Zabbix going crazy with modified /etc/passwd
This morning i was awakened by multiple alarm emails sent by our zabbix agent monitoring system, telling us that /etc/passwd was being modified. The agent sent us an email for every one of our droplets (debian 9 stretch).
After the initial scare, i checked the apt logs and it seems that do-agent service was upgraded silently:
apt-get -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold -qq install -y --only-upgrade do-agent
No other alarms were going off, and everything seems to be working nominal.
I think the changes to /etc/passwd were made to the do-agent user during the upgrade process, but i would like to know from you guys if this is actually the case.
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.×