{"id":396,"date":"2024-12-19T08:04:59","date_gmt":"2024-12-19T14:04:59","guid":{"rendered":"https:\/\/tekweis.com\/?p=396"},"modified":"2024-12-19T08:09:28","modified_gmt":"2024-12-19T14:09:28","slug":"excluding-windows-service-alerts-from-zabbix","status":"publish","type":"post","link":"https:\/\/tekweis.com\/index.php\/2024\/12\/19\/excluding-windows-service-alerts-from-zabbix\/","title":{"rendered":"Excluding Windows service alerts from Zabbix"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.zabbix.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zabbix<\/a> is a fantastic open-source application for monitoring your network attached devices. In regard to monitoring Windows endpoints, there are many Windows services that you will not want to see alerts for in your Zabbix dashboard. You can add exclusions to the template so that this excess clutter is not shown. This is a question that is asked a lot in the Zabbix forums, and the answers do not always seem to clearly give a beginner to Zabbix easy to follow steps for this. So, here it is.<\/p>\n\n\n\n<p>From your main dashboard, go into, &#8220;<strong>Data collection<\/strong>&#8220;, then select, &#8220;<strong>Templates<\/strong>&#8220;. Almost to the end of the list of templates, you will see a template named, &#8220;<strong>Windows services by Zabbix agent<\/strong>&#8220;. Select that template.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"513\" src=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template1.png\" alt=\"\" class=\"wp-image-397\" srcset=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template1.png 625w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template1-300x246.png 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/figure>\n<\/div>\n\n\n<p>Now select the <strong>MACROS<\/strong> tab within the template. Look for the section for, &#8220;<strong>{SERVICE.NAME.NOT_MATCHES}<\/strong>&#8220;. In the box, enter the service names you would like to exclude from detection. The list must begin with a <strong><mark style=\"background-color:#fcb900\" class=\"has-inline-color has-black-color\">^<\/mark><\/strong> character and is separated by a <strong><mark style=\"background-color:#fcb900\" class=\"has-inline-color has-black-color\">|<\/mark><\/strong> pipe character. The end of the list must be a <strong><mark style=\"background-color:#fcb900\" class=\"has-inline-color has-black-color\">$<\/mark><\/strong> dollar sign. An example would be:<\/p>\n\n\n\n<p><strong>^BITS|cplspcon|DolbyDAXAPI|edgeupdate|SysmonLogTrustedInstaller$<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"940\" height=\"538\" src=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template2.png\" alt=\"\" class=\"wp-image-398\" srcset=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template2.png 940w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template2-300x172.png 300w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template2-768x440.png 768w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template2-660x378.png 660w\" sizes=\"auto, (max-width: 940px) 100vw, 940px\" \/><\/figure>\n\n\n\n<p>Click on <strong>UPDATE<\/strong> and your changes will be saved.<\/p>\n\n\n\n<p>The exclusions will not be immediate. Normally the changes will only happen after the current lifecycle of the alerts history you have set. If you want the changes to be immediate and the services that you want to exclude removed from the dashboard immediately, then you will need to temporarily unlink and clear the windows services template from the, &#8220;Windows by Zabbix agent&#8221;, template, then add the template back in.<\/p>\n\n\n\n<p>Using the same method to find the previous template, search for, &#8220;<strong>Windows by Zabbix agent<\/strong>&#8221; and open the template. Look for the, &#8220;<strong>Windows services by Zabbix agent<\/strong>&#8220;, and click on the link to the righ that says, &#8220;<strong>Unlink and clear<\/strong>&#8220;. Then click <strong>UPDATE.<\/strong> After several moments, the template will be removed. Now you can use the select function below to search and add the, &#8220;<strong>Windows services by Zabbix agent<\/strong>&#8220;, back into the template. Once you update the temaplate after adding the, &#8220;Windows services by Zabbix agent&#8221; back in, the alerts will be cleared out and now only be populated moving forward with the alerts you want.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"936\" height=\"576\" src=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template3.png\" alt=\"\" class=\"wp-image-399\" srcset=\"https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template3.png 936w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template3-300x185.png 300w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template3-768x473.png 768w, https:\/\/tekweis.com\/wp-content\/uploads\/2024\/12\/Zabbix-template3-660x406.png 660w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\" \/><\/figure>\n\n\n\n<p>All existing alerts are now cleared from dashboard and all future alerts will be shown except the ones you added to be excluded.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zabbix is a fantastic open-source application for monitoring your network attached devices. In regard to monitoring Windows endpoints, there are many Windows services that you will not want to see alerts for in your Zabbix dashboard. You can add exclusions to the template so that this excess clutter is not shown. This is a question\u2026 <span class=\"read-more\"><a href=\"https:\/\/tekweis.com\/index.php\/2024\/12\/19\/excluding-windows-service-alerts-from-zabbix\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-396","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/posts\/396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/comments?post=396"}],"version-history":[{"count":3,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions"}],"predecessor-version":[{"id":402,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions\/402"}],"wp:attachment":[{"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/media?parent=396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/categories?post=396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekweis.com\/index.php\/wp-json\/wp\/v2\/tags?post=396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}