From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hB0Gm3TsGz37DN for ; Thu, 30 Jul 2026 19:52:32 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hB0GK4kFKz36X3 for ; Thu, 30 Jul 2026 19:52:09 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4hB0G936bJz45w for ; Thu, 30 Jul 2026 19:52:01 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=BzmHuCGg; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1785441121; b=ccVZ79i7wAMVDYDDihct9NjtTEEP3uKsufvyrOkZHm0v1peIF1xBhMd7E/QoBmq5o3BaY5 FSC9HcO7QVARPXTz6fv/KmEG4fLXXNhjecpPs3v/M4bW4bjzKCN3+LR6BK94Xn/auqPyGW 4o9GQq/lzlwQg0MIegRbqKOcXiB1ZnQsvjflug/Vbg7MMVdwPc+aHtQN7Gr3VNg7DF1q3S i53Zz8I6Vr6u7jlL5/u5103MvXVWA1J6NfxQqAIwTUGXfX9alSWb0k4zYLJvLedrk0gveR gkIlx9Xua+Zp4OM0WSjqt1ynf7A9yYzqP34tFcCD3cvGnO+s1KjkrRTUO/q40A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1785441121; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:dkim-signature; bh=CKsovQZ6jS0BX2C3Iz9tKcW7wgDVQr9mHv1ma1JiwGU=; b=FktLQ+f4JS0rFzK77Dpy15LoWNDGEdqoyNJ4SOZHySVOWcDbi4Abk48u9qptITTgi9KvUp aSvtkxV4KtMnyz4kBitfUJJS+5aJ000VGgpNnYoCtdMwQuLhlVg5FkzAkfMxMAFJMKDQdG EO/aXPmptTknQi34R/NAQynT65A1qeDPE8xGvhMCigryc/0Mdz444PCgxz+IUj6w6+mrny PS3+XM/hBT1Se0In7k8R2R/XzO2qIE8P74VHTNn0VCh0UYX70Qc6ibQSoyNtr4e7Heegtn VOSEzhriuV7pBFne+SOfbllKLdQNDhPZ78muHR3Hd1jD0XE7PZKxRMdB2atWVA== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=BzmHuCGg; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org Received: from mail01.layka.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 0FFF941C12 for ; Thu, 30 Jul 2026 21:52:01 +0200 (CEST) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id 8IJnYTh3qC2a for ; Thu, 30 Jul 2026 21:52:00 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1785441120; bh=l7ZVfsul1pNwSDsIThnFmEDq+NENd/sJb2ZoVgpHYL0=; h=From:To:Cc:Subject:Date; b=BzmHuCGgd1FduvHyz5nnb+qS0hIkHIPvU6Bu3RAjmxZ3+uwLr/cBA6A5ru7Ba2o6V XGAbRclI7VXBF1DSjVYDUtfTG24gsikCXIh/z+rJgbE3ZWZweGjShyA/OzqFcIp4Eo Nx8PhgjsUFQSx3WhaX/adu47sKoDi+UDtreZvavWk7osUu1XGVn4ew958R4YGi9wi9 JCM3+As3ajvK5g6BcQ5fiXfsaQW0mlH0hPUkL2HUHms08eW8gB+6cXYh/FyalylHvM qta5jkB3ohGmDTVnYrIFCqQWH8ID3UPuBlDX957Wvv0kSVON5hR/ctx327Aqc53XY3 PoHpAvcgjvqLg== Received: from chojin.roevenslambrechts.be (chojin.roevenslambrechts.be [192.168.0.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (no client certificate requested) (Authenticated sender) by hachiman (MailScanner Milter) with SMTP id 0972C585FD7; Thu, 30 Jul 2026 21:51:52 +0200 (CEST) From: Robin Roevens To: development@lists.ipfire.org Cc: Robin Roevens Subject: [PATCH 0/5] Add Zabbix functionality to suricata-reporter Date: Thu, 30 Jul 2026 21:15:51 +0200 Message-ID: <20260730195148.3278295-1-robin.roevens@disroot.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-RoevensLambrechts-MailScanner-ID: 0972C585FD7.AD543 X-RoevensLambrechts-MailScanner: Found to be clean X-RoevensLambrechts-MailScanner-From: robin.roevens@disroot.org X-RoevensLambrechts-MailScanner-Watermark: 1786045915.27566@eYlYf0NU0mCvZAU8VLM/XQ X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hB0G936bJz45w X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.63 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.65)[disroot.org:s=mail]; MID_CONTAINS_FROM(1.00)[]; DKIM_REPUTATION(-0.92)[-0.92153870218341]; SPF_REPUTATION_HAM(-0.65)[-0.65402885146808]; DMARC_POLICY_ALLOW(-0.50)[disroot.org,reject]; R_MISSING_CHARSET(0.50)[]; R_SPF_ALLOW(-0.20)[+a:c]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.10)[disroot.org]; RCPT_COUNT_TWO(0.00)[2]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; IP_REPUTATION_HAM(0.00)[asn: 50673(0.00), country: NL(-0.01), ip: 178.21.23.139(0.00)]; ARC_NA(0.00)[]; TO_DN_SOME(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_COUNT_THREE(0.00)[3]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_SOME(0.00)[]; MISSING_XM_UA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[disroot.org:+]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; FROM_HAS_DN(0.00)[] Hi all, As discussed here earlier, I've worked on implementing sending Suricata alerts straight to Zabbix from within suricata-reporter instead of trying to parse the suricata logging separately using the Zabbix agent. For this I use the zabbix-utils python library, which I submited here also as a separate pak (but meanwhile already requires an update, which I will post soon). This set of patches makes suricata-reporter able to directly communicate to a Zabbix server without having the zabbix_agentd pak installed, sending suricata alerts in real-time. As Zabbix supports sending items in bulk, I have opted to create an async background task that will send all events from last 1 second in bulk so that even in the case that there are hundreds of incoming alerts, Zabbix server is only contacted once per second. When for some reason sending to Zabbix server fails, it will be retried 3 times and then the background task will be suspended until a new suricata event comes in. That will wake the task again and retry to send all pending events. In environments with many events, that may actually not have that much of an effect. But in the average environment, this will give the Zabbix Server some breathing space as it failing to receive our events, may indicate a Zabbix server overload. For this I have to keep track which events are sent and which are pending. So I added a column in the database that keeps track of that. I have also added an alert_max_age config parameter that allows the user to set how long suricata-reporter should retry to send events to Zabbix. Events older than that set age, will no longer be sent to Zabbix. This also give the user the implicit option to send older events when only just enabling the zabbix sending functionality, since the DB column exists and no event was ever sent to Zabbix, all events will be 'pending". At first run with zabbix functionality enabled, all events up to alert_max_age that are in the database will be sent to zabbix immediatly. All events sent to Zabbix contain the timestamp of retrieval by suricata-reporter, so Zabbix will register and order them as received on that timestamp independently of the actual time Zabbix itself received the event. This is my first adventure in Python async programming, so I hope I did not make any flagrant mistakes. But the code has been running here for weeks now without any problem. I have not actually tested large bursts of events, as I could not simulate that.. But I did make Zabbix server slow, unavailable and finally replaced it with netcat (to accept the connection, but not react on it) and I had the connection with the server off for a few hours to then re-establish the connection to see hundereds of pending events being registered in only a few milliseconds. I did not notice any problems with suricata-reporter in any of these cases. Regards Robin -- Dit bericht is gescanned op virussen en andere gevaarlijke inhoud door MailScanner en lijkt schoon te zijn.