All Apps and Add-ons

SNMP Modular Input not showing remote IP

DoD_MI
New Member

Hi All,

I have just installed SNMP Modular Input and started to receive some SNMP traps. I can see some SNMP packets coming in but the problem is that the reporting IP is not shown in the output. I have no idea which remote IP is sending which traps. All I see is "host=None" in the snmp trap data.

Any suggestions as to what I am doing wrong would be gratefully received.

Tags (2)
0 Karma

nit123
Path Finder

This could be an issue with the fact that when you upgraded to splunk 'X' version and have an app installed which is not supported in that version. You should uninstall this X version of app and restart Splunk to see inputs

0 Karma

sirsyedian
New Member

I am having the same issue. Splunk is receivign SNMP traps for multiple servers but I can't seem to find a way to differentiate them as they all have 'host=None' in the data.
Did you find a way to find the remote server details from the events?

0 Karma

fab73
Path Finder

Just a suggestion : Try configureing trapping of the correct OID on the Switch (Object Names List : iso.org.dod.internet.mgmt.mib-2.system.... )

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...