Zabbix Agent Update Manager is an enterprise-grade frontend module for Zabbix 6.4 and 7.0+ LTS. It centralizes agent lifecycle management, cross-references installed agent versions across all monitored Linux, Windows, and FreeBSD hosts against official Zabbix release branches, identifies hardware and virtualization architectures, and provides automated, copy-paste ready upgrade commands tailored to each host's operating system.
Developed by George Filho.
-
🌐 Multi-Source Version Resolution Engine:
- Primary Provider: Fetches official stable releases from
https://cdn.zabbix.comwith mandatory strict SSL validation. - Secondary Fallback: GitHub Releases / Tags API fallback for high availability.
- Air-Gapped / Offline Support: Embedded static version database for fully isolated enterprise environments.
- Automatically isolates major branches (
6.0.x,6.4.x,7.0.x,7.2.x,7.4.x).
- Primary Provider: Fetches official stable releases from
-
📊 High-Level KPI Summary Dashboard:
- Real-time KPI summary cards displaying Total Monitored Hosts, Physical Hosts (Bare-Metal), Virtual Machines (VMs), Up to Date, Outdated (Update Needed), Offline (Unreachable), and Unknown Version.
-
🖥️ Modular Hardware & Hypervisor Detection (
HardwareDetectionService):- Identifies Physical Bare-Metal Servers (Dell PowerEdge, HPE ProLiant, Lenovo ThinkServer/ThinkSystem, Supermicro, Cisco UCS) vs. Virtual Machines (VMware ESXi, Proxmox, KVM/QEMU, Hyper-V, VirtualBox, Xen, AWS EC2, GCP, Azure, Nutanix).
- Passive DMI/WMI telemetry without requiring custom remote scripts.
-
🐧 Decoupled 5-Layer OS Engine (
OsDetectionService):- Natively identifies Linux distributions (Fedora, Debian, Ubuntu, RHEL, Rocky, AlmaLinux, CentOS, openSUSE, Alpine, FreeBSD) and Windows Editions (Windows Server 2025, 2022, 2019, 2016, Windows 11/10).
-
📑 Native Pagination for Massive Scale (
CPagerHelper):- Seamlessly handles large enterprise infrastructures (+10,000 hosts) with fluent pagination and configurable page limits.
-
🔍 Advanced Multi-Dimensional Filtering:
- Filter by Host Name/IP, Status, OS Family, Hardware Type, Host Group, and Zabbix Proxy.
-
📋 Host Details Modal:
- Click any host name to open an extended information panel showing IP, OS Family, Raw OS Info, Interface Type, Agent Version, and a timestamped Version History log (last 5 upgrades).
-
📥 Direct CSV Export:
- Instant one-click CSV export with UTF-8 BOM (Excel compatible) of all filtered hosts including Hardware Type (Container LXC, VM, Cloud, Physical), OS, version gaps, and availability status.
-
🤖 Automated Batch & Ansible Playbooks:
- Interactive modal with per-host instructions and dynamic mass update command generators (SSH Batch / Ansible Playbooks).
-
🔒 Hardened Security & CSP Compliance:
- Strict SSL verification, exclusive cache locking (
LOCK_EX&chmod 0600), zero inline scripts, and no hardcoded credentials.
- Strict SSL verification, exclusive cache locking (
Before installing this module, ensure that:
- You are running Zabbix Frontend 6.4 LTS, 7.0 LTS, or higher.
- The web server user (e.g.,
www-data,apache, ornginx) has read access to the module directory. - The PHP
curlextension orallow_url_fopenis enabled to allow fetching official Zabbix release version information fromcdn.zabbix.com(proxies supported via standard environment variableshttps_proxy/http_proxy).
Installing modules in the Zabbix frontend is straightforward and plug-and-play.
Download the module files to your Zabbix server.
Move the module folder into the modules directory of your Zabbix web interface.
Important
The module folder must be placed inside modules/ keeping the name Module Agent Update (with spaces), exactly as provided in this repository.
