available in Reports > System information in the Zabbix user interface.
Mandatory: Yes
TLSConfig.AllowedCN
Specify a comma-separated list of permitted client Common Names (mTLS only).
If not specified, the bridge adapter does not check the client Common Name.
TLSConfig.CAFile
Specify the full path to a file containing the top-level CA certificate(s) used to verify client certificates in mTLS mode.
TLSConfig.CertFile
Specify the full path to a file containing the certificate or certificate chain.
TLSConfig.KeyFile
Specify the full path to a file containing the private key.
TLSConfig.Mode
Set the TLS mode for incoming connections on ListenPort:
none- accept connections without encryption.tls- standard TLS with v1.2 minimum.mtls- extends TLS with mutual authentication.
Default: none
ZabbixAPITLSCAFile
Specify the full pathname of a file containing the top-level CA certificate(s) used by the bridge adapter to verify the Zabbix API certificate.
Mandatory: Yes if ZabbixAPITLSConnect is set to verify_ca or verify_full.
ZabbixAPITLSConnect
Set the TLS mode for outbound connections to the Zabbix API:
disabled(or empty) - use plain HTTP;ZabbixAPIURLmust usehttp://.required- use HTTPS without certificate verification (testing only).verify_ca- use HTTPS and verify the Zabbix API certificate.verify_full- use HTTPS and verify the Zabbix API certificate and hostname.
ZabbixAPIURL
Specify the URL of the Zabbix API endpoint.
Mandatory: Yes
Example:
ZabbixAPIURL=https://example.com/zabbix/api_jsonrpc.php
ZabbixBridgeURL
Specify Zabbix bridge URL for Zabbix Bridge configuration retrieval (retrieved when the bridge adapter starts).
Default: ZabbixBridgeURL=https://test.aws.zabbix-lab.win/.well-known/bridge-configuration