通过check_nrpe执行脚本与本地执行输出不一致问题求助
It’s super common to hit this scenario where a script works perfectly locally but fails when called via NRPE—let’s break down the most likely causes and how to fix them:
1. Fix the curl Path & Shell Context
When you run the script locally, it uses your user’s PATH variable, but NRPE runs as the nagios (or nobody) user, which might not have curl in its default PATH.
- First, find the full path to
curl:which curl - Update your script to use this absolute path instead of just
curl. For example, ifwhich curlreturns/usr/bin/curl, modify the line to:status="$(/usr/bin/curl --write-out %{http_code} --silent --output /dev/null $url)" - Also, add a shebang at the top of your script to explicitly specify the shell:
This avoids any inconsistencies between your local shell and the one NRPE uses.#!/bin/bash
2. Test the Script as the NRPE User
NRPE runs under a restricted user account, so permissions or network access might be blocked for that user.
- Switch to the
nagiosuser and run the script directly:
If this returns "Not responding", you know the issue is with thesu - nagios -c "/usr/local/nagios/libexec/check.sh"nagiosuser’s environment, not NRPE itself.
3. Check Network & Security Restrictions
Even if the URL is accessible from your local user, the nagios user might be blocked by:
- Firewall rules: Verify that the
nagiosuser isn’t restricted from outbound connections to port 5000. You can test this by runningcurl http://xxx.xxx.xxx.xxx:5000/v2/_catalogas thenagiosuser. - SELinux/AppArmor: These security modules might prevent the
nagiosuser from making network requests. Temporarily disable SELinux to test:
If the script works after this, you’ll need to add a SELinux policy to allowsetenforce 0nagiosto initiate outbound connections. - Target Service Whitelisting: The service at port 5000 might be configured to only accept requests from specific users or IPs. Confirm that the
nagiosuser’s context (or the server’s IP) is allowed.
4. Add Debug Logs to the Script
To get more visibility into what’s failing, modify your script to log curl’s verbose output:
#!/bin/bash url="http://xxx.xxx.xxx.xxx:5000/v2/_catalog" # Log curl details to a file (make sure nagios has write access to /tmp) /usr/bin/curl --write-out %{http_code} --verbose $url > /tmp/curl_nrpe_debug.log 2>&1 status="$(/usr/bin/curl --write-out %{http_code} --silent --output /dev/null $url)" if [ "$status" = 200 ]; then echo "OK"; exit 0; else echo "Not responding.Please check."; exit 2; fi
After running the NRPE check, check /tmp/curl_nrpe_debug.log—it will show exactly why curl is failing (connection refused, timeout, SSL errors, etc.).
5. Verify NRPE Configuration
Double-check that your NRPE command is correctly defined with an absolute script path:
command[check_registry]=/usr/local/nagios/libexec/check.sh
Also, ensure that NRPE is allowed to execute this command—confirm dont_blame_nrpe=1 is set in nrpe.cfg if needed, and that your Nagios Core server is listed in allowed_hosts.
内容的提问来源于stack exchange,提问作者Dinuka Kavinda

