Getting Data In

Does Splunk use SNMP on 161?

weevil
New Member

Hi,

We have a customer who is currently doing some compliance scanning, and have found port 161, SNMP Server, open for various periods throughout the day. Is Splunk guilty of this or does Splunk not use port 161 in this fashion?

Thanks!

Tags (1)
0 Karma

Ayn
Legend

Splunk does not use port 161.

See this recent answer regarding "Splunk"'s SNMP functionality: http://splunk-base.splunk.com/answers/58537/what-version-of-splunk-can-receive-traps-via-snmpv3

MHibbin
Influencer

Splunk does not directly use SNMP. It may be an SNMP daemon that is running on the same server, ref the following for the splunk recommended practice http://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventstoSplunk

Is it a *nix platform? - If so you can use netstat and ps to locate some more information...

netstat -antp | egrep '161|162'

This will show you what processes are using those ports, you can then find the PID in this information and use that in a ps search...

ps -ef | grep <PID>
0 Karma

MHibbin
Influencer

Okay cool!

0 Karma

weevil
New Member

I will have a look and see if it is a Daemon or something untoward doing the SNMP. I guess this is why PCI Compliance exists 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...