From patchwork Fri Jul 31 08:49:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Robin Roevens X-Patchwork-Id: 10085 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hBKdt41Ysz3wb0 for ; Fri, 31 Jul 2026 08:55:14 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hBKdk2k58z1Mn for ; Fri, 31 Jul 2026 08:55:06 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hBKcb3Xt9z36gx for ; Fri, 31 Jul 2026 08:54:07 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hBKcX6wZwz36Wd for ; Fri, 31 Jul 2026 08:54:04 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4hBKcN4htGz7b for ; Fri, 31 Jul 2026 08:53:56 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=U9Hkggwj; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1785488036; b=jZ8p1q3UwTu3Sslwjz2DeD1S0Xk8PmV/jUgHUfWKJGEKlmltkq3Xs1mqxBR3SqnIBizV9k XoxhMMNM3C0shVqGMmRTKHaDDrUGaQTgkhTc5xgbv1A0XC2I7/wwDMFkBsL58n4RDVmuE0 1H4EUiWpDOPobER0bYW7Mk8UHRUgQ24NI2jb/6lchwWGNGXmS1jkueSEGtdah1cKfLGFzC LLZvDXKntLgTBz1ixIirCOgSyoePc1N0TUlr3ECv+gqfzGIsrQx4WjOummYE45XUJ6IDnr s/XardfR8HI8cmitPwMYkbkiJLdSdnqhsij3a8NJ7AboJ6sZodPscmjxMc1klA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1785488036; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=5m2uwzrfJpjM4rsh+yt5Win0asJo1Wa2HEy96Kdzhtg=; b=j/URTi4eC0pwZNaO4ArKDH7UKrq1IRa722Lgpnlyi/03jaxySxbIVqzQjiwlbgA22d8zJT Xhx8Zjd84l0DlRjFFEMTrLtI1vTCFO4DsLLBqXXSyX98c8mQvW1DgFFFh76BJLETUQjI1M LuSM+rJ8yq5s1p4utUj6FcQu7EaiWMTft5vVsPgpCpixPok3/ujBfRLACI33nU6Qj0IlBr 4nBwqEypjRtWYrz2XFLxKhFVjvOwysMBTYs/PdC1xlbiNMt2h8iPbdVuKyNxaQzN2LofdS nvTCml3h+TX804meCbNDxiN6m9fyPzhpMAiOgKdECeC6vpEdbhnf6dN90yVBMA== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=U9Hkggwj; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org Received: from mail01.layka.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 3AC1B42124 for ; Fri, 31 Jul 2026 10:53:51 +0200 (CEST) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id QifUD6uWLbsc for ; Fri, 31 Jul 2026 10:53:50 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1785488030; bh=QaS/XFJUccQ0WhyAf2xPd1Xk+ncYbb4gaiaS86zirZc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U9HkggwjyK7i8pDQUomVcHeXQvK/qhK8LHI18jSO+XKPWDoDpogdHsRIu9OKcCiHi XwU4b4dggUL6k9EP1lwcxshvm7GOwbVic0CAH2pHzoPDbrm+IHNXy9G1bfv2818+7V thDwF6s/OLaC6fqnbrDUZg9K5dxtoNmDawAMUxsbxj0qQB255jhZSsigvqDHlsO791 VQ8mdTSTibQLlUJxW6sqmt1lmzYZE8NBVlkvu7/j9jbNew4uIj4ODrQmmZw25WhHFu FK2rGr+J8uaw/moJs6xbufyFU/8bBxcqE5W59BFw0pNVyvOwjfVqYYXTGCzCW/rl4a ykJT9gNPyJA+g== Received: from chojin.roevenslambrechts.be (chojin.roevenslambrechts.be [192.168.0.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (no client certificate requested) (Authenticated sender) by hachiman (MailScanner Milter) with SMTP id 2F8EF586AFE; Fri, 31 Jul 2026 10:53:46 +0200 (CEST) From: Robin Roevens To: development@lists.ipfire.org Cc: Robin Roevens Subject: [PATCH] zabbix_agentd: Add support for suricata metrics Date: Fri, 31 Jul 2026 10:49:17 +0200 Message-ID: <20260731085343.1085178-2-robin.roevens@disroot.org> In-Reply-To: <20260731085343.1085178-1-robin.roevens@disroot.org> References: <20260731085343.1085178-1-robin.roevens@disroot.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 X-RoevensLambrechts-MailScanner-ID: 2F8EF586AFE.AD543 X-RoevensLambrechts-MailScanner: Found to be clean X-RoevensLambrechts-MailScanner-From: robin.roevens@disroot.org X-RoevensLambrechts-MailScanner-Watermark: 1786092828.59609@z4ygnSn2kwH7vvqMzJJ/tQ X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hBKcN4htGz7b X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.63 