# Cannot see SNMP trap message in Kibana

**URL:** <https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833>\
**Category:** Kibana\
**Created:** [June 9, 2017, 11:02am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833 "2017-06-09T11:02:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkain](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mkain](https://discuss.elastic.co/u/mkain)\
**Post date:** [June 9, 2017, 11:02am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/1 "2017-06-09T11:02:46Z")

</div>

Hi,

I am running

Kibana 4.3.0  
logstash 2.0.0  
elasticsearch 2.4.5

Here is my logstash config for snmp traps:

```auto
input {
  snmptrap {
    type => "snmptrap"
    host => "0.0.0.0"
    port => 162
  }
}

filter{
   ruby {
     code => "
     event.to_hash.keys.each { |k| event[k.gsub('.','_')] = event.remove(k) if k.include?'.' }
     "
   }
}

output {
  elasticsearch { hosts => ["127.0.0.1:9200"] }
  stdout { codec => rubydebug }
}

```

I am able to see SNMP trap messages on stdout

```auto
{
                                       "message" => "#<SNMP::SNMPv2_Trap:0x391f0422 @error_index=0, @varbind_list=[#<SNMP::VarBind:0x691212ae @value=#<SNMP::TimeTicks:0x21889366 @value=17030767>, @name=[1.3.6.1.2.1.1.3.0]>, #<SNMP::VarBind:0xd851ebd @value=[1.3.6.1.4.1.22420.2.14.0.0.1], @name=[1.3.6.1.6.3.1.1.4.1.0]>, #<SNMP::VarBind:0x1e67c664 @value=#<SNMP::Gauge32:0x2f11ded4 @value=661>, @name=[1.3.6.1.4.1.22420.2.14.1.3.2.0]>], @error_status=0, @request_id=907477978, @source_ip=\"10.91.140.99\">",
                                          "host" => "10.91.140.99",
                                      "@version" => "1",
                                    "@timestamp" => "2017-06-09T10:42:10.993Z",
                                          "type" => "snmptrap",
                       "SNMPv2-MIB::sysUpTime_0" => "1 day, 23:18:27.67",
                     "SNMPv2-MIB::snmpTrapOID_0" => "SNMPv2-SMI::enterprises.22420.2.14.0.0.1",
    "SNMPv2-SMI::enterprises_22420_2_14_1_3_2_0" => "661"
}

```

But these messages are not visible to Kibana. I do have similar setup for syslog which is working very well and I am able to see messages in Kibana.

here is my logstash syslog config:

```auto
input {
  tcp {
    port => 514
    type => syslog
  }
  udp {
    port => 514
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch { hosts => ["127.0.01:9200"] }
  stdout { codec => rubydebug }
}

```

and messages on stdout are like:

```auto
{
             "message" => "<174>Jun 9 15:18:51 10.91.142.100 Mediation: [ID 127899 local5.info] MESSAGE= Discovery in progress ; TARGET= 10.91.123.56; CONDITION_TYPE= NEMGMT511; USER= Manager_for_6k_OM5k_and_CPL ",
            "@version" => "1",
          "@timestamp" => "2017-06-09T09:48:51.000Z",
                "host" => "10.91.142.103",
                "type" => "syslog",
    "syslog_timestamp" => "Jun 9 15:18:51",
     "syslog_hostname" => "10.91.142.100",
      "syslog_program" => "Mediation",
      "syslog_message" => "[ID 127899 local5.info] MESSAGE= Discovery in progress ; TARGET= 10.91.123.56; CONDITION_TYPE= NEMGMT511; USER= Manager_for_6k_OM5k_and_CPL ",
         "received_at" => "2017-06-09T09:48:38.261Z",
       "received_from" => "10.91.142.103"
}

```

Please guide what can I do to fix the problem with SNMP traps. and what should I query in elastic search wrt to SNMP traps.

Regards,  
-Manish

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [June 9, 2017, 8:19pm UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/2 "2017-06-09T20:19:36Z")

</div>

Hi Manish,

Thanks for posting this. What is Kibana set to query? Can we see the query?

Also, could you please check the Logstash and Elasticsearch logs? I'm wondering if documents are even being created for the SNMP trap events. I wonder if `SNMPv2-MIB::sysUpTime_0` will be accepted by ES as a valid name.

