Checkmk packages created
by the community

Extend your Checkmk monitoring with packages created by community members. Or create your own packages and share the here with the rest of the community.

Recently added

  • by sebfeldm

    A Checkmk special agent that monitors the expiration of Microsoft Entra (Azure AD) app registration client secrets via the Microsoft Graph API, so you can rotate them before they expire and break an integration. What it does Queries all app registrations in a tenant and finds those with client secrets (passwordCredentials). Creates one service per app registration, named "Graph Secret" followed by the app's name. Reports the remaining validity of the secret expiring next, with configurable WARN/CRIT thresholds (default 30 / 14 days). Full details for all of an app's secrets in the service output; optional regex exclude list for secrets you don't want monitored. Requirements Checkmk 2.3+ (plug-in API v2) A dedicated Entra app registration with the Application.Read.All application permission (admin consent required) Free, MIT-licensed. Full setup guide (Entra app registration walkthrough, install via git or .mkp, WATO configuration) in the README: https://github.com/sebfeldm/checkmk/tree/main/special_agents/check_graph_secrets

  • by alex23

    This MKP is an early version and not final yet. Feedback, suggestions, and improvements are very welcome. The VMware Avi Special Agent monitors: - Alerts - Certificates - Clouds - Controller clusters and nodes - Pools - Service Engines using piggyback data - Virtual Services The package includes configurable monitoring rules, performance metrics, graph definitions, and a preconfigured dashboard for VMware Avi environments. **When upgrading from version 0.2.0, existing VMware Avi Special Agent and Virtual Service rules must be deleted before the update and recreated afterward. Version 0.2.0 also contains a severe parsing error and should no longer be used.** For installation instructions, configuration details, monitored metrics, upgrade notes, and the complete changelog, see the linked GitHub repository.

  • by rsander

    This alert handler automatically acknowledges host or service problems. It uses the REST-API wrapper from https://exchange.checkmk.com/p/check-mk-api

  • by Kuhn-Ruess-GmbH

    Monitoring of Aruba Central access points. An agent plug-in (Linux and Windows) calls the Aruba Central CLI (cencli show aps -v --json) and turns its output into one piggyback host per access point. Services: AP status, connected clients, CPU utilization, memory, uptime and one service per radio with channel utilization and TX power. A collector service reports the access point counts and the remaining API calls of Aruba Central. Includes host labels for group, site and model, a hardware/software inventory, check parameters, metrics and an agent bakery rule.

  • by Kuhn-Ruess-GmbH

    Runs the mk_logwatch of the Checkmk agent as another user through sudo, so logfiles that the agent user cannot read are still monitored. The typical case is a non-root agent deployment, where mk_logwatch has to read the logfiles as root. It does not replace mk_logwatch and it does not ship a copy of it. The rule "Text logfiles (Linux, UNIX, Windows)" keeps deploying and configuring mk_logwatch as before, logwatch.cfg and logwatch.d are untouched, and the output reaches the agent unchanged, so the existing logwatch services keep working. The included bakery rule "Run mk_logwatch as another user (sudo)" deploys the wrapper and its configuration. On its first run the wrapper takes the execute bit off the mk_logwatch that the agent package delivered, so the agent does not run it a second time as the agent user and report every message twice. Only the mode of that file is changed - it is not moved, renamed or deleted. An agent update puts the bit back and the next agent call removes it again. Every change is written to mk_logsudo.log in the state directory of the agent, together with the command to undo it. Prerequisite: the agent user needs a sudo rule for the wrapper. The bakery rule writes it to /etc/sudoers.d/check_mk_mk_logsudo when the agent user and the agent plug-in directory are configured; an agent that runs as root needs none. If sudo refuses the call, the plug-in reports this in the agent output together with the exact line that is needed, and "mk_logsudo.py --diag" prints it on the host as well. Supported: Checkmk 2.4 and 2.5, Linux only (no Windows, AIX or Solaris), Python 3.6 or newer on the monitored host. Note that sudo does not pass the address of the Checkmk server on, so mk_logwatch keeps one state file instead of one per server - this only matters when several Checkmk servers query the same host.

Most downloaded

  • by rsander

    Agent Plugin to check SSL certificates in specified directories Now with support to check signature algorithm Windows Plugin added JSON data in agent data section Is now able to ignore certificates with a short lifetime

  • by simonmeggle

    Robotmk integrates Robot Framework results into Checkmk.

  • by lgbff

    This check monitors the status of ssl cert checks on ssllab.com. Changelog: - 3.2.0 no systemtime in agent output - 3.x version for cmk 2.2 - 2.1.0 change to python3 - 2.0.1 fix datasource_programm group definition - 2.0.0 insert cache for api response - 1.6.0 insert Agent status (line[3]) - 1.5.3 change default status - 1.5.2 Insert Agent Header infos - 1.5.1 cache default settings - 1.5.0 new data seperator (59) - 1.4.9 fix display JSON Error on check result. - 1.4.8 fix connect exeption - 1.4.7 add default value for timeout - 1.4.6 change timeout handling - 1.4.5 fix inventory issue while JSON issues - 1.4.4 change urlopen error handling - 1.4.3 Rename check file - 1.4.2 Fix check manpage - 1.4.1 delete modul calls from check - 1.4.0 changes for cmk version 1.4 - 1.3.1 improve error handling.

  • by rsander

    Plugin to gather Ceph statistics. ### Starting with Checkmk 2.4, this plug-in is distributed with Checkmk. No need to download this MKP. Use this MKP only if you want to monitor Ceph with Checkmk 2.2 or 2.3. ###

  • by lgbff

    group of checks to monitor checkpoint firewalls