How to Install and Configure Zabbix on Debian 9 Linux
9 min read
Zabbix is a mature open-source software for monitoring networks and applications. Zabbix can collects metrics from various networks devices, systems, and applications. In case of any failures, Zabbix will send notification alerts via various methods.
Zabbix supports both agent-based and agent-less monitoring. The Zabbix agent has a small footprint and can run on various platforms, including Linux, UNIX, macOS, and Windows.
This tutorial explains how to install and configure the latest version of Zabbix 4.0 on a Debian 9 Linux server using MySQL as a database back-end. We will also show you how to install the Zabbix agent on a remote host and add the host to the Zabbix server.
The user you are logged in as must have sudo privileges to be able to install packages.
Creating MySQL Database
If you don’t have MariaDB installed on your Debian server, install it by following these instructions .
Login to the MySQL console:
Run the following SQL statement to create a new database :
CREATE DATABASE zabbix CHARACTER SET utf8 collate utf8_bin;
Next, create a MySQL user account and grant access to the database :
GRANT ALL ON zabbix.* TO 'zabbix'@'localhost' IDENTIFIED BY 'change-with-strong-password';
change-with-strong-passwordwith a strong password.
Once done, exit the MySQL console by typing:
Installing Zabbix on Debian
At the time of writing this article, the latest stable version of Zabbix is version 4.0. The Zabbix packages available in Debian repositories are often outdated so we’ll use the official Zabbix repository .
1. Installing Zabbix
Download the latest Zabbix repository
.deb package with following wget command
Once the file is downloaded, install it with:
sudo apt install ./zabbix-release_4.0-2+stretch_all.deb
Update the packages list and install the Zabbix server, the web frontend with MySQL database support and the Zabbix agent:
sudo apt update
sudo apt install zabbix-server-mysql zabbix-frontend-php zabbix-agent
2. Configuring PHP for Zabbix frontend
An Apache configuration file with all the required Apache and PHP settings is created during the installation.
Open the configuration file, uncomment the timezone line and change it to your time zone. You can find the complete list of time zones supported by PHP here .
... <IfModule mod_php7.c> php_value max_execution_time 300 php_value memory_limit 128M php_value post_max_size 16M php_value upload_max_filesize 2M php_value max_input_time 300 php_value max_input_vars 10000 php_value always_populate_raw_post_data -1 php_value date.timezone America/Denver </IfModule> ...
Once done, save the file and restart the Apache service for changes to be activated.
sudo systemctl restart apache2
3. Configuring the MySQL Database For Zabbix Server
Import the MySQL dump file which includes an initial schema and data for the Zabbix server with MySQL.
gunzip < /usr/share/doc/zabbix-server-mysql/create.sql.gz | mysql -uzabbix -p zabbix
When prompted enter the user password you created previously. On success, no output is given.
Next, open the Zabbix configuration and set the database password:
sudo nano /etc/zabbix/zabbix_server.conf
Search for the following section, uncomment the
DBPassword directive and add the database password.
... ### Option: DBPassword # Database password. # Comment this line if no password is used. # # Mandatory: no # Default: DBPassword=change-with-strong-password ...
Save and close the file.
Restart and enable the Zabbix server and agent services:
sudo systemctl restart zabbix-server zabbix-agent
sudo systemctl enable zabbix-server zabbix-agent
Verify that the Zabbix server is running:
sudo systemctl status zabbix-server
● zabbix-server.service - Zabbix Server Loaded: loaded (/lib/systemd/system/zabbix-server.service; enabled; vendor preset: enabled) Active: active (running) since Mon 2019-01-28 15:37:21 CST; 35s ago Main PID: 27632 (zabbix_server) CGroup: /system.slice/zabbix-server.service ...
Installing and Configuring Zabbix Frontend
Zabbix web interface is written in PHP and allows you to configure the server, view gathered data and add hosts you want to monitor.
TO start the installation, open your favorite browser
and type your server’s domain name or public IP address followed by
On the first screen, you will be presented with a welcome message. Click
Next step to continue.
Next, you will see an information page with a list of the necessary PHP packages required to run the Zabbix Frontend. Scroll down to verify that everything is installed and set up correctly. Once verified, click
Next step to proceed.
On the next screen, the setup wizard will ask you to enter the database connection details. Enter the MySQL user and database details you previously created.
Entering a name for the server is optional. Enter it if you have more than one Zabbix monitoring servers. If provided, it will be displayed in the menu bar and page titles.
Next step to continue.
On the next screen, you will see the pre-installation summary.
Next step and once the installation is completed you will be taken to a page showing that Zabbix web interface has been installed. To access your Zabbix login page click on the
The default user is “Admin” and the password is “zabbix”. Enter the username and password and click on the
Log in button.
Once you log in, you will be redirected to the Zabbix administration dashboard.
From here, you can start customizing your Zabbix installation and adding new hosts. First, you need to change the current password. To do that navigate to the user profile page by clicking on the profile icon on the top navigation.