The default module path on most distributions is:
# Ubuntu / Debian
cp -r "Module Agent Update" /usr/share/zabbix/ui/modules/
# RHEL / Rocky Linux / AlmaLinux / CentOS
cp -r "Module Agent Update" /usr/share/zabbix/modules/Ensure the web server user has read access to all module files:
# Debian / Ubuntu (Nginx / Apache)
chown -R www-data:www-data "/usr/share/zabbix/ui/modules/Module Agent Update"
chmod -R 755 "/usr/share/zabbix/ui/modules/Module Agent Update"
# Allow the web server to write runtime cache files
chmod -R 777 "/usr/share/zabbix/ui/modules/Module Agent Update/data"
# RHEL / Rocky / Alma / CentOS (Apache / Nginx)
chown -R apache:apache "/usr/share/zabbix/modules/Module Agent Update"
chmod -R 755 "/usr/share/zabbix/modules/Module Agent Update"
chmod -R 777 "/usr/share/zabbix/modules/Module Agent Update/data"- Log into your Zabbix Web Interface as a Super Admin.
- Navigate to Administration → General → Modules (or Administration → Modules in Zabbix 7.0).
- Click the "Scan directory" button in the top right corner.
- Locate "Zabbix Agent Update Manager" in the list.
- In the Status column, click Disabled to change it to Enabled.
Once enabled, a new dedicated menu item will be accessible in your Zabbix main navigation:
- Navigate to SuporTI → Agent Updates in the left sidebar menu.
- Review Global KPI Cards: View an instant summary of outdated servers, physical machines, and virtual machines.
- Filter Hosts: Use the top filter form to filter by:
- Host / IP: Search by hostname, DNS, or interface IP address.
- Status: Filter by Outdated only, Up to date only, Offline, or Unknown version.
- OS Family: Filter by Linux, Windows, FreeBSD, or Unknown.
- Hardware Type: Filter by Physical, Virtual (VM), Cloud, or Unknown.
- Host Group and Proxy for additional segmentation.
- Inspect Version Gaps: Review the side-by-side Current Version and Target Version columns.
- Get Update Instructions: For any outdated host, click the Instructions button to open the interactive upgrade modal with exact commands for your operating system and package manager.
- Host Details: Click any host name in the table to view the extended Host Details modal, including OS details, interface type, agent version, and the last 5 detected version changes.
- Export CSV: Click Export CSV in the header to download a full spreadsheet of all filtered hosts.
- Bulk Actions: Select multiple hosts via the checkboxes, then copy their IPs or generate a batch update script in one click.
To display the exact, official distribution name and version (e.g., Ubuntu 22.04.4 LTS, Debian GNU/Linux 12 (bookworm), Microsoft Windows Server 2022 Datacenter) in the Operating System column, the module includes automated scanning scripts executed directly on the Zabbix Server.
- Zero Configuration on Monitored Agents: Does not require remote commands (
AllowKey=system.run[*]) or creating customUserParameterkeys on target machines. - Native Zabbix Agent Keys:
- Linux: Reads
/etc/os-releaseviavfs.file.contents[/etc/os-release]and extractsPRETTY_NAME=. - Windows: Queries WMI via
wmi.get[root\cimv2,select Caption from Win32_OperatingSystem]or queries the official OS caption.
- Linux: Reads
- Zero-Token Database Auto-Discovery: Connects directly via PDO to the local Zabbix database (MySQL or PostgreSQL) by parsing
/etc/zabbix/web/zabbix.conf.php, without needing API tokens or web sessions.
Important
SNMP Hosts: OS and Hardware detection are not supported for hosts monitored exclusively via SNMP (without Zabbix Agent installed). Both the Operating System and Hardware columns will display a grey Not Collected badge for these hosts, ensuring no false positives are shown.
On the Zabbix server terminal, navigate to the module directory and execute:
cd "/usr/share/zabbix/ui/modules/Module Agent Update"
php scripts/detect_real_os.php --all
# Or via Bash:
bash scripts/detect_real_os.sh --allphp scripts/detect_real_os.php --ip=192.168.1.100 --hostid=10084
# Or via Bash:
bash scripts/detect_real_os.sh 192.168.1.100 10084You can register the script directly in the Zabbix Web UI to scan any host on-demand with 1 click:
- Navigate to Alerts → Scripts (or Administration → Scripts).
