Zabbix
The Zabbix connector allows for the integration of Zabbix's robust monitoring capabilities into Swimlane's security automation workflows.
Zabbix is a comprehensive network monitoring solution that enables organizations to identify and resolve IT infrastructure issues before they impact critical business processes. The Zabbix Turbine Connector allows users to integrate Zabbix's robust monitoring capabilities directly into Swimlane Turbine's low-code security automation platform. This integration empowers users to automate event acknowledgment, retrieve detailed event information, and manage triggers within Zabbix, streamlining incident response and enhancing operational efficiency.
Limitations
To simplify API versioning, since Zabbix 2.0.4, the version of the API matches the version of Zabbix itself. You can use the apiinfo.version method to find out the version of the API you are working with. This can be useful for adjusting your application to use version-specific features.
Supported Version
Zabbix API implements JSON-RPC version 2.0.
Configuration
Prerequisites
To effectively utilize the Zabbix connector with Swimlane Turbine, ensure you have the following prerequisites:
- Custom authentication via the user.login method with the following parameters:
- URL: The endpoint URL for your Zabbix API.
- Username: Your Zabbix username to authenticate API requests.
- Password: Your Zabbix password associated with the provided username.
- ID: A unique identifier for the API session or call.
Authentication Methods
- URL: The endpoint URL for the Zabbix API.
- Username: The Zabbix user account name.
- Password: The password associated with the Zabbix user account.
- ID: A unique identifier for the API session.
- By Auth Property: Specific property used for authentication purposes. If this Property is true, Auth Property will be used and if false, the Authorization Header will be used.
Setup Instructions:
The API token is obtained by:
To access any data in Zabbix, you need to either:
- Use an existing API token (created in Zabbix frontend or using the Token API).
- Use an authentication token obtained with the user.login method.
Document reference: https://www.zabbix.com/documentation/6.4/en/manual/api
To set up the Zabbix connector in Turbine, follow these steps:
- Ensure to enable by_auth_property in the Asset to choose either "Authorization" Header or "Auth" Property.
- If by_auth_property is true, then it will work using By "auth" Property Authentication Method.
- If by_auth_property is false, then it will work using By "Authorization" Header Authentication Method.
- Other required fields are URL, Username, Password and ID.
By "Authorization" Header
All API requests require an authentication or an API token. You can provide the credentials by using the "Authorization" request header:
curl --request POST \
--url 'https://example.com/zabbix/api_jsonrpc.php' \
--header 'Authorization: Bearer 0424bd59b807674191e7d77572075f33'By "auth" Property
An API request can be authorized by the "auth" property.
Note that the "auth" property is deprecated. It will be removed in the future releases.
curl --request POST \
--url 'https://example.com/zabbix/api_jsonrpc.php' \
--header 'Content-Type: application/json-rpc' \
--data '{"jsonrpc":"2.0","method":"host.get","params":{"output":["hostid"]},"auth":"0424bd59b807674191e7d77572075f33","id":1}'Troubleshoot Tips:
If you wanted to obtain a new authentication token by logging in as a standard Admin user, then a JSON request would look like this:
--url 'https://example.com/zabbix/api_jsonrpc.php' \
--header 'Content-Type: application/json-rpc' \
--data '{"jsonrpc":"2.0","method":"user.login","params":{"username":"Admin","password":"zabbix"},"id":1}'If you provided the credentials correctly, the response returned by the API should contain the user authentication token:
{
"jsonrpc": "2.0",
"result": "0424bd59b807674191e7d77572075f33",
"id": 1
}Capabilities
- Event Acknowledge
- Get Event
- Get Trigger
Event Acknowledge
This method allows to update events. The following update actions can be performed:
- Close event. If event is already resolved, this action will be skipped.
- Acknowledge event. If event is already acknowledged, this action will be skipped.
- Unacknowledge event. If event is not acknowledged, this action will be skipped.
- Add message.
- Change event severity. If event already has same severity, this action will be skipped.
- Suppress event. If event is already suppressed, this action will be skipped.
- Unsuppress event. If event is not suppressed, this action will be skipped. More details on this actions can be found here.
Get Event
The method allows to retrieve events according to the given parameters. This method may return events of a deleted entity if these events have not been removed by the housekeeper yet. This method is available to users of any type. Permissions to call the method can be revoked in user role settings. See User roles for more information. More details on this method can be found here.
