Getting Data In

SNMP Modular Input trap issue

clymbouris
Path Finder

Hi,

I'm trying to setup Splunk as a trap listener via the Modular Input for some testing.

My inputs.conf looks like this:

[snmp://saa_traps]

communitystring = public

do_bulk_get = 0

ipv6 = 0

snmp_mode = traps

snmp_version = 1

sourcetype = saa_traps

split_bulk_output = 0

trap_host = localhost

trap_port = 162

v3_authProtocol = usmHMACMD5AuthProtocol

v3_privProtocol = usmDESPrivProtocol

I can see the packet coming in through Wireshark but it doesn't get indexed. The splunkd.log doesn't indicate any issues.

Not sure if related but once I get the SNMP packet from my monitored system my Splunk server sends back an ICMP reply: Destination Unreachable/Port Unreachable

Any ideas?

Lots of thanks

Tags (3)
0 Karma

starcher
Influencer

Just taking a stab at it. But you specified the snmp_host as local host. That probably is binding it to the localhost interface instead of the IP address your trap generating hosts are sending to. If your network address for the Splunk server is say 192.168.1.10, try changing it to snmp_host=192.168.1.10 instead. Not sure if you need to restart Splunk but probably.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...