Checkmk is an infrastructure monitoring system that discovers the services running on each host (CPU, memory, filesystems, network interfaces, systemd units and more) and applies thresholds through rules instead of hand-written check definitions. In this tutorial you will install the free Checkmk Raw edition on Ubuntu 24.04, create a monitoring site, install the Checkmk agent on a Linux host, register it over TLS, run service discovery and activate the changes so the host is monitored.
Prerequisites
To follow this guide you need:
- A server for Checkmk running Ubuntu 24.04 LTS with at least 2 CPU cores, 4 GB of RAM and 20 GB of free disk, for example a CubePath VPS. It should not already run a web server on port 80.
- A second Linux server to monitor (Ubuntu 24.04 in the examples), referred to as
web01with the addresshost_ip. - A non-root user with
sudoprivileges on both servers. - UFW enabled on both servers with SSH allowed.
In the commands below, checkmk_ip is the address of the Checkmk server and monitoring is the name of the Checkmk site you will create.
Step 1 - Downloading the Checkmk package
Checkmk is distributed as a single .deb package per Ubuntu release, not through an APT repository. Go to the Checkmk download page, choose Checkmk Raw, Ubuntu and 24.04 (Noble Numbat), and note the current stable version, for example 2.4.0p12. Store it in a variable on the Checkmk server:
CMK_VERSION=2.4.0p12
Download the package for that version:
cd /tmp
wget "https://download.checkmk.com/checkmk/${CMK_VERSION}/check-mk-raw-${CMK_VERSION}_0.noble_amd64.deb"
Compare the checksum with the SHA256 value shown on the download page:
sha256sum "check-mk-raw-${CMK_VERSION}_0.noble_amd64.deb"
If the two values do not match, delete the file and download it again.
Step 2 - Installing Checkmk
Install the package with apt, which also pulls in its dependencies (Apache, Python libraries and others) from the Ubuntu archive:
sudo apt update
sudo apt install "./check-mk-raw-${CMK_VERSION}_0.noble_amd64.deb"
Checkmk is managed with the omd command (Open Monitoring Distribution). Check the installed version:
omd version
OMD - Open Monitoring Distribution Version 2.4.0p12.cre
The .cre suffix identifies the Raw edition.
Step 3 - Creating and starting a monitoring site
A site is an independent Checkmk instance with its own Linux user, configuration, web UI and data under /omd/sites/<name>. Create one called monitoring:
sudo omd create monitoring
Adding /opt/omd/sites/monitoring/tmp to /etc/fstab.
Creating temporary filesystem /omd/sites/monitoring/tmp...OK
Updating core configuration...
Generating configuration for core (type nagios)...
Precompiling host checks...OK
Executing post-create script "01_create-sample-config.py"...OK
Restarting Apache...OK
Created new site monitoring with version 2.4.0p12.cre.
The site can be started with omd start monitoring.
The default web UI is available at http://checkmk-01/monitoring/
The admin user for the web applications is cmkadmin with password: Xy7kP2qLm9Rt
Copy the generated cmkadmin password. Start the site:
sudo omd start monitoring
Verify that all of its components are running:
sudo omd status monitoring
agent-receiver: running
mkeventd: running
rrdcached: running
npcd: running
nagios: running
apache: running
redis: running
crontab: running
-----------------------
Overall state: running
The exact list of components depends on the version, but the overall state must be running.
Step 4 - Opening the firewall and logging in
The site's web UI is served by the system Apache on port 80, and the agent receiver that handles TLS registration of agents listens on port 8000 for the first site. Allow both:
sudo ufw allow 80/tcp
sudo ufw allow 8000/tcp
Open http://checkmk_ip/monitoring/ in your browser and log in as cmkadmin with the password from the previous step.
To replace the generated password with one of your own, switch to the site user and use cmk-passwd:
sudo su - monitoring
cmk-passwd cmkadmin
exit
NoteThe UI is served over plain HTTP. Before exposing it on the internet, put it behind HTTPS (for example with a Let's Encrypt certificate on Apache) or restrict port
80to your own IP withsudo ufw allow from your_ip to any port 80 proto tcp.
Step 5 - Installing the agent on the monitored host
Checkmk reads data from each host through the Checkmk agent. Every site serves the agent packages that match its own version. On web01, download the Debian package from the site, using the same version as the server:
CMK_VERSION=2.4.0p12
cd /tmp
wget "http://checkmk_ip/monitoring/check_mk/agents/check-mk-agent_${CMK_VERSION}-1_all.deb"
You can also find the exact file name in the web UI under Setup > Agents > Linux. Install it:
sudo apt install "./check-mk-agent_${CMK_VERSION}-1_all.deb"
The package installs the agent script, the agent controller cmk-agent-ctl and systemd units that listen on TCP port 6556. Check the controller:
sudo cmk-agent-ctl status
Version: 2.4.0p12
Agent socket: operational
IP allowlist: any
No connections
No connections means the agent is not registered yet. Allow the Checkmk server to reach the agent port, and only that server:
sudo ufw allow from checkmk_ip to any port 6556 proto tcp
Step 6 - Adding the host in Checkmk
In the web UI, go to Setup > Hosts and click Add host. Fill in:
- Host name:
web01 - IPv4 address:
host_ip(tick the checkbox next to the field to enable it)
Leave the other attributes at their defaults and click Save & view folder. Then click the yellow changes button in the top right corner and Activate on selected sites. Registration in the next step only works for hosts that already exist in the active configuration.
