<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to capture snmp traps in splunk ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325766#M60565</link>
    <description>&lt;P&gt;Hi Woodcock, I tried to install the app from splunk base on my test machine, after installing the app, I had followed the below steps to capture the CISCO PRIME SNMP traps.&lt;/P&gt;

&lt;P&gt;Steps:&lt;BR /&gt;
1) Manager--&amp;gt;settings--&amp;gt;datainputs--snmp--new&lt;/P&gt;

&lt;P&gt;2) SNMP Mode was set as "Listen for traps" &lt;/P&gt;

&lt;P&gt;3) SNMP Version kept as "2c"&lt;/P&gt;

&lt;P&gt;4) Community String as "Public"&lt;/P&gt;

&lt;P&gt;5) Custom MIBs - "Left Blank"&lt;/P&gt;

&lt;P&gt;6)  Custom Response Handling&lt;BR /&gt;
         Response Handler --&amp;gt; Left Blank&lt;BR /&gt;
         Response Handler Arguments --&amp;gt; Left Blank&lt;/P&gt;

&lt;P&gt;7) SNMP Trap listener settings &lt;BR /&gt;
     TRAP listener host " 10.X.X.X"  --&amp;gt; Heavy Forwarder IP Address&lt;BR /&gt;
      TRAP listener port   "162" &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;  Reverse DNS lookup of trap sources. --&amp;gt; Left this option "unchecked"&lt;/P&gt;

&lt;P&gt;9) Source type  set to Manual &lt;/P&gt;

&lt;P&gt;10) sourcetype : network:cisco:primesnmp&lt;/P&gt;

&lt;P&gt;11) More settings -- &amp;gt; In this setting, I would like to set the index name as network.&lt;/P&gt;

&lt;P&gt;Question :&lt;/P&gt;

&lt;P&gt;1)How to set the index=network in the more settings ?&lt;BR /&gt;
2) After saving the settings where I can see the inputs.conf stanza in this app. I mean from /opt/splunk/etc/apps/snmp_ta&lt;BR /&gt;
3) Which option is better to capture the snmp traps, whether by using the snmptrapd or by using this app.&lt;/P&gt;

&lt;P&gt;Kindly guide me on this. &lt;BR /&gt;
thanks in advance.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Dec 2017 17:21:10 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2017-12-09T17:21:10Z</dc:date>
    <item>
      <title>How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325762#M60561</link>
      <description>&lt;P&gt;Hi All, I have told to configure one of the Heavy forwarder instance to receive and index the CISCO prime traps. i had gone through the links &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.0/Data/SendSNMPeventstoSplunk"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.0/Data/SendSNMPeventstoSplunk&lt;/A&gt;  provide in the splunk documentation.&lt;BR /&gt;
 but I am not sure how to install / configure the snmptrapd to capture the remote data.&lt;/P&gt;

&lt;P&gt;Question:&lt;/P&gt;

&lt;P&gt;1) From where I need to download the snmptrapd ? Please provide me the link. &lt;BR /&gt;
2) My Heavy forwarder running on top of  Linux version  "Red Hat Enterprise Linux Server release 7.3 (Maipo)" 64 bit OS, so what version of snmptrapd will be compatible ?&lt;BR /&gt;
3) How to  configure the snmptrapd to capture  from cisco prime traps? where to configure this  two stanza in snamptrapd.&lt;/P&gt;

&lt;P&gt;snmptrapd -Lf /var/log/snmp-traps&lt;BR /&gt;
snmptrapd -Lf /var/log/snmp-traps --disableAuthorization=yes&lt;/P&gt;

&lt;P&gt;4) Once snaptrapd is configured, I will be configuring the below inputs.conf stanza, so that splunk can read the trap from this location in heavyforwarder.&lt;/P&gt;

&lt;P&gt;inputs.conf &lt;BR /&gt;
[monitor:///var/log/snmp-traps*] &lt;BR /&gt;
index=network&lt;BR /&gt;
sourcetype=network:cisco:primesnmp&lt;/P&gt;

&lt;P&gt;Kindly guide me on the above questions.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 15:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325762#M60561</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-08T15:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325763#M60562</link>
      <description>&lt;P&gt;Hi All, Can any one guide me on this ?????&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 17:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325763#M60562</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-08T17:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325764#M60563</link>
      <description>&lt;P&gt;You need the &lt;CODE&gt;SNMP Modular Input&lt;/CODE&gt; app by @damiendallimore:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1537/"&gt;https://splunkbase.splunk.com/app/1537/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 04:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325764#M60563</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-12-09T04:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325765#M60564</link>
      <description>&lt;P&gt;Hi Woodcock, thanks for your support on this, yes i have gone through the link but my requirement is to configure one of the splunk Heavy forwarder instances to receive and index the CISCO prime traps and at the same time I need to have this index=network and sourcetype=network:cisco:primesnmp details configured in inputs.conf stanza.  &lt;/P&gt;