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![mkain](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mkain](https://discuss.elastic.co/u/mkain)\
**Post date:** [June 10, 2017, 2:13am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/3 "2017-06-10T02:13:20Z")

</div>

Hi CJ, Thanks for throwing some light on the problem. I am very new to ELK  
world 🙂

I dont see any complains in logstash.log wrt to SNMP trap messages.

Here is the snip of logs file

root@deb0:/var/log/logstash# tail -f logstash.log  
{:timestamp=\>"2017-06-09T16:25:00.471000+0530", :message=\>"SIGINT received.  
Shutting down the pipeline.", :level=\>:warn}  
{:timestamp=\>"2017-06-09T16:25:00.496000+0530", :message=\>"Pipeline  
shutdown complete.", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.577000+0530", :message=\>"Worker threads  
expected: 2, worker threads started: 2", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.577000+0530", :message=\>"It's a Trap!",  
:Port=\>162, :Community=\>["public"], :Host=\>"0.0.0.0", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.608000+0530", :message=\>"Automatic  
template management enabled", :manage\_template=\>"true", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:41.089000+0530", :message=\>"Using mapping  
template", :template=\>{"template"=\>"logstash-_",  
"settings"=\>{"index.refresh\_interval"=\>"5s"},  
"mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "omit\_norms"=\>true},  
"dynamic\_templates"=\>[{"message\_field"=\>{"match"=\>"message",  
"match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string",  
"index"=\>"analyzed", "omit\_norms"=\>true}}},  
{"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string",  
"mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true,  
"fields"=\>{"raw"=\>{"type"=\>"string", "index"=\>"not\_analyzed",  
"ignore\_above"=\>256}}}}}], "properties"=\>{"@version"=\>{"type"=\>"string",  
"index"=\>"not\_analyzed"}, "geoip"=\>{"type"=\>"object", "dynamic"=\>true,  
"properties"=\>{"location"=\>{"type"=\>"geo\_point"}}}}}}}, :level=\>:info}

I am still getting proper output on stdout from logstash

{  
"message" =\>  
"#\<SNMP::SNMPv2\_Trap:0x54aaa2ff @error\_index=0,  
@varbind\_list=[#\<SNMP::VarBind:0x19de40b4  
@value=#\<SNMP::TimeTicks:0x4e69f6b0 @value=22541758\>,  
@name=[1.3.6.1.2.1.1.3.0]\>, #\<SNMP::VarBind:0xec2c508  
@value=[1.3.6.1.4.1.22420.2.14.0.0.1], @name=[1.3.6.1.6.3.1.1.4.1.0]\>,  
#\<SNMP::VarBind:0x151597ca @value=#\<SNMP::Gauge32:0x3ca05996 @value=828\>,  
@name=[1.3.6.1.4.1.22420.2.14.1.3.2.0]\>], @error\_status=0,  
@request\_id=909307654, @source\_ip="10.91.140.99"\>",  
"host" =\> "10.91.140.99",  
"@version" =\> "1",  
"@timestamp" =\>  
"2017-06-10T02:00:38.878Z",  
"type" =\> "snmptrap",  
"SNMPv2-MIB::sysUpTime\_0" =\> "2 days, 14:36:57.58",  
"SNMPv2-MIB::snmpTrapOID\_0" =\>  
"SNMPv2-SMI::enterprises.22420.2.14.0.0.1",  
"SNMPv2-SMI::enterprises\_22420\_2\_14\_1\_3\_2\_0" =\> "828"  
}

While in the elasticsearch logs was getting following: After this I  
followed the changes in filter mentioned at

> [@Catch SNMP traps from windows for every 5minutes](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846):
>
> Hi, Can anyone please let me know how to collect the snmp traps from windows system using CentOS machine for every 5minutes using Logstash? Also i needs to know how to get trap by mentioning the OID using Logstash? Please anyone give me the clarification on this. Thanks in advance

and this error has disappeared now.

