All Apps and Add-ons

SNMP Modular Input: Is it possible to listen for SNMP trap v2 and trap V3 at the same time on the same Splunk instance?

cafissimo
Communicator

Hello,

Please, I would like to know if it is possible to listen for snmp trap v2 AND snmp trap v3 on the same Splunk instance at the same time.

Thanks in advance.

0 Karma

Damien_Dallimor
Ultra Champion

You should be able to. Just setup 2 separate SNMP stanzas on different trap listening ports.

0 Karma

cafissimo
Communicator

Hello Damien,
thank you, but I need to set both listener (v2 and v3) on the same port, do you think this is feasible?
If not, is there any kind of workaround you suggest?
For example, I was thinking to create another network interface on the splunk host, then set v2 to listen on an interface, v3 on the other one and having packet forwarded via iptables from one interface to another.
With this config the v2 listener will discard v3 udp packets (but forward all traps to the other interface) and v3 listener will discard v2 packets and keep v3 packets.

0 Karma

Stevelim
Communicator

In case the SNMP Modular input dont work, check out Kepware's SNMP Driver. It is GUI driven, combined with the IDF, you can accquire and listen to the SNMP traps.

https://www.kepware.com/products/kepserverex/drivers/snmp/

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...