# Cannot see SNMP trap message in Kibana

**URL:** <https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833>\
**Category:** Kibana\
**Created:** [June 9, 2017, 11:02am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833 "2017-06-09T11:02:45Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![mkain](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mkain](https://discuss.elastic.co/u/mkain)\
**Post date:** [June 10, 2017, 2:13am UTC](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833/3 "2017-06-10T02:13:20Z")

</div>

Hi CJ, Thanks for throwing some light on the problem. I am very new to ELK  
world 🙂

I dont see any complains in logstash.log wrt to SNMP trap messages.

Here is the snip of logs file

root@deb0:/var/log/logstash# tail -f logstash.log  
{:timestamp=\>"2017-06-09T16:25:00.471000+0530", :message=\>"SIGINT received.  
Shutting down the pipeline.", :level=\>:warn}  
{:timestamp=\>"2017-06-09T16:25:00.496000+0530", :message=\>"Pipeline  
shutdown complete.", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.577000+0530", :message=\>"Worker threads  
expected: 2, worker threads started: 2", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.577000+0530", :message=\>"It's a Trap!",  
:Port=\>162, :Community=\>["public"], :Host=\>"0.0.0.0", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:40.608000+0530", :message=\>"Automatic  
template management enabled", :manage\_template=\>"true", :level=\>:info}  
{:timestamp=\>"2017-06-09T16:28:41.089000+0530", :message=\>"Using mapping  
template", :template=\>{"template"=\>"logstash-_",  
"settings"=\>{"index.refresh\_interval"=\>"5s"},  
"mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "omit\_norms"=\>true},  
"dynamic\_templates"=\>[{"message\_field"=\>{"match"=\>"message",  
"match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string",  
"index"=\>"analyzed", "omit\_norms"=\>true}}},  
{"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string",  
"mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true,  
"fields"=\>{"raw"=\>{"type"=\>"string", "index"=\>"not\_analyzed",  
"ignore\_above"=\>256}}}}}], "properties"=\>{"@version"=\>{"type"=\>"string",  
"index"=\>"not\_analyzed"}, "geoip"=\>{"type"=\>"object", "dynamic"=\>true,  
"properties"=\>{"location"=\>{"type"=\>"geo\_point"}}}}}}}, :level=\>:info}

I am still getting proper output on stdout from logstash

{  
"message" =\>  
"#\<SNMP::SNMPv2\_Trap:0x54aaa2ff @error\_index=0,  
@varbind\_list=[#\<SNMP::VarBind:0x19de40b4  
@value=#\<SNMP::TimeTicks:0x4e69f6b0 @value=22541758\>,  
@name=[1.3.6.1.2.1.1.3.0]\>, #\<SNMP::VarBind:0xec2c508  
@value=[1.3.6.1.4.1.22420.2.14.0.0.1], @name=[1.3.6.1.6.3.1.1.4.1.0]\>,  
#\<SNMP::VarBind:0x151597ca @value=#\<SNMP::Gauge32:0x3ca05996 @value=828\>,  
@name=[1.3.6.1.4.1.22420.2.14.1.3.2.0]\>], @error\_status=0,  
@request\_id=909307654, @source\_ip="10.91.140.99"\>",  
"host" =\> "10.91.140.99",  
"@version" =\> "1",  
"@timestamp" =\>  
"2017-06-10T02:00:38.878Z",  
"type" =\> "snmptrap",  
"SNMPv2-MIB::sysUpTime\_0" =\> "2 days, 14:36:57.58",  
"SNMPv2-MIB::snmpTrapOID\_0" =\>  
"SNMPv2-SMI::enterprises.22420.2.14.0.0.1",  
"SNMPv2-SMI::enterprises\_22420\_2\_14\_1\_3\_2\_0" =\> "828"  
}

While in the elasticsearch logs was getting following: After this I  
followed the changes in filter mentioned at

> [@Catch SNMP traps from windows for every 5minutes](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846):
>
> Hi, Can anyone please let me know how to collect the snmp traps from windows system using CentOS machine for every 5minutes using Logstash? Also i needs to know how to get trap by mentioning the OID using Logstash? Please anyone give me the clarification on this. Thanks in advance

and this error has disappeared now.

[2017-06-09 14:11:08,863][DEBUG][action.bulk] [Doughboy]  
[logstash-2017.06.09][3] failed to execute bulk item (index) index  
{[logstash-2017.06.09][snmptra  
p][AVyMA6f4lB7dSLba9Y7f], source[{"message":"#\<SNMP::SNMPv2\_Trap:0x72749130  
@error\_index=0, @varbind\_list=[#\<SNMP::VarBind:0x15cfafed  
@value=#\<SNMP::TimeTicks:0x7626fbc  
a @value=16304519\>, @name=[1.3.6.1.2.1.1.3.0]\>, #\<SNMP::VarBind:0x795cc75f  
@value=[1.3.6.1.4.1.22420.2.14.0.0.1], @name=[1.3.6.1.6.3.1.1.4.1.0]\>,  
#\<SNMP::VarBind:0x3a25  
6c38 @value=#\<SNMP::Gauge32:0x6ee3ee5a @value=628\>,  
@name=[1.3.6.1.4.1.22420.2.14.1.3.2.0]\>], @error\_status=0,  
@request\_id=907236719, @source\_ip="10.91.140.99"\>","hos  
t":"10.91.140.99","@version":"1","@timestamp":"2017-06-09T08:41:08.778Z","type":"snmptrap","SNMPv2-MIB::sysUpTime.0":"1  
day, 21:17:25.19","SNMPv2-MIB::snmpTrapOID.0":"S  
NMPv2-SMI::enterprises.22420.2.14.0.0.1","SNMPv2-SMI::enterprises.22420.2.14.1.3.2.0":"628"}]}  
MapperParsingException[Field name [SNMPv2-MIB::snmpTrapOID.0] cannot  
contain '.']  
at  
org.elasticsearch.index.mapper.object.ObjectMapper$TypeParser.parseProperties(ObjectMapper.java:277)  
at  
org.elasticsearch.index.mapper.object.ObjectMapper$TypeParser.parseObjectOrDocumentTypeProperties(ObjectMapper.java:222)  
at  
org.elasticsearch.index.mapper.object.RootObjectMapper$TypeParser.parse(RootObjectMapper.java:139)  
at  
org.elasticsearch.index.mapper.DocumentMapperParser.parse(DocumentMapperParser.java:118)  
at  
org.elasticsearch.index.mapper.DocumentMapperParser.parse(DocumentMapperParser.java:99)  
at  
org.elasticsearch.index.mapper.MapperService.parse(MapperService.java:549)  
at  
org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.applyRequest(MetaDataMappingService.java:257)  
at  
org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.execute(MetaDataMappingService.java:230)  
at  
org.elasticsearch.cluster.service.InternalClusterService.runTasksForExecutor(InternalClusterService.java:480)  
at  
org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run(InternalClusterService.java:784)  
at  
org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:231)  
at  
org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:194)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:745)

Regards,  
-Manish

---

_[View the full topic](https://discuss.elastic.co/t/cannot-see-snmp-trap-message-in-kibana/88833)._