Get Trigger
The method allows to retrieve triggers according to the given parameters. This method is available to users of any type. Permissions to call the method can be revoked in user role settings. See User roles for more information. More details on this method can be found here.
Configurations
Zabbix User Login Authentication
An API request can be authorized by the user.login method.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Username for authentication. | string | Required |
password | Password for authentication. | string | Required |
id | ID of the request. | string | Required |
by_auth_property | If this Property is true, Auth Property will be used and if false, the Authorization Header will be used. | boolean | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Event Acknowledge
Updates event statuses in Zabbix, allowing users to manage problem events with options to close or modify severity. Requires read/write trigger rights.
Endpoint
- URL: /zabbix/api_jsonrpc.php
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
jsonrpc | string | Optional | Version of the JSON-RPC protocol. Default value is 2.0. |
id | number | Optional | ID of the request. |
method | string | Optional | Method to call. |
params | object | Optional | Parameters for the Method. |
params.eventids | array | Required | IDs of the Events to acknowledge. |
params.action | number | Required | Event update Actions to perform. Possible bitmap values are 1 - close problem; 2 - acknowledge event; 4 - add message; 8 - change severity; 16 - unacknowledge event; 32 - suppress event; 64 - unsuppress event; 128 - change event rank to cause; 256 - change event rank to symptom.This is a bitmask field; any sum of possible bitmap values is acceptable (for example, 34 for acknowledge and suppress event). |
params.cause_eventid | string | Optional | Cause Event ID for Symptom Rank. It is required if action contains the "change event rank to symptom" bit. |
params.message | string | Optional | Text of the Message to add. It is required if action contains the "add message" bit. |
params.severity | number | Optional | New Severity for Events. Possible values are 0 - not classified; 1 - information; 2 - warning; 3 - average; 4 - high; 5 - disaster. It is required if action contains the "change severity" bit. |
params.suppress_until | number | Optional | Unix timestamp until which event must be suppressed. If set to "0", the suppression will be indefinite. Parameter behavior:- required if action contains the "suppress event" bit. |
Input Example
{"jsonrpc":2.0,"id":123,"method":"event.acknowledge","params":{"eventids":["string"],"action":123,"cause_eventid":"string","message":"string","severity":123,"suppress_until":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
jsonrpc | string | Output field: jsonrpc |
result | object | Result of the operation |
result.eventids | array | Unique identifier |
id | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 2 May 2024 20:37:23 GMT"},"reason":"OK","json_body":{"jsonrpc":"2.0","result":{"eventids":[]},"id":1}}
Get Event
Retrieves specified events from Zabbix, including details on deleted entities awaiting cleanup. Requires jsonrpc, id, method, and params.
Endpoint
- URL: /zabbix/api_jsonrpc.php
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
jsonrpc | string | Optional | Version of the JSON-RPC protocol. Default value is 2.0. |
id | number | Optional | ID of the request. |
method | string | Optional | Method to call. |
params | object | Optional | Parameter for Get Event |
params.eventids | array | Optional | Return only events with the given IDs. |
params.groupids | array | Optional | Return only events created by objects that belong to the given host groups. |
params.hostids | array | Optional | Return only events created by objects that belong to the given hosts. |
params.objectids | array | Optional | Return only events created by the given objects. |
params.source | number | Optional | Return only events with the given type. Refer to the event object page for a list of supported event types. Type of the event. Possible values are 0 - event created by a trigger; 1 - event created by a discovery rule; 2 - event created by active agent autoregistration; 3 - internal event; 4 - event created on service status update. |
params.object | number | Optional | Return only events created by objects of the given type. Possible values if source is set to "event created by a trigger" - 0 - trigger. Possible values if source is set to "event created by a discovery rule" - 1 - discovered host; 2 - discovered service. Possible values if source is set to "event created by active agent autoregistration" - 3 - auto-registered host. Possible values if source is set to "internal event" - 0 - trigger; 4 - item; 5 - LLD rule. Possible values if source is set to "event created on service status update" - 6 - service. |