&lt;P&gt;Kindly guide me whether we can do this via SNMP Modular Input app. &lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 05:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325765#M60564</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-09T05:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325766#M60565</link>
      <description>&lt;P&gt;Hi Woodcock, I tried to install the app from splunk base on my test machine, after installing the app, I had followed the below steps to capture the CISCO PRIME SNMP traps.&lt;/P&gt;

&lt;P&gt;Steps:&lt;BR /&gt;
1) Manager--&amp;gt;settings--&amp;gt;datainputs--snmp--new&lt;/P&gt;

&lt;P&gt;2) SNMP Mode was set as "Listen for traps" &lt;/P&gt;

&lt;P&gt;3) SNMP Version kept as "2c"&lt;/P&gt;

&lt;P&gt;4) Community String as "Public"&lt;/P&gt;

&lt;P&gt;5) Custom MIBs - "Left Blank"&lt;/P&gt;

&lt;P&gt;6)  Custom Response Handling&lt;BR /&gt;
         Response Handler --&amp;gt; Left Blank&lt;BR /&gt;
         Response Handler Arguments --&amp;gt; Left Blank&lt;/P&gt;

&lt;P&gt;7) SNMP Trap listener settings &lt;BR /&gt;
     TRAP listener host " 10.X.X.X"  --&amp;gt; Heavy Forwarder IP Address&lt;BR /&gt;
      TRAP listener port   "162" &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;  Reverse DNS lookup of trap sources. --&amp;gt; Left this option "unchecked"&lt;/P&gt;

&lt;P&gt;9) Source type  set to Manual &lt;/P&gt;

&lt;P&gt;10) sourcetype : network:cisco:primesnmp&lt;/P&gt;

&lt;P&gt;11) More settings -- &amp;gt; In this setting, I would like to set the index name as network.&lt;/P&gt;

&lt;P&gt;Question :&lt;/P&gt;

&lt;P&gt;1)How to set the index=network in the more settings ?&lt;BR /&gt;
2) After saving the settings where I can see the inputs.conf stanza in this app. I mean from /opt/splunk/etc/apps/snmp_ta&lt;BR /&gt;
3) Which option is better to capture the snmp traps, whether by using the snmptrapd or by using this app.&lt;/P&gt;

&lt;P&gt;Kindly guide me on this. &lt;BR /&gt;
thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 17:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325766#M60565</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-09T17:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325767#M60566</link>
      <description>&lt;P&gt;Hi Woodcock,  hey I had downloaded the snmptrapd from this link &lt;A href="https://sourceforge.net/projects/net-snmp/files/net-snmp/5.7.3/"&gt;https://sourceforge.net/projects/net-snmp/files/net-snmp/5.7.3/&lt;/A&gt;  but I am not sure how to install this package in linux os .&lt;/P&gt;

&lt;P&gt;"Download net-snmp-5.6.1.1-1.x86.exe (4.2 MB)" &lt;/P&gt;

&lt;P&gt;Kindly let me know how to install this in linux&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 18:46:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325767#M60566</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-09T18:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325768#M60567</link>
      <description>&lt;P&gt;@Hemnaath Custom MIBs - you may get from source Cisco device's management portal - download them and place them to your splunk instance machine (HF)  at snmp_ta/bin/mibs location &lt;/P&gt;

&lt;P&gt;1)How to set the index=network in the more settings ?&lt;/P&gt;

&lt;P&gt;Under more settings - to highlight 'network' as index name - you first have to create this  'network' index on splunk. indexer. &lt;BR /&gt;
Go to indexer machine Settings &amp;gt; indexes &amp;gt; create new index &amp;gt; name and give location of hot/warm/cold buckets. &lt;BR /&gt;
now come to snmp settings page and then you will get "network" as index listed under this.&lt;/P&gt;

&lt;P&gt;2) After saving the settings where I can see the inputs.conf stanza in this app. I mean from /opt/splunk/etc/apps/snmp_ta&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/snmp_ta&lt;BR /&gt;
inside this location, create a new directory named 'local'&lt;BR /&gt;
create a new file here and name it "inputs.conf" for any data collection&lt;/P&gt;

