3 Passive and active agent checks

Overview

This section provides details on passive and active checks performed by Zabbix agent.

Zabbix uses a JSON based communication protocol for communicating with Zabbix agent.

Passive checks

A passive check is a simple data request. Zabbix server or proxy asks for some data (for example, CPU load) and Zabbix agent sends back the result to the server.

Server request

For definition of header and data length please refer to protocol details.

  1. <item key>

Agent response

  1. <DATA>[\0<ERROR>]

Above, the part in square brackets is optional and is only sent for not supported items.

For example, for supported items:

  1. Server opens a TCP connection

  2. Server sends <HEADER><DATALEN>agent.ping

  3. Agent reads the request and responds with <HEADER><DATALEN>1

  4. Server processes data to get the value, ‘1’ in our case

  5. TCP connection is closed

For not supported items:

  1. Server opens a TCP connection

  2. Server sends <HEADER><DATALEN>vfs.fs.size[/nono]

  3. Agent reads the request and responds with <HEADER><DATALEN>ZBX_NOTSUPPORTED\0Cannot obtain filesystem information: [2] No such file or directory

  4. Server processes data, changes item state to not supported with the specified error message

  5. TCP connection is closed

Active checks

Active checks require more complex processing. The agent must first retrieve from the server(s) a list of items for independent processing.

The servers to get the active checks from are listed in the ‘ServerActive’ parameter of the agent configuration file. The frequency of asking for these checks is set by the ‘RefreshActiveChecks’ parameter in the same configuration file. However, if refreshing active checks fails, it is retried after hardcoded 60 seconds.

The agent then periodically sends the new values to the server(s).

If an agent is behind the firewall you might consider using only Active checks because in this case you wouldn’t need to modify the firewall to allow initial incoming connections.

Getting the list of items

Agent request

  1. {
  2. "request":"active checks",
  3. "host":"<hostname>"
  4. }

Server response

  1. {
  2. "response":"success",
  3. "data":[
  4. {
  5. "key":"log[/home/zabbix/logs/zabbix_agentd.log]",
  6. "delay":30,
  7. "lastlogsize":0,
  8. "mtime":0
  9. },
  10. {
  11. "key":"agent.version",
  12. "delay":600,
  13. "lastlogsize":0,
  14. "mtime":0
  15. },
  16. {
  17. "key":"vfs.fs.size[/nono]",
  18. "delay":600,
  19. "lastlogsize":0,
  20. "mtime":0
  21. }
  22. ]
  23. }

The server must respond with success. For each returned item, all properties key, delay, lastlogsize and mtime must exist, regardless of whether item is a log item or not.

For example:

  1. Agent opens a TCP connection

  2. Agent asks for the list of checks

  3. Server responds with a list of items (item key, delay)

  4. Agent parses the response

  5. TCP connection is closed

  6. Agent starts periodical collection of data

Note that (sensitive) configuration data may become available to parties having access to the Zabbix server trapper port when using an active check. This is possible because anyone may pretend to be an active agent and request item configuration data; authentication does not take place unless you use encryption options.

Sending in collected data

Agent sends

  1. {
  2. "request":"agent data",
  3. "session": "12345678901234567890123456789012",
  4. "data":[
  5. {
  6. "host":"<hostname>",
  7. "key":"agent.version",
  8. "value":"2.4.0",
  9. "id": 1,
  10. "clock":1400675595,
  11. "ns":76808644
  12. },
  13. {
  14. "host":"<hostname>",
  15. "key":"log[/home/zabbix/logs/zabbix_agentd.log]",
  16. "lastlogsize":112,
  17. "value":" 19845:20140621:141708.521 Starting Zabbix Agent [<hostname>]. Zabbix 2.4.0 (revision 50000).",
  18. "id": 2,
  19. "clock":1400675595,
  20. "ns":77053975
  21. },
  22. {
  23. "host":"<hostname>",
  24. "key":"vfs.fs.size[/nono]",
  25. "state":1,
  26. "value":"Cannot obtain filesystem information: [2] No such file or directory",
  27. "id": 3,
  28. "clock":1400675595,
  29. "ns":78154128
  30. }
  31. ],
  32. "clock": 1400675595,
  33. "ns": 78211329
  34. }

A virtual ID is assigned to each value. Value ID is a simple ascending counter, unique within one data session (identified by the session token). This ID is used to discard duplicate values that might be sent in poor connectivity environments.

Server response

  1. {
  2. "response":"success",
  3. "info":"processed: 3; failed: 0; total: 3; seconds spent: 0.003534"
  4. }

If sending of some values fails on the server (for example, because host or item has been disabled or deleted), agent will not retry sending of those values.

For example:

  1. Agent opens a TCP connection

  2. Agent sends a list of values

  3. Server processes the data and sends the status back

  4. TCP connection is closed

Note how in the example above the not supported status for vfs.fs.size[/nono] is indicated by the “state” value of 1 and the error message in “value” property.

Error message will be trimmed to 2048 symbols on server side.

Older XML protocol

Zabbix will take up to 16 MB of XML Base64-encoded data, but a single decoded value should be no longer than 64 KB otherwise it will be truncated to 64 KB while decoding.