# Elastic Search and Logstash for SNMP

**URL:** <https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089>\
**Category:** Logstash\
**Created:** [January 13, 2016, 11:12am UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089 "2016-01-13T11:12:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jansi](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@Jansi](https://discuss.elastic.co/u/Jansi)\
**Post date:** [January 13, 2016, 11:12am UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089/1 "2016-01-13T11:12:30Z")

</div>

Hi,

I have collected the SNMP from router in Cent OS using Logstash also imported those into ES.

Now I need a clarification on this.

I have to separate MIB name and value from received message. also have to do some manipulation on this value by using corresponding formulas.  
Please help how to do the following process using Logstash and Elastic search.

Before using logstash and ES, i have used SQL server and C#.

1. Collected SNMP from server using services in C#
2. Uploaded into MS SQL with the manipulated data using C#
3. Retrieving the SNMP data from MS SQL and loaded that data as a chart.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 13, 2016, 12:29pm UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089/2 "2016-01-13T12:29:32Z")

</div>

Are you collecting the data via SNMP traps? If so you should use Logstash's [snmptrap](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmptrap.html) plugin. Add filter plugins to manipulate the data and finish with an elasticsearch output plugin for submitting the data to Elasticsearch. Once there, Kibana can be used for charts.

---

<div class="post-metadata">

**Author:** ![Jansi](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@Jansi](https://discuss.elastic.co/u/Jansi)\
**Post date:** [January 14, 2016, 7:18am UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089/3 "2016-01-14T07:18:18Z")

</div>

HI,

Thanks for your reply.

I have few more doubts. As you said, we can use filters for manipulations. Yes Of course, we can do splitting, manipulations on data. But formula will be differed based on the collected data. Is it possible to do this with Filter?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 14, 2016, 7:24am UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089/4 "2016-01-14T07:24:23Z")

</div>

You can have different filters depending on the contents of the events. See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/elastic-search-and-logstash-for-snmp/39089/5 "2017-07-06T05:15:45Z")

</div>


