# Constructing snmp input for logstash

**URL:** <https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663>\
**Category:** Logstash\
**Created:** [June 26, 2019, 7:25pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663 "2019-06-26T19:25:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [June 26, 2019, 7:25pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/1 "2019-06-26T19:25:44Z")

</div>

Newbie here, can someone outline how I'd parse construct the inputs for log example below in Logstash? I replaced some sensitive info like real ip address etc

Sat Jun 22 03:43:35 2019 - SNMPV1TRAP sent - 10.10.10.10:162 public - .1.3.6.1.4.1.6324.2.1 i 146002674 .1.3.6.1.4.1.6324.2.2 s MY-ROUTER-R1 (172.32.33.34) pp\_cp: QFP:0.0 Thread:001 TS:00003555265902986061 %IPSEC-3-RECVD\_PKT\_NOT\_IPSEC: Rec'd packet not an IPSEC packet, dest\_addr= 172.32.50.8, src\_addr= 172.32.50.9, prot= 17 .1.3.6.1.4.1.6324.2.3 s MY-ROUTER-R1 .1.3.6.1.4.1.6324.2.4 s 172.32.33.34 .1.3.6.1.4.1.6324.2.5 i 1 .1.3.6.1.4.1.6324.2.6 s pp\_cp: QFP:0.0 Thread:001 TS:00003555265902986061 %IPSEC-3-RECVD\_PKT\_NOT\_IPSEC: Rec'd packet not an IPSEC packet, dest\_addr= 172.32.50.8, src\_addr= 172.32.50.9, prot= 17 .1.3.6.1.4.1.6324.2.7 s User VarBind 1 .1.3.6.1.4.1.6324.2.8 s User VarBind 2 .1.3.6.1.4.1.6324.2.9 s my\_tool to ABX .1.3.6.1.4.1.6324.2.10 s my\_tool to ABX - Trapent1 .1.3.6.1.4.1.6324.2.11 s Alarm Group:Agent:Node .1.3.6.1.4.1.6324.2.12 s Profile Type:_Unspecified_ .1.3.6.1.4.1.6324.2.13 s Organizational:_Unspecified_ .1.3.6.1.4.1.6324.2.14 s Geographic:_Unspecified_ .1.3.6.1.4.1.6324.2.15 s TEAM/Engineers:_Unspecified_ .1.3.6.1.4.1.6324.2.16 s 1 .1.3.6.1.4.1.6324.2.17 s 2 .1.3.6.1.4.1.6324.2.18 s Sat, 22 Jun 2019 03:43:24 -0500 .1.3.6.1.4.1.6324.2.19 i 1004984 .1.3.6.1.4.1.6324.2.20 s ABCDE-3-PLATFORM (nc,clog) .1.3.6.1.4.1.6324.2.21 s User VarBind 3

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 8:54pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/2 "2019-06-26T20:54:35Z")

</div>

Please edit and format your post. It looks like the forum software has eaten some underscores, and I cannot tell what else it might have eaten. [This](https://discuss.elastic.co/t/logstash-instance-missing-from-kibana-monitoring/186734/11) might help with the formatting.

Are you using an snmp input? I would expect to get structured data in the events if you were. Or are you parsing a log where some device is dumping traps in a not so structured format?

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [June 26, 2019, 11:21pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/3 "2019-06-26T23:21:44Z")

</div>

snmp input as in a plugin or the input section of the \*.conf file? No to the former and yes to the latter. I am attempting to parse a log where a monitoring server is dumping traps in a the format shown in my example. BTW that's exactly how it's dumping the file. No missing underscores. Appreciate your assisance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 27, 2019, 12:32am UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/4 "2019-06-27T00:32:00Z")

</div>

How does the device specify an italic font for " Organizational: _Unspecified_"

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [June 27, 2019, 12:16pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/5 "2019-06-27T12:16:50Z")

</div>

That's just cosmetic metadata honestly, it was expecting an organisation, like say "STORAGE"

---

<div class="post-metadata">

**Author:** ![ksarpong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksarpong/32/101801_2.png) [@ksarpong](https://discuss.elastic.co/u/ksarpong)\
**Post date:** [June 28, 2019, 4:34pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/6 "2019-06-28T16:34:42Z")

</div>

We're good...it helps to read documentation 😄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2019, 4:34pm UTC](https://discuss.elastic.co/t/constructing-snmp-input-for-logstash/187663/7 "2019-07-26T16:34:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