&lt;P&gt;3) Which option is better to capture the snmp traps, whether by using the snmptrapd or by using this app.&lt;/P&gt;

&lt;P&gt;Both ways are right - use one which suits your requirements. I would prefer app. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 11:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325768#M60567</guid>
      <dc:creator>saurabh_tek11</dc:creator>
      <dc:date>2017-12-10T11:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325769#M60568</link>
      <description>&lt;P&gt;@Hemnaath - &lt;BR /&gt;
you are using Red Hat Enterprise Linux Server release 7.3 (Maipo)" 64 bit OS on HF. then .exe fileformat is not for you.&lt;/P&gt;

&lt;P&gt;You may download some .gz file version which you can untar in linux OS &lt;BR /&gt;
tar xvzf -C &lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 11:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325769#M60568</guid>
      <dc:creator>saurabh_tek11</dc:creator>
      <dc:date>2017-12-10T11:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325770#M60569</link>
      <description>&lt;P&gt;Hi saurabh , thanks for your support, can you please provide me the link and exact file to download from the site. &lt;/P&gt;

&lt;P&gt;thank in advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 12:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325770#M60569</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-10T12:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325771#M60570</link>
      <description>&lt;P&gt;hi saurabh, In our production environment we have already indexing other network related device data in to the index=network. &lt;/P&gt;

&lt;P&gt;But when I tested in my personal laptop after providing the required details I could see the inputs.conf file being placed under this folder /opt/splunk/etc/apps/launcher/local/inputs.conf.  can I copy the same and place it in the /opt/splunk/etc/apps/snmp_ta/local/inputs.conf. &lt;/P&gt;

&lt;P&gt;I am not sure about the custom MIB, So can I leave that option blank will there be any impact because of it.&lt;/P&gt;

&lt;P&gt;Please guide me whether the above steps are correct to capture the remote CISCO prime snmp into the Heavy forwarder instance using the app.&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 12:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325771#M60570</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-10T12:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325772#M60571</link>
      <description>&lt;P&gt;Hi All, I have successfully download and installed the snmptrap with the help of linux administrator.  &lt;/P&gt;

&lt;P&gt;From the below site you can  download the snmptrapd.rpm  for  "Red Hat Enterprise Linux Server release 7.3 (Maipo)" 64 bit OS. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://rpm.pbone.net/index.php3"&gt;http://rpm.pbone.net/index.php3&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Questions :&lt;/P&gt;

&lt;P&gt;1) Should I need add any other configuration details in /etc/snmp/snmptrapd.conf &lt;/P&gt;

&lt;H1&gt;TRAPD BEHAVIOUR&lt;/H1&gt;

&lt;P&gt;snmpTrapdAddr udp:127.0.0.1:162,udp6:[::1]:162&lt;BR /&gt;
doNotLogTraps no&lt;/P&gt;

&lt;H1&gt;ACCESS CONTROL&lt;/H1&gt;

&lt;P&gt;authCommunity log,execute,net solarwinds&lt;BR /&gt;
disableAuthorization no&lt;/P&gt;

&lt;H1&gt;NOTIFICATION PROCESSING&lt;/H1&gt;

&lt;H1&gt;OTHER CONFIGURATION&lt;/H1&gt;

&lt;P&gt;2) What configuration details should be added under this file /etc/sysconfig/snmptrapd.  &lt;/P&gt;

&lt;H1&gt;snmptrapd command line options&lt;/H1&gt;

&lt;P&gt;OPTIONS="-Lsd"&lt;/P&gt;

&lt;P&gt;Kindly guide me on this. &lt;BR /&gt;
thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 17:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325772#M60571</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-10T17:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to capture snmp traps in splunk ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325773#M60572</link>
      <description>&lt;OL&gt;
&lt;LI&gt;That input is coming at /opt/splunk/etc/apps/launcher/local/inputs.conf because you made the settings changes in UI Manager--&amp;gt;settings--&amp;gt;datainputs--snmp--new
ALthough the movement is not needed as this is your test env. but if you move that wont affect anything except at later point of time if you revisit it under ta_snmp this inputs.conf shall clearly indicate what inputs its used for(as this is under snmp). &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;MIB is about explanation of some codes.. like http 200 means OK. It adds value for sake of better understanding and clarity. \&lt;/P&gt;

&lt;P&gt;steps seems to be correct. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 18:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-capture-snmp-traps-in-splunk/m-p/325773#M60572</guid>
      <dc:creator>saurabh_tek11</dc:creator>
      <dc:date>2017-12-10T18:59:27Z</dc:date>
    </item>
  </channel>
</rss>