[2017-06-09 14:11:08,863][DEBUG][action.bulk] [Doughboy]  
[logstash-2017.06.09][3] failed to execute bulk item (index) index  
{[logstash-2017.06.09][snmptra  
p][AVyMA6f4lB7dSLba9Y7f], source[{"message":"#\<SNMP::SNMPv2\_Trap:0x72749130  
@error\_index=0, @varbind\_list=[#\<SNMP::VarBind:0x15cfafed  
@value=#\<SNMP::TimeTicks:0x7626fbc  
a @value=16304519\>, @name=[1.3.6.1.2.1.1.3.0]\>, #\<SNMP::VarBind:0x795cc75f  
@value=[1.3.6.1.4.1.22420.2.14.0.0.1], @name=[1.3.6.1.6.3.1.1.4.1.0]\>,  
#\<SNMP::VarBind:0x3a25  
6c38 @value=#\<SNMP::Gauge32:0x6ee3ee5a @value=628\>,  
@name=[1.3.6.1.4.1.22420.2.14.1.3.2.0]\>], @error\_status=0,  
@request\_id=907236719, @source\_ip="10.91.140.99"\>","hos  
t":"10.91.140.99","@version":"1","@timestamp":"2017-06-09T08:41:08.778Z","type":"snmptrap","SNMPv2-MIB::sysUpTime.0":"1  
day, 21:17:25.19","SNMPv2-MIB::snmpTrapOID.0":"S  
NMPv2-SMI::enterprises.22420.2.14.0.0.1","SNMPv2-SMI::enterprises.22420.2.14.1.3.2.0":"628"}]}  
MapperParsingException[Field name [SNMPv2-MIB::snmpTrapOID.0] cannot  
contain '.']  
at  
org.elasticsearch.index.mapper.object.ObjectMapper$TypeParser.parseProperties(ObjectMapper.java:277)  
at  
org.elasticsearch.index.mapper.object.ObjectMapper$TypeParser.parseObjectOrDocumentTypeProperties(ObjectMapper.java:222)  
at  
org.elasticsearch.index.mapper.object.RootObjectMapper$TypeParser.parse(RootObjectMapper.java:139)  
at  
org.elasticsearch.index.mapper.DocumentMapperParser.parse(DocumentMapperParser.java:118)  
at  
org.elasticsearch.index.mapper.DocumentMapperParser.parse(DocumentMapperParser.java:99)  
at  
org.elasticsearch.index.mapper.MapperService.parse(MapperService.java:549)  
at  
org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.applyRequest(MetaDataMappingService.java:257)  
at  
org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.execute(MetaDataMappingService.java:230)  
at  
org.elasticsearch.cluster.service.InternalClusterService.runTasksForExecutor(InternalClusterService.java:480)  
at  
org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run(InternalClusterService.java:784)  
at  
org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:231)  
at  
org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:194)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:745)

Regards,  
-Manish

---

<div class="post-metadata">

**Author:** ![mkain](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mkain](https://discuss.elastic.co/u/mkain)\
**Post date:** [June 12, 2017, 8:15am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/4 "2017-06-12T08:15:53Z")

</div>

Hi CJ,

There were two problems

1. "." was not permitted in fields
2. when I enabled received\_at time field in syslog logstash filter and indexed using received\_at field. SNMP stopped working in kibana.

Now I am using @timestamp in syslog and SNMP and now both SNMP and syslog are looking good in kibana. and replacing "." with "\_" in SNMP filter.

here are the final configs:

Syslog:

input {  
tcp {  
port =\> 514  
type =\> syslog  
}  
udp {  
port =\> 514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_from", "%{host}"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["127.0.01:9200"] }  
stdout { codec =\> rubydebug }

SNMP config:

input {  
snmptrap {  
type =\> "snmptrap"  
host =\> "0.0.0.0"  
port =\> 162  
yamlmibdir =\> "/opt/logstash/vendor/bundle/jruby/1.9/gems/snmp-1.2.0/data/ruby/snmp/mibs"  
}  
}

filter{  
if [type] == "snmptrap" {  
ruby {  
code =\> "  
event.to\_hash.keys.each { |k| event[k.gsub('.','\_')] = event.remove(k) if k.include?'.' }  
"  
}  
}  
}

output {  
elasticsearch { hosts =\> ["127.0.0.1:9200"] }  
stdout { codec =\> rubydebug }  
}

I had also installed smitools package. Not sure if it helped.

Regards,  
-Manish

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [June 12, 2017, 3:20pm UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/5 "2017-06-12T15:20:11Z")

</div>

Hi Manish, I'm so happy to hear you were able to solve your problem! Thanks for sharing the solution. I'll forward this information onto the Logstash team.

CJ

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [June 12, 2017, 3:36pm UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/6 "2017-06-12T15:36:26Z")

</div>

By the way, I just spoke with @jordansissel and he mentioned that upgrading to a newer version of Elasticsearch can solve your problem with using periods in field names. He also guessed that your second problem might be a mapping issue but it's hard to say without digging deeper.

CJ

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 3:36pm UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/7 "2017-07-10T15:36:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