params.acknowledged | boolean | Optional | If set to true return only acknowledged events. |
params.action | number | Optional | Return only events for which the given event update actions have been performed. For multiple actions, use a sum of any acceptable bitmap values as bitmask (for example, 34 for acknowledge and suppress event). Possible bitmap values are 1 - close problem; 2 - acknowledge event; 4 - add message; 8 - change severity; 16 - unacknowledge event; 32 - suppress event; 64 - unsuppress event; 128 - change event rank to cause; 256 - change event rank to symptom. |
params.action_userids | array | Optional | Return only events with the given IDs of users who performed the event update actions. |
params.suppressed | boolean | Optional | true - return only suppressed events. false - return events in the normal state. |
params.symptom | boolean | Optional | true - return only symptom events. false - return only cause events. |
params.severities | array | Optional | Return only events with the given event severities. Applies only if object is trigger. |
params.trigger_severities | array | Optional | Return only events with the given trigger severities. Applies only if object is trigger. |
params.evaltype | number | Optional | Rules for tag searching. Possible values 0 - (default) And/Or; 2 - Or. |
params.tags | array | Optional | Return only events with the given tags. Exact match by tag and case-insensitive search by value and operator. An empty array returns all events. |
params.tags.tag | string | Optional | Parameter for Get Event |
params.tags.value | string | Optional | Value for the parameter |
params.tags.operator | string | Optional | Possible operator types are 0 - (default) Like; 1 - Equal; 2 - Not like; 3 - Not equal; 4 - Exists; 5 - Not exists. |
params.eventid_from | string | Optional | Return only events with IDs greater or equal to the given ID. |
params.eventid_till | string | Optional | Return only events with IDs less or equal to the given ID. |
params.time_from | string | Optional | Return only events that have been created after or at the given time. |
Input Example
{"jsonrpc":2.0,"id":123,"method":"event.get","params":{"eventids":["string"],"groupids":["string"],"hostids":["string"],"objectids":["string"],"source":123,"object":123,"acknowledged":true,"action":123,"action_userids":["string"],"suppressed":true,"symptom":true,"severities":[123],"trigger_severities":[123],"evaltype":123,"tags":[{"tag":"string","value":"string","operator":"string"}],"eventid_from":"string","eventid_till":"string","time_from":"string","time_till":"string","problem_time_from":"string","problem_time_till":"string","value":[123],"selectAcknowledges":"string","selectAlerts":"string","selectHosts":"string","selectRelatedObject":"string","selectSuppressionData":"string","selectTags":"string","filter":{},"sortfield":["string"],"groupBy":["string"],"countOutput":true,"editable":true,"excludeSearch":true,"limit":123,"output":"extend","preservekeys":true,"search":{},"searchByAny":true,"searchWildcardsEnabled":true,"sortorder":"ASC","startSearch":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
jsonrpc | string | Output field: jsonrpc |
result | array | Result of the operation |
result.eventid | string | Unique identifier |
result.source | string | Result of the operation |
result.object | string | Result of the operation |
result.objectid | string | Unique identifier |
result.clock | string | Result of the operation |
result.value | string | Value for the parameter |
result.acknowledged | string | Result of the operation |
result.ns | string | Result of the operation |
result.name | string | Name of the resource |
result.severity | string | Result of the operation |
result.r_eventid | string | Unique identifier |
result.c_eventid | string | Unique identifier |
result.correlationid | string | Unique identifier |
result.userid | string | Unique identifier |
result.cause_eventid | string | Unique identifier |
result.acknowledges | array | Result of the operation |
result.acknowledges.acknowledgeid | string | Unique identifier |
result.acknowledges.userid | string | Unique identifier |
result.acknowledges.clock | string | Result of the operation |
result.acknowledges.message | string | Result of the operation |
result.acknowledges.action | string | Result of the operation |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 6 Mar 2025 20:37:23 GMT"},"reason":"OK","json_body":{"jsonrpc":"2.0","result":[{},{}],"id":1}}
Get Trigger
Retrieves Zabbix triggers based on specified parameters, with role-based permissions for access control.
