> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Zabbix to Neo

> Save your Zabbix address and an API token in Neo

## Before you start

* Neo needs **Zabbix 6.4 or later**, the first release that accepts an API token in the `Authorization` header.
* Neo reaches your Zabbix frontend over the internet. It must answer on **HTTPS** with a certificate from a public certificate authority, at a public address. If a firewall or reverse proxy limits who can reach it, allow [Neo's addresses](/integrations/ip-whitelisting) to reach `api_jsonrpc.php`.

## 1. Prepare a Zabbix user and token

<Steps>
  <Step title="Create a user for Neo">
    In Zabbix, open **Users → Users** and create a user for Neo. Its **role** decides which API methods Neo may call: on the role, keep **Access to API** on. Its **user groups** decide which host groups Neo can read or change, so give the groups read access to the clients' host groups, or read-write where you want agents to make changes.

    A **User** role reads hosts and problems and acknowledges problems. Maintenance and configuration changes need an **Admin** role, and users, roles and global settings need **Super admin**.
  </Step>

  <Step title="Create the API token">
    Open **Users → API tokens**, click **Create API token**, choose Neo's user, and set an expiry date if your policy needs one. Copy the token: Zabbix shows it once.
  </Step>
</Steps>

<Warning>
  If the token expires, or you disable the token or its user, Neo loses access until you save a new token here.
</Warning>

## 2. Add the token in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **Zabbix**](https://dashboard.neoagent.io/integrations?open=zabbix), under Networking.
  </Step>

  <Step title="Save the address and token">
    Enter the address you open Zabbix at, including a path such as `/zabbix` if it has one (for example `https://monitor.example.com/zabbix`), and the API token, then click **Save settings**. Neo reads your Zabbix version and checks the token before saving, so a wrong address, an older Zabbix or a refused token is rejected straight away.
  </Step>
</Steps>

## 3. Turn Zabbix on per agent

Open the agent, go to the Integrations section, and configure the Zabbix block. Agents see only what Neo's Zabbix user can see.

### Pick an access profile

<CardGroup cols={2}>
  <Card title="Read Only" icon="magnifying-glass">
    Read hosts, problems, latest data, history and configuration. Nothing is changed.
  </Card>

  <Card title="Helpdesk" icon="headset">
    Acknowledge, comment on and close problems without approval. Maintenance and running a script wait on a technician. Everything else is read only.
  </Card>

  <Card title="IT Admin" icon="user-gear">
    Problems, hosts, maintenance, items, triggers and templates change without approval, except deleting a host. Scripts, actions and media types, users and access, and administration wait on a technician.
  </Card>

  <Card title="Full Automation" icon="bolt">
    Every change runs without approval, except the [changes that always ask a technician](#changes-that-always-ask-a-technician).
  </Card>
</CardGroup>

### Or set each area by hand

| Area | Notes |
| - | - |
| **Problems and Events** | Current problems, events and sent alerts. Write acknowledges, comments on, closes, suppresses or changes the severity of a problem. |
| **Hosts** | Hosts, host groups and interfaces, with availability, inventory and tags. Deleting a host always waits on a technician. |
| **History and Trends** | Collected values and hourly trends. Write sends values to trapper items. |
| **Maintenance** | Maintenance periods. |
| **Scripts** | Global scripts. Write runs a script on a host, or creates and changes scripts. |
| **Items, Triggers and Discovery** | Items, triggers, graphs, web scenarios, low-level discovery, host macros, value maps and "check now". |
| **Templates** | Templates, template groups and template dashboards. |
| **Actions and Media Types** | Actions, media types and event correlation. |
| **Dashboards, Maps and Reports** | Dashboards, network maps, images and scheduled reports. |
| **Services and SLAs** | Business services and SLAs. |
| **Network Discovery and Proxies** | Network discovery, proxies and active agent autoregistration. |
| **Users and Access** | Users, user groups, roles, API tokens, LDAP and SAML, MFA and authentication. The changes listed under [Changes that always ask a technician](#changes-that-always-ask-a-technician) always wait on a technician, and Neo never creates an API token. |
| **Administration** | Global settings, housekeeping, modules, regular expressions, connectors, global macros, the audit log and HA nodes. |

Each area can be Disabled, Read Only or Read/Write, and has its own technician approval setting.

### Changes that always ask a technician

These wait on a technician under every profile, whatever the area's own approval setting:

* Changing authentication settings (HTTP, LDAP and SAML sign-in, the default sign-in method, the password policy).
* Creating, changing, testing or deleting an LDAP or SAML user directory.
* Creating, changing or deleting an MFA method.
* Creating, changing or deleting a user role or a user group.
* Creating, deleting or provisioning a user from LDAP, or changing a user's role, user groups or user directory. Disabling a user means moving them to a disabled user group, so it asks too.
* Resetting a user's MFA.
* Changing or deleting an API token.
* Deleting a host, which removes its collected history.
* Any change that stores a credential: a password, a secret macro, a credential header or parameter, the user name and password in a URL, or an HTTP agent's request body.

## Troubleshooting

| Error when you save | What to check |
| - | - |
| No Zabbix API answered | The address, including a path such as `/zabbix`. Open `<address>/api_jsonrpc.php` in a browser: Zabbix answers it. |
| This Zabbix runs version ... | Upgrade to Zabbix 6.4 or later. |
| Zabbix rejected the API token | The token, its expiry, and that its user is enabled and its role has API access. |
| A web server in front of Zabbix refused Neo | Allow Neo's addresses to reach `api_jsonrpc.php`. |
| ... is a private or reserved address | Use the public address of your Zabbix frontend. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.