- Click Create script:
- Name:
Detect Real OS - Scope: Check
Action operationand/orManual host action(enables 1-click execution from the Hosts page). - Type:
Script - Execute on:
Zabbix proxy or server - Commands:
/usr/share/zabbix/ui/modules/Module\ Agent\ Update/scripts/detect_real_os.php "{HOST.CONN}" "{HOST.ID}"
- Name:
- Click Add / Update.
- How to test: Go to Monitoring → Hosts, click on any monitored host name, and select
Detect Real OS. A pop-up modal will instantly display the real-time execution output.
Script configuration in Zabbix Alerts → Scripts for on-demand OS detection from the Hosts page.
To ensure operating system data remains continuously validated without manual overhead, use one of the following methods:
On the Zabbix server, run crontab -e as root and schedule the task to run weekly (e.g., every Sunday at 03:00 AM):
# Runs weekly every 7 days and outputs to a dedicated log file
0 3 * * 0 /usr/bin/php "/usr/share/zabbix/ui/modules/Module Agent Update/scripts/detect_real_os.php" --all > /var/log/zabbix/detect_real_os.log 2>&1To inspect the output of the latest execution:
cat /var/log/zabbix/detect_real_os.log- Create a symlink in the Zabbix Server external scripts directory:
ln -s "/usr/share/zabbix/ui/modules/Module Agent Update/scripts/detect_real_os.sh" /usr/lib/zabbix/externalscripts/detect_real_os_all.sh chmod +x /usr/lib/zabbix/externalscripts/detect_real_os_all.sh - Create an Item on the Zabbix server host:
- Type:
External check - Key:
detect_real_os_all.sh["--all"] - Update interval:
0 - Custom intervals: Scheduling
wd7h3(Every Sunday at 03:00 AM)
- Type:
If a host is offline, unreachable, the agent times out, or is monitored only via SNMP:
- The script explicitly records the status as
Not Collectedin cache (for offline/timeout scenarios). - SNMP-only hosts are automatically assigned
Not Collectedwithout attempting any collection. - The user interface renders the neutral
Not Collectedbadge with an explanatory tooltip on mouse hover. - This strictly avoids displaying outdated or irrelevant historical guesses, maintaining 100% inventory fidelity.
To ensure the Hardware column displays with pinpoint accuracy whether a host is a Virtual Machine (VM), a Container (LXC / Docker), a Cloud Instance (AWS / GCP / Azure), or a Physical Server (Bare-Metal) along with its specific hardware/hypervisor model, the module includes multi-tiered scanner logic with anti-false-positive isolation:
- Tier 1: Container Detection (
LXC / Docker / Podman):- LXC containers (common on Proxmox VE) inherit DMI vendor/model tables and kernel from the host node (e.g. Dell PowerEdge).
- The scanner checks
systemd-detect-virt,Chassis: container,Icon: computer-container, and native markers/run/systemd/container,/proc/1/cgroup, and/proc/1/environ. - Result: Accurately labels containers as
Container · LXC, completely eliminating false positives where containers were misidentified as the physical host server!
- Tier 2: Cloud Instance Detection (
AWS / GCP / Azure / OCI / DigitalOcean):- Cloud instances (such as AWS Nitro c5/m5/t3) report chassis as
server. - The scanner identifies cloud providers via DMI and virtualization hypervisors, categorizing as
Cloud · AWS EC2 (t3.medium),Cloud · GCP Instance, orCloud · Azure VM.
- Cloud instances (such as AWS Nitro c5/m5/t3) report chassis as
- Tier 3: Hypervisors & Virtual Machines (
KVM / QEMU / VMware / Hyper-V / VirtualBox / Xen):- Inspects the CPU
hypervisorflag in/proc/cpuinfo(strictly exclusive to virtualized CPUs),Virtualization:tags, and virtual DMI (QEMU Standard PC,VMware Virtual Platform,Virtual Machine). - Categorizes as
VM · KVM / QEMU,VM · VMware, orVM · Hyper-V.
- Inspects the CPU
- Tier 4: Genuine Physical Bare-Metal Servers:
- Only hosts that do not possess container, cloud, or CPU hypervisor markers and belong to verified hardware manufacturers (Dell, HPE, Lenovo, Supermicro, Cisco, etc.) are categorized as
Physical · Dell PowerEdge R740orPhysical · HPE ProLiant.