Adding a New Host to Zabbix Server
The procedure for adding a new host for monitoring to the Zabbix server includes two steps.
First, you need to install the Zabbix agent on the remote host and then add the host to the Zabbix server through the web interface.
Installing the Zabbix agent
This tutorial assumes that the host machine also uses Debian 9.
Same as when installing the Zabbix server, run the following commands to enable the Zabbix repository:
sudo apt install ./zabbix-release_4.0-2+stretch_all.deb
Update the packages list and install the Zabbix agent package:
sudo apt update
sudo apt install zabbix-agent
Zabbix supports two methods for server-client communication encryption, Preshared Key (PSK) and certificate-based encryption. In this guide, we will use the pre-shared keys (PSK) method to secure the connection between the server and agent.
Run to following command to generate a pre-shared key and save it to a file:
openssl rand -hex 32 | sudo tee /etc/zabbix/zabbix_agentd.psk
The PSK key will look something like this:
Open the Zabbix agent configuration file:
sudo nano /etc/zabbix/zabbix_agentd.conf
Search for the
Server IP Address and change it from the default value to your Zabbix server IP:
... ### Option: Server # List of comma delimited IP addresses, optionally in CIDR notation, or DNS names of Zabbix servers and Zabbix proxies. # Incoming connections will be accepted only from the hosts listed here. # If IPv6 support is enabled then '127.0.0.1', '::127.0.0.1', '::ffff:127.0.0.1' are treated equally # and '::/0' will allow any IPv4 or IPv6 address. # '0.0.0.0/0' can be used to allow any IPv4 address. # Example: Server=127.0.0.1,192.168.1.0/24,::1,2001:db8::/32,zabbix.example.com # # Mandatory: yes, if StartAgents is not explicitly set to 0 # Default: # Server= Server=127.0.0.1 ...
Next, find the
TSLConnect option, uncomment it and set it to
... ### Option: TLSConnect # How the agent should connect to server or proxy. Used for active checks. # Only one value can be specified: # unencrypted - connect without encryption # psk - connect using TLS and a pre-shared key # cert - connect using TLS and a certificate # # Mandatory: yes, if TLS certificate or PSK parameters are defined (even for 'unencrypted' connection) # Default: TLSConnect=psk ...
TLSAccept option, uncomment it and set it to
... ### Option: TLSAccept # What incoming connections to accept. # Multiple values can be specified, separated by comma: # unencrypted - accept connections without encryption # psk - accept connections secured with TLS and a pre-shared key # cert - accept connections secured with TLS and a certificate # # Mandatory: yes, if TLS certificate or PSK parameters are defined (even for 'unencrypted' connection) # Default: TLSAccept=psk ...
Next, find the
TLSPSKIdentity option, uncomment it and set it to
PSK 001 The value needs to be a unique string:
... ### Option: TLSPSKIdentity # Unique, case sensitive string used to identify the pre-shared key. # # Mandatory: no # Default: TLSPSKIdentity=PSK 001 ...
Finally, locate the
TLSPSKFile option, uncomment it and set it to point to the previously created pre-shared key:
... ### Option: TLSPSKFile # Full pathname of a file containing the pre-shared key. # # Mandatory: no # Default: TLSPSKFile=/etc/zabbix/zabbix_agentd.psk ...
Once done, save and close the file.
Start the Zabbix agent service and set it to start at boot time with:
sudo systemctl start zabbix-agent
sudo systemctl enable zabbix-agent
Next, add a firewall rule that enables traffic from your Zabbix server on TCP port
Assuming you are using
to manage your firewall and you want to allow access from the
192.168.121.70 IP address you would run the following command:
sudo ufw allow proto tcp from 192.168.121.70 to any port 10050
Set up a New Host
Now that the agent on the remote host you want to monitor is installed and configured the next step is to register the host on the Zabbix server.
Log in to the Zabbix Server web interface as the admin user:
Once inside, in the top navigation bar click on the
Configuration, and then
Next, click on the blue
Create host button in the top right corner of the screen and the host configuration page will open:
Enter the Hostname and the IP Address of the remote host machine you want to monitor. Add the host to one or multiple groups by selecting the group from the list, or enter a non-existing group name to create a new one. The
Linux Servers group is a good choice.
Once done, click the
Templates tab. Select the
Template OS Linux and click on the
Add link to add the template to the host.
Next, click on the
Encryption tab. Select PSK for both
Connections to host and
Connections from host.
PSK identity value to
PSK 001, the value of the
TLSPSKIdentity option of the Zabbix agent you configured in the previous step.
PSK value filed add the key you generated for the Zabbix agent, the one stored in the
Finally, to add the host click on the blue Add
You have successfully installed the latest Zabbix on your Debian system and learned how to add new hosts that you want to monitor.
You should now check the Zabbix Documentation and learn more about how to configure and use Zabbix.
If you hit a problem or have feedback, leave a comment below.