# Zabbix

EvoHub receives Zabbix problems through a **Webhook** media type with a short script. A problem opens an EvoHub alert, and the recovery message resolves it.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Zabbix**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create a webhook media type
In Zabbix, go to **Alerts → Media types → Create media type** and choose type **Webhook**.
### Add the parameters
Add these parameters (**Name** = **Value**), using your webhook URL for `url`.
### Paste the script
Paste the script below into the **Script** field and save the media type.
### Assign the media type
Add the media type to the Zabbix user that your trigger actions notify (the user's **Media** tab), and make sure an action sends problems to that user.
:::

Parameters:

```text
url = https://evohub.io/ingest/zabbix?key=YOUR_INTEGRATION_KEY
event_id = {EVENT.ID}
trigger_name = {EVENT.NAME}
trigger_severity = {EVENT.SEVERITY}
trigger_status = {EVENT.STATUS}
host_name = {HOST.NAME}
host_ip = {HOST.IP}
event_value = {EVENT.VALUE}
```

Script:

```javascript
var p = JSON.parse(value);
var req = new HttpRequest();
req.addHeader('Content-Type: application/json');
req.post(p.url, JSON.stringify({
  event_id: p.event_id, trigger_name: p.trigger_name,
  trigger_severity: p.trigger_severity, trigger_status: p.trigger_status,
  host_name: p.host_name, host_ip: p.host_ip, event_value: p.event_value
}));
if (req.getStatus() < 200 || req.getStatus() >= 300) throw 'EvoHub ' + req.getStatus();
return 'OK';
```

## Turn on auto-resolve

Zabbix only sends a recovery if you ask it to:

1. In the media type, open **Message templates** and add a **Problem recovery** template. Without it, Zabbix never sends a recovery and alerts stay open.
2. In your trigger action, open **Recovery operations** and send a message through this same media type.

No script or parameter change is needed: the recovery carries `event_value = 0` and EvoHub resolves the matching alert.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `trigger_name` (or "Zabbix Alert"). |
| Description | "Host: " and `host_name`. |
| Labels | `host`, `severity` and, when sent, `host_ip`. |
| Fingerprint | The host name and trigger name together. |

### Severity

| Zabbix severity | EvoHub severity |
| --- | --- |
| Disaster | critical |
| High | high |
| Average | medium |
| Warning | low |
| Information, Not classified | info |

## Resolve and deduplication

- A message is a recovery when `event_value` is `0` or `trigger_status` is `RESOLVED` or `OK`. It resolves the open alert for the same host and trigger.
- Because the fingerprint is host plus trigger name, repeated notifications for the same problem are recorded as **Retriggered** on the open alert, and the same trigger on different hosts opens separate alerts.

## Troubleshooting

- In Zabbix, **Reports → Action log** shows each media type call. An error such as `EvoHub 401` means the key is wrong or the integration is disabled.
- If alerts never resolve, check that the **Problem recovery** template exists and that the action has a recovery operation using this media type.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [PRTG](https://docs-dev.evohub.io/prtg.md)
- [Escalation policies](https://docs-dev.evohub.io/escalation-policies.md)
