# Catch SNMP traps from windows for every 5minutes

**URL:** <https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846>\
**Category:** Logstash\
**Created:** [January 11, 2016, 8:31am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846 "2016-01-11T08:31:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jansi](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@Jansi](https://discuss.elastic.co/u/Jansi)\
**Post date:** [January 11, 2016, 8:31am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846/1 "2016-01-11T08:31:59Z")

</div>

Hi,

Can anyone please let me know how to collect the snmp traps from windows system using CentOS machine for every 5minutes using Logstash?

Also i needs to know how to get trap by mentioning the OID using Logstash?

Please anyone give me the clarification on this.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2016, 2:37am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846/2 "2016-01-12T02:37:35Z")

</div>

You can't poll traps, you can only accept them - [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmptrap.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmptrap.html)

---

<div class="post-metadata">

**Author:** ![Jansi](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@Jansi](https://discuss.elastic.co/u/Jansi)\
**Post date:** [January 12, 2016, 5:32am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846/4 "2016-01-12T05:32:31Z")

</div>

Hi,  
I have the issue while uploading traps into ES. I'm using ES 2.0, Logstash 2.1.1, Cent OS-7.Please find the below and provide the solution.  
**My Config File is as follows**  
input{snmptrap{type =\> "snmptrap"community =\> "public"port =\> 162yamlmibdir =\> "/opt/logstash/vendor/bundle/jruby/1.9/gems/snmp-1.2.0/data/ruby/snmp/mibs"}}output{stdout{}elasticsearch {}}  
**Error**  
Failed action. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2016.01.12", :\_type=\>"snmptrap", :\_routing=\>nil}, .... "SNMPv2-MIB::snmpTrapOID.0"]}\>\>], :response=\>{"create"=\>{"\_index"=\>"logstash-2016.01.12", "\_type"=\>"snmptrap", "\_id"=\>"AVI0USPPp6YsUwkp\_39O", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Field name [SNMPv2-MIB::snmpTrapOID.0] cannot contain '.'"}}}, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![Jansi](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@Jansi](https://discuss.elastic.co/u/Jansi)\
**Post date:** [January 12, 2016, 7:47am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846/5 "2016-01-12T07:47:14Z")

</div>

I found the solution from one Blog..

. should be replaced into another acceptable character in ES field names.

Replaced . as \_ in the field names and finally got the solution for this issue

filter{  
ruby {  
code =\> "  
event.to\_hash.keys.each { |k| event[k.gsub('.','\_')] = event.remove(k) if k.include?'.' }  
"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:16am UTC](https://discuss.elastic.co/t/catch-snmp-traps-from-windows-for-every-5minutes/38846/6 "2017-07-06T05:16:04Z")

</div>


