Enter your own Checkmk ideas or vote for existing ones
In order to continually improve Checkmk, we're looking for your ideas. They provide valuable input to our roadmap discussions and allow us to contact you directly for more in-depth discussions or during development. A few tips:
- Concisely describing the problem rather than the solution will help other users understand and relate to your idea.
- An idea should be easy to understand. This will increase your chances of getting votes.
- Be as specific as possible. Knowing exactly what to expect when voting on an idea makes it a much better experience for all of us when it is adapted later in Checkmk.
Further information can be found in this guide. If you have any questions, please send an email to ideas@checkmk.com.
LDAP: In Distributed/MSP Setups, Test AD/LDAP Connections on the Effective Remote Site
In distributed and MSP environments, it is currently not possible to test the effective LDAP connection of a remote site from the central site. This becomes ...
SAML: SCIM Provisioning
It would be nice if CheckMK supported SCIM provisioning. The login via SAML syncs at login time, which is nice, but about half of our users never log into CheckMK so ...
[ROLES] Apply changes page and icon to be shown/hidden via dedicated permission
Actually it is possible for any user to see the "apply changes" icon in the top right of the GUI even if that user has no permission to apply changes.
Obviously, ...
User management: test LDAP connection without saving (dry run) & preview detected users
Hey,
we had some ideas regarding "user management" / "LDAP"
- Add the ability to test an LDAP connection without saving. Currently there is only "Save" and "Save ...
User Management: icon to permanently delete a user from user list
Hey,
we had some ideas regarding "user management" / "LDAP"
- Add a button in each user row (maybe a red recycle icon) that allows (the admin) to permanently ...
User Management: auto-disable users if LDAP connection is deactivated
Hey,
we had some ideas regarding "user management" / "LDAP"
- If an LDAP connection is deactivated, the users that originate from this binding should be disabled ...
SAML SSO: Bypass "Login with SAML" button for seamless SSO (autologin)
Single Signon can be obtained by enabling SAML, whilst other application(s) log you into the application itself by just clicking the link from
some INTRANET portal ...
PUT/PATCH for SAML connections
The SAML connection endpoint currently allows Create, Read and Delete, but it does not seem to support Update (PUT/PATCH) according to the API documentation.
Would ...
User Messages - add "Delete all" Button
$sitecheck_mk/user_message.py
Due to different reasons there are piling up user messages from time to time. might be 5, might be 10 or into the hundrets. ...
Role permission matrix: compare specific roles only
Proposition to extend the user role permission matrix.
With more than the default user roles (and even only with them), the permission matrix gets more and more ...
Make "Authorized Sites" for new users empty or configurable via default user profile
When using external authentication a user is created if it does not exist, but the default "Authorized sites" is "All sites", i'd like to modify this behavior to an ...
Create Contact Groups by LDAP Groups
Hello everyone,
currently we have to manually create Contact Groups with the same name as the groups in our LDAP system.
I would prefer to have an option to sync ...
the Option to hide the Service Check command for Roles ...
the possibility to hide service check command in the service view for different roles
Background to hide user names and passwords e.g. from Classic Checks for ...
map mobilephone to pager in SAML
https://forum.checkmk.com/t/map-mobilephone-to-pager-address/43662
I would love to map the user.mobilephone to the pager attribute in cmk user
First logon with SAML - automatic activation
If a new user logins with the SAML connection the first time, then an admin needs to activate the change before the user can access hosts and services.
It should be ...
Add support for SAML authentication with distributed sites
See ticket:
https://forum.checkmk.com/t/saml-authentication-distributed-monitoring/42839
Configure "Authorized Sites" for LDAP accounts based on LDAP group membership
The authorized sites for an LDAP account should also be "syncable" from LDAP groups like for contact groups and roles.
SAML2 for existing users (no new creation)
Currently, you can only create new users with SAML2 via EntraID, but not authenticate existing ones (e.g. which are already synchronized via LDAP anyway and the ...
Add OpenID-Connect support
It would be wishful to have CMK (Enterprise) support OIDC as a federative method next to SAML.
Also because some public cloud-services only support(or prefer) ...
Two-factor authentication via SafeNet 5110+
2FA support support SafeNet 5110+
Move/Get Debug UI Option as User Profile Option
The Global settings - User interface - Debug Mode Option would be nice as a User Profile Option IMHO. Actually it can switched on/off which applies for all user and ...
Better visualization of derived roles
When creating a role by deriving it from an existing one, the role overview shows a column "Modifications", giving the number of permissions deviating from the source ...
Make Dashboards editable for other users
It would be great when users (members of a usergroup or a contactgroup) can edit a published dashboard.
Allow menu overwrites in user menu
When using non-local users it would be nice to change the links from the user menu to external source for change of password and 2fa config. Allow to set per login ...
Mass editing of User attributes
If you have to add/change/remove attributes for a group of users, it can quickly become very time-consuming.
It would be very helpful if you could search for users ...
Setup: Users GUI: show users with insecure password in an upper Warning list
Like shown in the update message of (cmk-update-config):
16/29 Check for insecure password hashes, enforce password reset...
Please show up the info as upper ...
Support for LDAP via StartTLS
Currently, Checkmk has the option to securely connect to LDAP servers for user sync via “LDAPS”, also known as “LDAP over TLS/SSL”, which can be activated by ticking ...
Define "contact group" in "LDAP Connection" like roles
Migrated from the forum.
Reference: https://forum.checkmk.com/t/define-contact-group-in-ldap-connection/15249
Currently, to associate “contact groups” with LDAP ...
LDAP Sync - set defaults per connection
Unfortunately it is not always possible to define the user attributes like groups, roles etc. in the LDAP.
Therefore it would be very helpful if you could define ...
LDAP Sync: Failsafe in case of too many deleted Users
Suddenly all users have disappeared from the LDAP Group and the LDAP sync removed them from Checkmk including all manually entered settings. Even if the users are ...
Mark dashboard/reports/views as global so they don't get deleted with users or allow bulk migration
As it is you are forced to clone a view and delete the old one for a user to take ownership.
An alternative is to copy user_*.mk files in cli under ...
Set time zones user-based
Currently, the time zone for CheckMK is used from the operating system. There should be an option for each user to choose their own time zone.
Show last login also on central site in a distributed setup
It may happen in a distributed setup, that users will log in on a remote instance of Checkmk, only. In this case, the last login is also logged on the remote ...
Hide Setup rules within folders without permission to users
As of now, Setup folders can be hidden from users, so that hosts within these folders are invisible to them.
This does not apply to Setup rules for said hidden ...
Make permission matrix exportable
For auditing purposes, a report showing all roles and the assigned permissions would be helpful
Impersonate as another user to check views and dashboards
Allow an admin to impersonate himself as another user, so he/she can see & verify views/dashboards, as the other user will see them. This helps to develop views or ...
Define user roles and permissions per host group and/or setup folders
This allows to have admin permissions for one set of hosts and viewer permissions on a different set. A set can be defined per host group and/or per setup folder
Simplify complex permission management
Challenge: If I have many users, which require only a very limited set of permissions, it is quite challenging to take existing rules and remove the unnecessary ...