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.65)[disroot.org:s=mail]; MID_CONTAINS_FROM(1.00)[]; DKIM_REPUTATION(-0.92)[-0.92145628873234]; SPF_REPUTATION_HAM(-0.66)[-0.65782129252818]; R_MISSING_CHARSET(0.50)[]; DMARC_POLICY_ALLOW(-0.50)[disroot.org,reject]; R_SPF_ALLOW(-0.20)[+a]; MX_GOOD(-0.10)[disroot.org]; MIME_GOOD(-0.10)[text/plain]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; TO_DN_SOME(0.00)[]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; ARC_NA(0.00)[]; MISSING_XM_UA(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; RCVD_COUNT_THREE(0.00)[3]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; IP_REPUTATION_HAM(0.00)[asn: 50673(-0.36), country: NL(-0.01), ip: 178.21.23.139(-0.90)]; TO_MATCH_ENVRCPT_SOME(0.00)[]; RCVD_TLS_LAST(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; DKIM_TRACE(0.00)[disroot.org:+] Add new UserParameters: - suricata.counters.get: for retrieval of suricata counters using suricatasc. - suricata.version for retrieval of current suricata version using suricatasc Add both suricatasc commands to sudoers for Zabbix agent to be able to query suricata. Signed-off-by: Robin Roevens --- config/rootfiles/packages/zabbix_agentd | 1 + config/zabbix_agentd/sudoers | 1 + config/zabbix_agentd/userparameter_suricata.conf | 3 +++ lfs/zabbix_agentd | 2 ++ 4 files changed, 7 insertions(+) create mode 100644 config/zabbix_agentd/userparameter_suricata.conf diff --git a/config/rootfiles/packages/zabbix_agentd b/config/rootfiles/packages/zabbix_agentd index 7f1f39b64..d73d9a0f2 100644 --- a/config/rootfiles/packages/zabbix_agentd +++ b/config/rootfiles/packages/zabbix_agentd @@ -24,6 +24,7 @@ var/ipfire/zabbix_agentd/userparameters/userparameter_ovpn.conf var/ipfire/zabbix_agentd/userparameters/userparameter_gateway.conf var/ipfire/zabbix_agentd/userparameters/userparameter_wireguard.conf var/ipfire/zabbix_agentd/userparameters/userparameter_locationdb.conf +var/ipfire/zabbix_agentd/userparameters/userparameter_suricata.conf var/ipfire/zabbix_agentd/scripts var/ipfire/zabbix_agentd/scripts/ipfire_certificate_detail.sh var/ipfire/zabbix_agentd/scripts/ipfire_services.pl diff --git a/config/zabbix_agentd/sudoers b/config/zabbix_agentd/sudoers index 13edfcce9..8669b0361 100644 --- a/config/zabbix_agentd/sudoers +++ b/config/zabbix_agentd/sudoers @@ -13,3 +13,4 @@ zabbix ALL=(ALL) NOPASSWD: /usr/local/bin/openvpnctrl rw log, /usr/local/bin/wir zabbix ALL=(ALL) NOPASSWD: /var/ipfire/zabbix_agentd/scripts/ipfire_certificate_detail.sh zabbix ALL=(ALL) NOPASSWD: /var/ipfire/zabbix_agentd/scripts/ipfire_services.pl zabbix ALL=(ALL) NOPASSWD: /usr/bin/curl -s --unix-socket /var/run/knot-resolver/kres-api.sock http\://localhost/metrics/json +zabbix ALL=(ALL) NOPASSWD: /usr/bin/suricatasc --command=dump-counters, /usr/bin/suricatasc --command=version \ No newline at end of file diff --git a/config/zabbix_agentd/userparameter_suricata.conf b/config/zabbix_agentd/userparameter_suricata.conf new file mode 100644 index 000000000..b8f8c5b98 --- /dev/null +++ b/config/zabbix_agentd/userparameter_suricata.conf @@ -0,0 +1,3 @@ +# Suricata statistics +UserParameter=suricata.counters.get,sudo /usr/bin/suricatasc --command=dump-counters +UserParameter=suricata.version,sudo /usr/bin/suricatasc --command=version \ No newline at end of file diff --git a/lfs/zabbix_agentd b/lfs/zabbix_agentd index cbf4b246c..e696828b5 100644 --- a/lfs/zabbix_agentd +++ b/lfs/zabbix_agentd @@ -118,6 +118,8 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) /var/ipfire/zabbix_agentd/userparameters/userparameter_wireguard.conf install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_locationdb.conf \ /var/ipfire/zabbix_agentd/userparameters/userparameter_locationdb.conf + install -v -m 644 $(DIR_SRC)/config/zabbix_agentd/userparameter_suricata.conf \ + /var/ipfire/zabbix_agentd/userparameters/userparameter_suricata.conf # Install IPFire-specific Zabbix Agent scripts -mkdir -pv /var/ipfire/zabbix_agentd/scripts