You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求修正并按发行版拆分适配多Linux环境的Zabbix安全更新监控脚本

我帮你重构并修复了这个跨发行版的Zabbix安全更新监控脚本,针对你遇到的三个核心问题做了针对性解决:Debian/Ubuntu的bash/dash兼容性、RHEL系的安全更新精准检测,同时新增了SuSE Linux的支持。下面是分发行版的修复脚本及说明:

修复后的分发行版Zabbix安全更新监控脚本

1. Debian/Ubuntu 系(解决bash/dash兼容性+安全更新检测)

核心修复点:

  • 明确指定#!/bin/bash执行,避免Ubuntu默认的dash触发语法兼容问题(比如Bad substitution)
  • 替换原全量更新检测逻辑,改为仅统计安全更新包(通过过滤apt-get模拟升级输出中的security标记)
  • 优化缓存刷新逻辑,仅在间隔超过1天时才执行apt update,减少系统负载
  • 完善变量处理,确保输出始终为数字(避免空值导致Zabbix采集异常)
#!/bin/bash
# Zabbix安全更新监控脚本 - Debian/Ubuntu系
# 要求bash 3.0+
if [[ "${BASH_VERSINFO[0]}" -lt "3" ]]; then
    echo "bash version < 3"
    exit 1
fi

set -o errexit
set -o nounset
set -o pipefail

PATH=/bin:/sbin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin
timestamp_file="/run/zabbix/caendra_check_update"
update_interval="86400" # 1天
epoch=$(date "+%s")
outfile="/run/zabbix/zabbix.count.security_updates"

# 创建临时目录(如果不存在)
mkdir -p /run/zabbix

# 检测上次更新时间
function check_last_update {
    if [[ ! -e "$timestamp_file" ]]; then
        update_needed="y"
        touch "$timestamp_file"
    else
        timestamp_file_mtime=$(stat -c %Y "$timestamp_file")
        if [[ $((epoch - timestamp_file_mtime)) -gt "$update_interval" ]]; then
            update_needed="y"
        else
            update_needed="n"
        fi
    fi
}

# 检测安全更新数量
function check_security_updates {
    if [[ "$update_needed" == "y" ]]; then
        # 刷新源缓存,静默执行
        apt update -qq &>/dev/null
        touch "$timestamp_file"
    fi
    # 模拟升级,仅统计安全更新包数量
    pkg_to_update=$(apt-get -s upgrade -o Debug::NoLocking=true 2>&1 | grep -E '^Inst.*security' | wc -l)
    # 处理可能的空值,确保输出为数字
    echo "${pkg_to_update:-0}" > "$outfile"
}

check_last_update
check_security_updates
cat "$outfile"

2. RHEL/CentOS/AlmaLinux 系(解决仅安全更新检测问题)

核心修复点:

  • 自动适配yum(CentOS 7)和dnf(AlmaLinux 8+/CentOS 8+)包管理器
  • 使用updateinfo list security命令精准获取安全更新数量,替代原全量更新检测
  • 修复缓存检测逻辑,避免误触发不必要的缓存刷新
  • 优化错误处理,确保在不同RHEL版本下稳定运行
#!/bin/bash
# Zabbix安全更新监控脚本 - RHEL/CentOS/AlmaLinux系
# 要求bash 3.0+
if [[ "${BASH_VERSINFO[0]}" -lt "3" ]]; then
    echo "bash version < 3"
    exit 1
fi

set -o errexit
set -o nounset
set -o pipefail

PATH=/bin:/sbin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin
timestamp_file="/run/zabbix/caendra_check_update"
update_interval="86400" # 1天
epoch=$(date "+%s")
outfile="/run/zabbix/zabbix.count.security_updates"

# 创建临时目录(如果不存在)
mkdir -p /run/zabbix

# 检测包管理器(yum/dnf)
detect_package_manager() {
    if command -v dnf &>/dev/null; then
        PM="dnf"
    else
        PM="yum"
    fi
}

# 检测上次更新时间
function check_last_update {
    if [[ ! -e "$timestamp_file" ]]; then
        update_needed="y"
        touch "$timestamp_file"
    else
        timestamp_file_mtime=$(stat -c %Y "$timestamp_file")
        if [[ $((epoch - timestamp_file_mtime)) -gt "$update_interval" ]]; then
            update_needed="y"
        else
            update_needed="n"
        fi
    fi
}

# 检测安全更新数量
function check_security_updates {
    detect_package_manager
    if [[ "$update_needed" == "y" ]]; then
        # 刷新缓存,静默执行
        $PM makecache -qq &>/dev/null
        touch "$timestamp_file"
    fi
    # 获取安全更新数量,过滤无效行
    pkg_to_update=$($PM updateinfo list security all 2>&1 | grep -E '^[0-9]+:' | wc -l)
    # 处理可能的空值,确保输出为数字
    echo "${pkg_to_update:-0}" > "$outfile"
}

check_last_update
check_security_updates
cat "$outfile"

3. SuSE Linux 系(新增支持)

实现要点:

  • 使用zypper list-updates --type security命令专门检测安全更新
  • 保持与其他发行版一致的缓存控制逻辑,每天仅刷新一次源
  • 输出格式统一,便于Zabbix统一配置采集
#!/bin/bash
# Zabbix安全更新监控脚本 - SuSE Linux系
# 要求bash 3.0+
if [[ "${BASH_VERSINFO[0]}" -lt "3" ]]; then
    echo "bash version < 3"
    exit 1
fi

set -o errexit
set -o nounset
set -o pipefail

PATH=/bin:/sbin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin
timestamp_file="/run/zabbix/caendra_check_update"
update_interval="86400" # 1天
epoch=$(date "+%s")
outfile="/run/zabbix/zabbix.count.security_updates"

# 创建临时目录(如果不存在)
mkdir -p /run/zabbix

# 检测上次更新时间
function check_last_update {
    if [[ ! -e "$timestamp_file" ]]; then
        update_needed="y"
        touch "$timestamp_file"
    else
        timestamp_file_mtime=$(stat -c %Y "$timestamp_file")
        if [[ $((epoch - timestamp_file_mtime)) -gt "$update_interval" ]]; then
            update_needed="y"
        else
            update_needed="n"
        fi
    fi
}

# 检测安全更新数量
function check_security_updates {
    if [[ "$update_needed" == "y" ]]; then
        # 刷新源缓存,静默执行
        zypper refresh -q &>/dev/null
        touch "$timestamp_file"
    fi
    # 获取安全更新数量
    pkg_to_update=$(zypper list-updates --type security 2>&1 | grep -E '^v' | wc -l)
    # 处理可能的空值,确保输出为数字
    echo "${pkg_to_update:-0}" > "$outfile"
}

check_last_update
check_security_updates
cat "$outfile"

Zabbix 部署步骤

  1. 将对应发行版的脚本上传到目标服务器的/usr/local/bin/zabbix_check_security_updates.sh,赋予执行权限:
    chmod +x /usr/local/bin/zabbix_check_security_updates.sh
    
  2. 在Zabbix Agent配置文件(如/etc/zabbix/zabbix_agentd.conf)中添加自定义参数:
    UserParameter=security.updates.count,/usr/local/bin/zabbix_check_security_updates.sh
    
  3. 重启Zabbix Agent使配置生效:
    systemctl restart zabbix-agent
    

内容的提问来源于stack exchange,提问作者Joji

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 17:27:27