All Apps and Add-ons

SNMP Modular Input: I created an input stanza to capture traps, but why is the data not getting indexed in Splunk?

monteirolopes
Communicator

Hi,

I created a input stanza using app "SNMP Modular Input" to catch traps (Data Inputs->SNMP->New).

My device is already sending traps to my server (I can see it on wireshark), but the data is not being indexed in Splunk.

Any suggestion? I need to do some extra setup?

Followed this blog that I used as a reference:
http://blogs.splunk.com/2013/06/27/making-snmp-simpler/

Best Regards,
Lopes.

0 Karma
1 Solution

monteirolopes
Communicator

Damien Dallimore,

My problem was that I had a SNMP service running on the Splunk server and it was already bound to the 162 port.
Now my inputs are working.

Thank you!

Best regard,
Lopes.

View solution in original post

0 Karma

Hemnaath
Motivator

Hi monteirolopes, hey we got a request from a client to configure an Cisco Prime SNMP Trap Monitoring in splunk. To start with I need to create an Inputstanza which has the index=network sourcetype=cisco:network:primesnmp.

Could please guide me how to setup a monitoring for capturing the SNMP trap in splunk.

thanks in advance.

0 Karma

monteirolopes
Communicator

Damien Dallimore,

My problem was that I had a SNMP service running on the Splunk server and it was already bound to the 162 port.
Now my inputs are working.

Thank you!

Best regard,
Lopes.

0 Karma

Damien_Dallimor
Ultra Champion

Try setting your trap_host to the fully qualified domain name that the trap is being sent to , or IP address etc...

0 Karma

monteirolopes
Communicator

I set the field trap_host with the hostname+domain and / or IP address and still didn't work .
Another suggestion?

0 Karma

Damien_Dallimor
Ultra Champion

Post your inputs.conf stanza

monteirolopes
Communicator

Follow my inputs.conf

[snmp://trap]
communitystring = public
do_bulk_get = 0
do_get_subtree = 0
index = networkdevices
ipv6 = 0
snmp_mode = traps
snmp_version = 2C
sourcetype = cisco:trap
split_bulk_output = 0
trap_host = deviceip
trap_port = 162
trap_rdns = 0
v3_authProtocol = usmHMACMD5AuthProtocol
v3_privProtocol = usmDESPrivProtocol

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...