[v3,5/5] zabbix_agentd: Add IPFire specific userparameters
Commit Message
Provide IPFire specific items for the Zabbix server to monitor:
- ipfire.net.gateway.pingtime: Internet Line Quality
- ipfire.net.gateway.ping: Internet connection
- ipfire.net.fw.hits.raw: JSON formatted list of Firewall hits/chain
- ipfire.dhcpd.clients: Number of active DHCP leases
- ipfire.captive.clients: Number of Captive Portal clients
Signed-off-by: Robin Roevens <robin.roevens@disroot.org>
---
config/rootfiles/packages/zabbix_agentd | 1 +
config/zabbix_agentd/sudoers | 2 +-
config/zabbix_agentd/userparameter_ipfire.conf | 18 ++++++++++++++++++
lfs/zabbix_agentd | 5 ++++-
src/paks/zabbix_agentd/uninstall.sh | 2 +-
5 files changed, 25 insertions(+), 3 deletions(-)
create mode 100644 config/zabbix_agentd/userparameter_ipfire.conf
@@ -6,6 +6,7 @@ etc/zabbix_agentd/scripts
etc/zabbix_agentd/zabbix_agentd.conf.ipfirenew
etc/zabbix_agentd/zabbix_agentd.d
etc/zabbix_agentd/zabbix_agentd.d/userparameter_pakfire.conf
+etc/zabbix_agentd/zabbix_agentd.d/userparameter_ipfire.conf
usr/bin/zabbix_get
usr/bin/zabbix_sender
#usr/lib/modules
@@ -14,4 +14,4 @@
# Append / edit the following list of commands to fit your needs:
#
Defaults:zabbix !requiretty
-zabbix ALL=(ALL) NOPASSWD: /opt/pakfire/pakfire status
+zabbix ALL=(ALL) NOPASSWD: /opt/pakfire/pakfire status, /usr/sbin/fping, /usr/local/bin/getipstat
new file mode 100644
@@ -0,0 +1,18 @@
+# IPFire specific configuration file
+#
+#
+# DO NOT MODIFY - Changes will be overwritten when zabbix_agentd addon is
+# updated.
+#
+# Parameters for monitoring IPFire specific metrics
+#
+# Internet Gateway ping timings, can be used to measure "Internet Line Quality"
+UserParameter=ipfire.net.gateway.pingtime,sudo /usr/sbin/fping -c 3 gateway 2>&1 | tail -n 1 | awk '{print $NF}' | cut -d '/' -f2
+# Internet Gateway availability, can be used to check Internet connection
+UserParameter=ipfire.net.gateway.ping,sudo /usr/sbin/fping -q -r 3 gateway; [ ! $? ]; echo $?
+# Firewall Filter Forward chain drops in bytes/chain (JSON), can be used for discovery of firewall chains and monitoring of firewall hits on each chain
+UserParameter=ipfire.net.fw.hits.raw,sudo /usr/local/bin/getipstat -xf | grep "\/\* DROP_.* \*\/$" | awk 'BEGIN { ORS = ""; print "["} { printf "%s{\"chain\": \"%s\", \"bytes\": \"%s\"}", separator, substr($11, 6), $2; separator = ", "; } END { print"]" }'
+# Number of currently Active DHCP leases
+UserParameter=ipfire.dhcpd.clients,grep -s -E 'lease|bind' /var/state/dhcp/dhcpd.leases | sed ':a;/{$/{N;s/\n//;ba}' | grep "state active" | wc -l
+# Number of Captive Portal clients
+UserParameter=ipfire.captive.clients,awk -F ',' 'length($2) == 17 {sum += 1} END {if (length(sum) == 0) print 0; else print sum}' /var/ipfire/captive/clients
\ No newline at end of file
@@ -33,7 +33,8 @@ DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = zabbix_agentd
PAK_VER = 5
-DEPS =
+
+DEPS = fping
###############################################################################
# Top-level Rules
@@ -97,6 +98,8 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
/etc/zabbix_agentd/zabbix_agentd.conf.ipfirenew
install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_pakfire.conf \
/etc/zabbix_agentd/zabbix_agentd.d/userparameter_pakfire.conf
+ install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_ipfire.conf \
+ /etc/zabbix_agentd/zabbix_agentd.d/userparameter_ipfire.conf
# Create directory for additional agent modules
-mkdir -pv /usr/lib/zabbix
@@ -27,7 +27,7 @@ stop_service ${NAME}
# Remove .ipfirenew files in advance so they won't be included in backup
rm -rfv /etc/zabbix_agentd/zabbix_agentd.conf.ipfirenew /etc/sudoers.d/zabbix.ipfirenew
# Remove IPFire provided userparameter config files in advance
-rm -rfv /etc/zabbix_agentd/zabbix_agentd.d/userparameter_pakfire.conf
+rm -rfv /etc/zabbix_agentd/zabbix_agentd.d/userparameter_pakfire.conf /etc/zabbix_agentd/zabbix_agentd.d/userparameter_ipfire.conf
make_backup ${NAME}
remove_files