5 Minimum permission level for Windows agent items

概述

使用 agent 监控系统时,一种最佳实践是从安装代理的主机上获取指标。要使用最小权限原则,有必要确定哪些指标是从agent 那里获得的。

本文档中的表格允许您选择最低权限,保证 Zabbix agent 的正确运行。

如果选择了其他用户才能使 agent 工作,而不是”LocalSystem”,则要使 agent 作为Windows服务运行,新用户必须具有“本地策略→用户权限分配”中的”作为服务登录”权限分配”以及创建、写入和删除 Zabbix 代理日志文件的权利。必须将 Active Directory 用户添加到性能监视器用户组。

基于 agent 的权限处理问题上,需要给出 “技术上可接受的最低要求 “的权限组,并且事先为监控对象提供权限。

Windows 上支持的常用 agent 监控项

监控项 key用户组
推荐的技术上可接受的最低权限组 (功能有限)
agent.hostnameGuestsGuests
agent.pingGuestsGuests
agent.variantGuestsGuests
agent.versionGuestsGuests
logAdministratorsGuests
log.countAdministratorsGuests
logrtAdministratorsGuests
logrt.countAdministratorsGuests
net.dnsGuestsGuests
net.dns.recordGuestsGuests
net.if.discoveryGuestsGuests
net.if.inGuestsGuests
net.if.outGuestsGuests
net.if.totalGuestsGuests
net.tcp.listenGuestsGuests
net.tcp.portGuestsGuests
net.tcp.serviceGuestsGuests
net.tcp.service.perfGuestsGuests
net.udp.serviceGuestsGuests
net.udp.service.perfGuestsGuests
proc.numAdministratorsGuests
system.cpu.discoveryPerformance Monitor UsersPerformance Monitor Users
system.cpu.loadPerformance Monitor UsersPerformance Monitor Users
system.cpu.numGuestsGuests
system.cpu.utilPerformance Monitor UsersPerformance Monitor Users
system.hostnameGuestsGuests
system.localtimeGuestsGuests
system.runAdministratorsGuests
system.sw.archGuestsGuests
system.swap.sizeGuestsGuests
system.unameGuestsGuests
system.uptimePerformance Monitor UsersPerformance Monitor Users
vfs.dir.countAdministratorsGuests
vfs.dir.getAdministratorsGuests
vfs.dir.sizeAdministratorsGuests
vfs.file.cksumAdministratorsGuests
vfs.file.contentsAdministratorsGuests
vfs.file.existsAdministratorsGuests
vfs.file.md5sumAdministratorsGuests
vfs.file.regexpAdministratorsGuests
vfs.file.regmatchAdministratorsGuests
vfs.file.sizeAdministratorsGuests
vfs.file.timeAdministratorsGuests
vfs.fs.discoveryAdministratorsGuests
vfs.fs.sizeAdministratorsGuests
vm.memory.sizeGuestsGuests
web.page.getGuestsGuests
web.page.perfGuestsGuests
web.page.regexpGuestsGuests
zabbix.statsGuestsGuests

Windows特定的监控项键

监控项 key用户组
推荐的技术上可接受的最低权限组 (功能有限)
eventlogEvent Log ReadersGuests
net.if.listGuestsGuests
perf_counterPerformance Monitor UsersPerformance Monitor Users
proc_infoAdministratorsGuests
service.discoveryGuestsGuests
service.infoGuestsGuests
servicesGuestsGuests
wmi.getAdministratorsGuests
vm.vmemory.sizeGuestsGuests