Getting Data In

SNMP metrics with collectd

mmoermans
Path Finder

Following the documentation here https://docs.splunk.com/Documentation/Splunk/7.2.0/Metrics/GetMetricsInCollectd we're trying to get SNMP data with collectd into a metrics index.

The current format we're receiving is as follows (about 50% of the entire event using sourcetype snmp_ta):

["value"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"cpu","plugin_instance":"2","type":"cpu","type_instance":"softirq"},{"values":[0],"dstypes":["derive"],"dsnames":["value"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"cpu","plugin_instance":"2","type":"cpu","type_instance":"idle"},{"values":[98.1006747093728],"dstypes":["derive"],"dsnames":["value"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"cpu","plugin_instance":"3","type":"cpu","type_instance":"idle"},{"values":[16.1998630209115,3.59996956020255],"dstypes":["derive","derive"],"dsnames":["rx","tx"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"interface","plugin_instance":"ens192","type":"if_packets","type_instance":""},{"values":[2098.28607958568,6531.45666911971],"dstypes":["derive","derive"],"dsnames":["rx","tx"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"interface","plugin_instance":"ens192","type":"if_octets","type_instance":""},{"values":[0,0],"dstypes":["derive","derive"],"dsnames":["rx","tx"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"interface","plugin_instance":"ens192","type":"if_errors","type_instance":""},{"values":[0,0],"dstypes":["derive","derive"],"dsnames":["rx","tx"],"time":1540210462.641,"interval":10.000,"host":"localhost","plugin":"interface","plugin_instance":"ens192","type":"if_dropped","type_instance":""},{"values":[16.0999211648893,16.0999211648893],"dstypes":["derive","derive"],"dsnames":

How do you get the right format for metrics?
The events don't show up in the metrics index but no error shows up either in the _internal log.

1 Solution

mmoermans
Path Finder

Got it working by using a different collection URL and changing the sourcetype to collectd_http.

View solution in original post

mmoermans
Path Finder

Got it working by using a different collection URL and changing the sourcetype to collectd_http.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...