Endpoint
- URL: /zabbix/api_jsonrpc.php
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
jsonrpc | string | Optional | Version of the JSON-RPC protocol. Default value is 2.0. |
id | number | Optional | ID of the request. |
method | string | Optional | Method to call. |
params | object | Optional | Parameters for the Method. |
params.triggerids | array | Optional | Return only triggers with the given IDs. |
params.groupids | array | Optional | Return only triggers that belong to hosts or templates from the given host groups or template groups. |
params.templateids | array | Optional | Return only triggers that belong to the given templates. |
params.hostids | array | Optional | Return only triggers that belong to the given hosts. |
params.itemids | array | Optional | Return only triggers that contain the given items. |
params.functions | array | Optional | Return only triggers that use the given functions. Refer to the supported function page for a list of supported functions. |
params.group | string | Optional | Return only triggers that belong to hosts or templates from the host group or template group with the given name. |
params.host | string | Optional | Return only triggers that belong to host with the given technical name. |
params.inherited | boolean | Optional | If set to true return only triggers inherited from a template. |
params.templated | boolean | Optional | If set to true return only triggers that belong to templates. |
params.dependent | boolean | Optional | If set to true return only triggers that have dependencies. If set to false return only triggers that do not have dependencies. |
params.monitored | boolean | Optional | Return only enabled triggers that belong to monitored hosts and contain only enabled items. |
params.active | boolean | Optional | Return only enabled triggers that belong to monitored hosts. |
params.maintenance | boolean | Optional | If set to true return only enabled triggers that belong to hosts in maintenance. |
params.withUnacknowledgedEvents | boolean | Optional | Return only triggers that have unacknowledged events. |
params.withAcknowledgedEvents | boolean | Optional | Return only triggers with all events acknowledged. |
params.withLastEventUnacknowledged | boolean | Optional | Return only triggers with the last event unacknowledged. |
params.skipDependent | boolean | Optional | Skip triggers in a problem state that are dependent on other triggers. Note that the other triggers are ignored if disabled, have disabled items or disabled item hosts. |
params.lastChangeSince | string | Optional | Return only triggers that have changed their state after the given time. |
params.lastChangeTill | string | Optional | Return only triggers that have changed their state before the given time. |
params.only_true | boolean | Optional | Return only triggers that have recently been in a problem state. |
Input Example
{"jsonrpc":2.0,"id":123,"method":"trigger.get","params":{"triggerids":["string"],"groupids":["string"],"templateids":["string"],"hostids":["string"],"itemids":["string"],"functions":["string"],"group":"string","host":"string","inherited":true,"templated":true,"dependent":true,"monitored":true,"active":true,"maintenance":true,"withUnacknowledgedEvents":true,"withAcknowledgedEvents":true,"withLastEventUnacknowledged":true,"skipDependent":true,"lastChangeSince":"string","lastChangeTill":"string","only_true":true,"min_severity":123,"evaltype":123,"tags":[{"tag":"string","value":"string","operator":"string"}],"expandComment":true,"expandDescription":true,"expandExpression":true,"selectHostGroups":"string","selectHosts":"string","selectItems":"string","selectFunctions":"string","selectDependencies":"string","selectDiscoveryRule":"string","selectLastEvent":"string","selectTags":"string","selectTemplateGroups":"string","selectTriggerDiscovery":"string","filter":{},"limitSelects":123,"sortfield":["string"],"countOutput":true,"editable":true,"excludeSearch":true,"limit":123,"output":["string"],"preservekeys":true,"search":{},"searchByAny":true,"searchWildcardsEnabled":true,"sortorder":"ASC"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
jsonrpc | string | Output field: jsonrpc |
result | array | Result of the operation |
result.triggerid | string | Unique identifier |
result.expression | string | Result of the operation |
result.description | string | Result of the operation |
result.url | string | URL endpoint for the request |
result.status | string | Status value |
result.value | string | Value for the parameter |
result.priority | string | Result of the operation |
result.lastchange | string | Result of the operation |
result.comments | string | Result of the operation |
result.error | string | Result of the operation |
result.templateid | string | Unique identifier |
result.type | string | Type of the resource |
result.state | string | Result of the operation |
result.flags | string | Result of the operation |
result.recovery_mode | string | Result of the operation |
result.recovery_expression | string | Result of the operation |
result.correlation_mode | string | Result of the operation |
result.correlation_tag | string | Result of the operation |
result.manual_close | string | Result of the operation |
result.opdata | string | Response data |
result.event_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"content-length":"140","content-type":"application/json","Date":"Thu, 6 Mar 2025 20:37:23 GMT"},"reason":"OK","json_body":{"jsonrpc":"2.0","result":[{}],"id":1}}
Response Headers
Header | Description | Example |
|---|---|---|
content-length | The length of the response body in bytes | 140 |
content-type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 6 Mar 2025 20:37:23 GMT |