- Only hosts that do not possess container, cloud, or CPU hypervisor markers and belong to verified hardware manufacturers (Dell, HPE, Lenovo, Supermicro, Cisco, etc.) are categorized as
- Windows (
Win32_ComputerSystem):- Native Zabbix Agent WMI queries and PowerShell
Get-CimInstance Win32_ComputerSystemmap physical vs. virtual platforms with full parity.
- Native Zabbix Agent WMI queries and PowerShell
- Dedicated Local Cache: Results are stored in
data/real_hw_cache.jsonand rendered on a single line with distinct theme-adaptive color accents.
Important
SNMP Hosts: Hardware detection is not supported for hosts monitored via SNMP only. These hosts display Not Collected in the Hardware column.
cd "/usr/share/zabbix/ui/modules/Module Agent Update"
php scripts/detect_hardware.php --all
# Or via Bash:
bash scripts/detect_hardware.sh --allphp scripts/detect_hardware.php --ip=192.168.1.100 --hostid=10084
# Or via Bash:
bash scripts/detect_hardware.sh 192.168.1.100 10084To scan and refresh both Operating System and Hardware across all hosts in a single command:
bash scripts/detect_all.sh --allRegister the hardware scanner in the Zabbix Web UI for 1-click on-demand execution:
- Navigate to Alerts → Scripts → Create script:
- Name:
Detect Real Hardware - Scope: Check
Action operationandManual host action. - Type:
Script - Execute on:
Zabbix proxy or server - Commands:
/usr/bin/php /usr/share/zabbix/ui/modules/Module\ Agent\ Update/scripts/detect_hardware.php "{HOST.CONN}" "{HOST.ID}"
- Name:
- Click Add / Update.
- In Monitoring → Hosts, left-click any host name and select
Detect Real Hardwareto view real-time diagnostics!
Script configuration in Zabbix Alerts → Scripts for on-demand Hardware detection from the Hosts page.
On the Zabbix server, run crontab -e as root and schedule the full weekly scan:
# Runs full weekly revalidation (OS + Hardware) every Sunday at 03:00 AM
0 3 * * 0 "/usr/share/zabbix/ui/modules/Module Agent Update/scripts/detect_all.sh" --all > /var/log/zabbix/detect_all.log 2>&1The structure follows the official Zabbix 6.4+ / 7.0+ MVC Module Architecture:
Module Agent Update/
├── .gitignore # Excludes runtime data and sensitive keys from version control
├── manifest.json # Module metadata, actions, and assets manifest
├── Module.php # Core module class and main navigation menu registration
├── README.md # English documentation
├── README_pt.md # Portuguese documentation
├── actions/
│ └── AgentUpdateList.php # Primary Controller
├── includes/
│ ├── AvailabilityResolver.php # Availability and agent interface resolution
│ ├── CsvExportService.php # Structured CSV export (UTF-8 with BOM)
│ ├── HardwareDetectionService.php # Hardware type resolution (Physical vs VM) with cache
│ ├── HostFilterService.php # Dynamic multi-criteria host filtering
│ ├── OsDetectionService.php # Multi-layer OS detection and cache loader
│ ├── VersionHistoryService.php # Temporal version history and stale tracker
│ └── ZabbixVersionFetcher.php # Official CDN scraper and HMAC cache
├── scripts/
│ ├── agent_update_alert.php # Optional: Push agent status to Zabbix via API (Zabbix 7.0+)
│ ├── detect_all.sh # Unified scanner script for both OS and Hardware
│ ├── detect_hardware.php # CLI PHP script to scan and cache Hardware (VM vs Physical)
│ ├── detect_hardware.sh # Bash wrapper script for Hardware scan
│ ├── detect_real_os.php # CLI PHP script to scan and cache real OS for all hosts
│ └── detect_real_os.sh # Bash wrapper script for OS scan
├── data/ # Runtime cache (excluded from version control via .gitignore)
│ ├── .hmac_key # Auto-generated HMAC signing key (chmod 0600)
│ ├── real_hw_cache.json # Real Hardware cache (VM vs Physical)
│ ├── real_os_cache.json # Real OS cache per host
│ └── zbx_agent_version_cache.json # Official Zabbix releases cache
├── views/
│ └── agent.update.list.php # Main view (KPIs, Filters, Hosts table, and Modal)
└── assets/
├── css/
│ └── module.css # Theme-adaptive styling (Dark, Light, HC-Dark)
├── js/
│ └── module.js # CSP-compliant interactions, column sorting, and bulk selection
└── images/
├── image-01.png # Main Dashboard & Full Hosts Table
├── image-02.png # Batch Automation Modal (Ansible Script)
├── image-03.png # Per-Host Update Instructions Modal
├── image-04.png # Header Action Buttons
├── image-05.png # KPI Cards & Filter Bar
├── image-06.png # Host Details Modal (Extended Info & Version History)
├── image-07.png # Outdated vs Up to Date Row Examples
├── image-detect_real_os.png # Zabbix Alerts → Scripts: Detect Real OS configuration
└── image-detect_hardware.png # Zabbix Alerts → Scripts: Detect Real Hardware configuration
Full host table view with Availability, OS, Hardware, Current/Target versions, Status badges, and Actions.
