<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk use SNMP on 161? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58934#M11622</link>
    <description>&lt;P&gt;Okay cool!&lt;/P&gt;</description>
    <pubDate>Thu, 13 Sep 2012 10:26:04 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2012-09-13T10:26:04Z</dc:date>
    <item>
      <title>Does Splunk use SNMP on 161?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58930#M11618</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a customer who is currently doing some compliance scanning, and have found port 161, SNMP Server, open for various periods throughout the day.  Is Splunk guilty of this or does Splunk not use port 161 in this fashion?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 09:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58930#M11618</guid>
      <dc:creator>weevil</dc:creator>
      <dc:date>2012-09-13T09:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk use SNMP on 161?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58931#M11619</link>
      <description>&lt;P&gt;Splunk does not directly use SNMP. It may be an SNMP daemon that is running on the same server, ref the following for the splunk recommended practice &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventstoSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventstoSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Is it a *nix platform? - If so you can use netstat and ps to locate some more information...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;netstat -antp | egrep '161|162'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will show you what processes are using those ports, you can then find the PID in this information and use that in a &lt;CODE&gt;ps&lt;/CODE&gt; search...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ps -ef | grep &amp;lt;PID&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 13 Sep 2012 10:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58931#M11619</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-09-13T10:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk use SNMP on 161?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58932#M11620</link>
      <description>&lt;P&gt;Splunk does not use port 161.&lt;/P&gt;

&lt;P&gt;See this recent answer regarding "Splunk"'s SNMP functionality: &lt;A href="http://splunk-base.splunk.com/answers/58537/what-version-of-splunk-can-receive-traps-via-snmpv3"&gt;http://splunk-base.splunk.com/answers/58537/what-version-of-splunk-can-receive-traps-via-snmpv3&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 10:06:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58932#M11620</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-13T10:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk use SNMP on 161?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58933#M11621</link>
      <description>&lt;P&gt;I will have a look and see if it is a Daemon or something untoward doing the SNMP.  I guess this is why PCI Compliance exists &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 10:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58933#M11621</guid>
      <dc:creator>weevil</dc:creator>
      <dc:date>2012-09-13T10:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk use SNMP on 161?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58934#M11622</link>
      <description>&lt;P&gt;Okay cool!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 10:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-use-SNMP-on-161/m-p/58934#M11622</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-09-13T10:26:04Z</dc:date>
    </item>
  </channel>
</rss>