Step 7 - Registering the agent with TLS
Until it is registered, the agent answers in legacy mode, in plain text, to anyone allowed to connect. Registration creates a trust relationship with the site so all agent data is sent encrypted over TLS. On web01 run:
sudo cmk-agent-ctl register --hostname web01 --server checkmk_ip --site monitoring --user cmkadmin
The command shows the site's certificate details and asks you to confirm with Y, then asks for the cmkadmin password. Afterwards, check the status again:
sudo cmk-agent-ctl status
Version: 2.4.0p12
Agent socket: operational
IP allowlist: any
Connection: checkmk_ip:8000/monitoring
UUID: 6f2b9c4e-1a3d-4b8f-9e7a-0c5d2f1b3a47
Local:
Connection type: pull-agent
Certificate issuer: Site 'monitoring' local CA
Certificate validity: Wed, 24 Sep 2026 10:55:12 +0000 - Mon, 25 Jan 3025 10:55:12 +0000
Remote:
Connection type: pull-agent
Registration state: operational
Host name: web01
To confirm the Checkmk server can fetch agent data, switch to the site user on the Checkmk server and dump the agent output for the host:
sudo su - monitoring
cmk -d web01 | head -n 5
<<<check_mk>>>
Version: 2.4.0p12
AgentOS: linux
Hostname: web01
AgentDirectory: /etc/check_mk
Type exit to leave the site user's shell.
Step 8 - Discovering services and activating changes
Checkmk now needs to know which services to monitor on web01. In the web UI go to Setup > Hosts, click the host, then Save & run service discovery (or the Run service discovery entry in the host's menu). The page lists the services found, such as CPU load, Memory, Filesystem /, Interface eth0 and Systemd Service Summary. Click Accept all.
Activate the changes again with the changes button and Activate on selected sites. Go to Monitor > Overview > All hosts: after a minute web01 should be UP with its services mostly OK.
If you prefer the command line, the same discovery and activation can be run as the site user:
sudo su - monitoring
cmk -vI web01
cmk -O
exit
cmk -I adds newly found services, cmk -v prints what it found, and cmk -O regenerates the core configuration and reloads it.
Step 9 - Adjusting thresholds with rules
Checkmk applies thresholds through rules that can target all hosts, a folder or hosts with a given tag or label. For example, to warn when the root filesystem of any host passes 85% and go critical at 95%:
- Go to Setup > Services > Service monitoring rules and search for Filesystems (used space and growth).
- Click Add rule. Under Levels for used/free space, set the warning level to
85%and critical to95%. - Under Conditions, restrict Filesystem to the mount point
/if you only want it for the root filesystem, then Save. - Activate the changes.
The Filesystem / service on web01 now shows the new levels in its summary. The same pattern applies to CPU load, memory and every other check.
Step 10 - Backing up the site
Each site can be backed up to a single archive with omd backup, which includes its configuration and monitoring history. Create a backup directory and run it as root:
sudo mkdir -p /var/backups/checkmk
sudo omd backup monitoring /var/backups/checkmk/monitoring-$(date +%F).tar.gz
Check the archive:
ls -lh /var/backups/checkmk/
-rw-r--r-- 1 root root 18M Sep 24 11:20 monitoring-2026-09-24.tar.gz
To restore it on a server with the same Checkmk version, stop and remove the existing site if there is one, then run sudo omd restore /var/backups/checkmk/monitoring-2026-09-24.tar.gz. Copy the archives to another server or object storage so they survive the loss of this one.
Troubleshooting
- The web UI returns 404 or the site is not found: run
sudo omd status monitoring; if components are stopped, start them withsudo omd start monitoringand check/omd/sites/monitoring/var/log/for errors. - Registration fails with a connection error: port
8000is closed on the Checkmk server, or the host does not exist yet in the activated configuration. Open the port and activate changes before registering. - The host shows
Check_MKin CRIT with a connection refused or timeout: the firewall on the monitored host is blocking port6556fromcheckmk_ip. Test from the Checkmk server withnc -zv host_ip 6556. - Email notifications are not delivered: Checkmk sends email through the local mail system. Install and configure an MTA such as Postfix relaying through your SMTP provider, and set an email address for
cmkadminunder User > Edit profile.
Conclusion
You installed Checkmk Raw on Ubuntu 24.04, created a monitoring site, deployed and registered the Linux agent over TLS, discovered the host's services and adjusted thresholds with a rule. From here you can add more hosts (folders help keep them organized), configure notification rules under Setup > Events > Notifications, and schedule the omd backup command with a systemd timer or cron job.
