Splunk Dev

SNMP doesnt get any data

jadengoho
Builder

I do all the configuration needed but still no data ingesting in the splunk

##POLL###
[snmp://<NAME>]
communitystring = public
destination = <ip address of the server>
do_bulk_get = 0
do_get_subtree = 0
index = <index_name>
ipv6 = 0
mib_names = <SMI>,<Custom MIB's i put in .egg>
object_names = <OID's>
port = 161
snmp_mode = attributes
snmp_version = 2C
sourcetype = <sourcetype_name>
split_bulk_output = 0
v3_authProtocol = usmHMACMD5AuthProtocol
v3_privProtocol = usmDESPrivProtocol

I deploy the addon on the universal forwarder, and reload the DS ,
But still no data ingesting .

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

The app requires python. Therefore it must be installed on full splunk installs (heavy forwarders,
Etc).

Thanks!

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

The app requires python. Therefore it must be installed on full splunk installs (heavy forwarders,
Etc).

Thanks!

0 Karma

jadengoho
Builder

i try to install i tto the Heavy forwarder with python 2.7 but still no data incomming

0 Karma

jadengoho
Builder

i am getting this log
index=_internal ExecProcessor error snmp.py host="HF1

5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py" Traceback (most recent call last):
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py"   File "/opt/splunk/etc/apps/snmp_ta/bin/snmp.py", line 771, in <module>
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py"     do_run()
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py"   File "/opt/splunk/etc/apps/snmp_ta/bin/snmp.py", line 475, in do_run
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py"     mibBuilder.loadModules(*mib_names_args)
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmp_ta/bin/snmp.py"   File "/opt/splunk/etc/apps/snmp_ta/bin/pysnmp-4.2.5-py2.7.egg/pysnmp/smi/builder.py", line 270, in loadModules
host =  prd-usc1-a-splunk-hf1 source =  /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd
5/9/18
3:11:58.976 AM  
05-09-2018 03:11:58.976 -0400 ERROR ExecProcessor - message from "python /opt/spl
0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you share the results of this search?

index=_internal snmp.py host="HF1

0 Karma

koshyk
Super Champion

which conf file you are updating this? Do you have an SNMP app for this?

0 Karma

jadengoho
Builder

yes there is a SNMP app deployed to 20 Universal Forwarders.
I am updating the snmp_ta/local/inputs.conf

0 Karma

jadengoho
Builder

is it connected to this message :

INFO ExecProcessor - Removing status item "/opt/splunk/etc/apps/snmp_ta/bin/snmp.py (snmp://testing) (isModInput=yes)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...