Real-time KPI summary cards (Total, Up to Date, Outdated, Offline, Unknown, Physical, VM) and the advanced multi-criteria filter bar.
Tailored upgrade instructions per OS with Agent 2 (Go), Agent 1 (C), Windows MSI download shortcuts, and one-click copy feedback.
Mass update command generator with SSH batch scripts and Ansible playbooks for all outdated hosts.
Extended host information panel with IP, OS Family, Interface Type, Agent Version, and timestamped Version History.
Highlighted Outdated badge with "patches behind" counter, compared to a fully up-to-date row. Container · LXC Hardware badge visible.
How to register the Detect Real OS script in Zabbix Alerts → Scripts for on-demand 1-click execution from the Hosts page.
How to register the Detect Real Hardware script in Zabbix Alerts → Scripts for on-demand 1-click execution from the Hosts page.
Important
Collection Compatibility & Support (Zabbix Agent Required):
Automated collection and detection of Operating System and Hardware are supported exclusively on servers with Zabbix Agent (or Agent 2) installed and active.
For servers or network appliances monitored exclusively via SNMP (or without Zabbix Agent installed), collection is not performed, and both columns will cleanly display Not Collected (subtle grey badge), ensuring only 100% verified agent data is presented and eliminating false positives.
The module resolves operating system information using a passive cascading architecture (requires Zabbix Agent):
- Real OS Cache (
data/real_os_cache.jsongenerated by server-side scan script viazabbix_get) vfs.file.contents[/etc/os-release](systemd standardPRETTY_NAME=)- Windows WMI (
Win32_OperatingSystem) system.sw.os[full]/system.sw.os(Zabbix template software OS items)vfs.file.contents[/etc/redhat-release]//etc/issue(Legacy RHEL/CentOS)- Host Inventory (
os_full,os_short,ospopulated by agent) system.uname(Kernel release parsing:.fcXX➔ Fedora,.elX➔ Enterprise Linux, Ubuntu, Debian, Windows)
Identifies hardware architectures through (requires Zabbix Agent):
- Real Hardware Cache (
data/real_hw_cache.jsongenerated by server-side scan script viazabbix_get) - Native OS commands:
hostnamectl(Linux) andGet-CimInstance Win32_ComputerSystem(Windows) - Container markers:
/run/systemd/container,/proc/1/cgroup(LXC / Docker / Podman) - DMI / WMI tables:
/sys/class/dmi/id/product_name,sys_vendor,chassis_type,Win32_ComputerSystem,Win32_BIOS - Contextual fallback through Template names, Host Groups, and Tags.
- Input Validation: All HTTP inputs strictly validated via Zabbix's
validateInput()with an explicit allowlist. - Permission Enforcement: Module requires
USER_TYPE_ZABBIX_ADMINor higher. - SSL Enforcement:
CURLOPT_SSL_VERIFYPEER = trueandCURLOPT_SSL_VERIFYHOST = 2— no exceptions. - Cache File Security: Written with
LOCK_EX(atomic) andchmod 0600(owner-read-only). - CSP Compliance: Zero inline scripts. All JavaScript uses DOM API methods (
createElement,textContent,setAttribute). - No Hardcoded Credentials: API token scripts use environment variables (
ZABBIX_API_TOKEN).
Copyright © 2006-2026 by George Filho.
All rights reserved.