Zabbix alerting
You can create Grafana alert rules that evaluate Zabbix metrics and trigger notifications when conditions are met. This lets you combine Zabbix monitoring data with Grafana alerting features such as contact points, notification policies, and silences.
Before you begin
- Configure the Zabbix data source.
- Understand Grafana Alerting.
Supported query types
The following query types can be used in alert rules:
- Metrics: query numeric time series data by group, host, and item.
- Item ID: query numeric data by specific Zabbix item IDs.
Other query types (Problems, Triggers, Services, Text, User macros) are not supported and return an error when used in alert rules.
Functions in alert rules
Data processing functions are evaluated in the backend, so they work in alert rules. You can use transform functions (groupBy, scale, delta, rate, movingAverage, and others), aggregate functions (aggregateBy, sumSeries, percentileAgg), filter functions (top, bottom, sortSeries), and time functions (timeShift).
The following functions are skipped during alert evaluation because they only affect display or are resolved by the frontend:
- Alias functions:
setAlias,setAliasByRegex, andreplaceAliaschange display names but not the underlying data. consolidateByandtrendValueare applied by the frontend or the Direct DB Connection path and have no effect on backend alert evaluation.
Two functions are especially useful when writing alert queries:
- Use
groupBy(interval, avg)to align raw data points to a consistent step before the alert condition reduces them. This smooths noisy collection intervals and makes thresholds predictable. - Use
aggregateByorsumSeriesto collapse multiple series into a single series when you want one alert instance instead of one per host or item. See Multi-dimensional alerts.
Create an alert rule
To create an alert rule using Zabbix data:
- Open a dashboard panel that uses the Zabbix data source with a Metrics or Item ID query.
- Click the panel title and select Edit.
- Click the Alert tab.
- Click Create alert rule from this panel.
- Configure the alert condition, evaluation interval, and notification settings.
- Click Save rule and exit.
For detailed instructions on configuring alert rules, evaluation groups, contact points, and notification policies, refer to the Grafana Alerting documentation.
Example alert rules
The following examples show how to combine a Zabbix query with the Grafana expression pipeline. In each case, query A returns the Zabbix data, a Reduce expression collapses the series to a single value per evaluation, and a Threshold expression defines the alert condition.
Alert on high CPU load for a single host
Alert when the average CPU load on a web server stays above 5.
- Add a Metrics query (A):
- Group:
Linux servers - Host:
web01 - Item:
CPU load - Add the function
groupBy(1m, avg)to align data points to a 1-minute step.
- Group:
- Add a Reduce expression (B): Function
Last, InputA. - Add a Threshold expression (C): Input
B, IS ABOVE5. - Set C as the alert condition.
Alert on low free memory across a host group
Create a separate alert for every host in a group whose available memory drops below 500 MB.
- Add a Metrics query (A):
- Group:
Linux servers - Host:
/.*/ - Item:
Available memory
- Group:
- Add a Reduce expression (B): Function
Last, InputA. - Add a Threshold expression (C): Input
B, IS BELOW524288000.
Because the Host field matches multiple hosts, this rule produces one alert instance per host. For more information, refer to Multi-dimensional alerts.
Alert on a specific item by ID
When you know the exact item you want to monitor, use an Item ID query to avoid regex matching.
- Add an Item ID query (A):
- Item Ids:
23456
- Item Ids:
- Add a Reduce expression (B): Function
Mean, InputA. - Add a Threshold expression (C): Input
B, IS ABOVE your threshold value.
Alert on an aggregated total across hosts
Alert on a single value that combines many series, such as total inbound traffic across a group of routers.
- Add a Metrics query (A):
- Group:
Network devices - Host:
/.*/ - Item:
Inbound traffic - Add the function
sumSeries()to combine all matching series into one.
- Group:
- Add a Reduce expression (B): Function
Last, InputA. - Add a Threshold expression (C): Input
B, IS ABOVE your threshold value.
Because sumSeries() collapses the data into a single series, this rule produces one alert instance for the whole group.
Multi-dimensional alerts
Grafana alerting creates one alert instance per series returned by the query. A Metrics query that matches multiple hosts or items with regex therefore generates a separate alert for each matching series, each with its own set of labels. This is useful when you want per-host notifications from a single rule.
If you instead want a single alert for a group of series, use aggregateBy or sumSeries() in the query to reduce the data to one series before the alert condition evaluates it.


