Splunk ITSI

SNMP traps are not getting to the index

isuruvh
New Member

I have a unique problem regarding SNMP and SPLUNK ITSI.First My VNF node was forwarding SNMP traps to SNMP target via SNMPv3 That target supports SNMP auto discovery so I don't had to manually configure ENGINID later I got the option of integrating my Node to SPLUNK ITSI and SC4SNMP whichi I did but intitially they didn't support EnginID auto discovery then I had Manually run the SNMPGET and provided the Engine ID for them.Now I am started sending my trap towards both the nodes ith same OID and ENgine ID.But My alarms are not getting to splunk index even though we will be able it capture it in the port of SC4SNMP.Later I found out that SPLUNkK ITST getting toe Same alarm same oid forwarded from the previous target.But this time target is using SNMPV2 and it sending as a community with a community string with few OIDs bundled together.Can this be the issue where my Nodes origina trap is not reaching the correct index?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...