# How to detect incorrect OID in SNMP input plugin?

**URL:** <https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [January 26, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062 "2023-01-26T18:48:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![scantron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scantron/32/114018_2.png) [@scantron](https://discuss.elastic.co/u/scantron)\
**Post date:** [January 26, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062/1 "2023-01-26T18:48:18Z")

</div>

When using the SNMP input plugin, I am trying to detect when an OID does not work on the given host. For instance, when using snmpget in the **command line** with an OID that does not correspond to the given host, it would return

```auto
No Such Object available on this agent at this OID

```

However, when attempting this via logstash, there are no error logs or anything that would indicate anything is failing. However, no logs come through either. Using, for instance, a host that does not support SNMP _does_ throw an error, such as

```auto
request has timed out

```

But for the case of an incorrect OID, nothing occurs. Is this just a missing feature?  
Here is the pipeline:

INPUT

```auto
input {
  snmp {
    get => ["<random-oid-that-does-not-work-on-given-host>"]
    hosts => [
   {host => "udp:<host-ip-that-responds-properly-to-correct-OIDs:161>" community => "<community>" version => "2c" retries => 2 timeout => 5000}
    ]
    mib_paths => ["/usr/share/logstash/MIB"]
    add_field => {
      "msg_type" => "<value>"
    }
  }
}

```

_Filter left blank to minimize any bugs_

OUTPUT

```auto
output {
  kafka {
    codec => json
    bootstrap_servers => "kafka01:9092,kafka02:9092"
    topic_id => "%<field>"
  }

```

This output works for all of our other logs that we want to send to kafka. SNMP logs that are supposed to work come through fine, and SNMP logs that break because of hosts that do not support SNMP appear in the logstash container's docker logs as exception=\>#\<LogStash::SnmpClientError: timeout sending snmp get request to target .

But again, nothing comes through if we intentionally use an OID that does not correspond to a host that accepts SNMP. No logs, and no errors.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 26, 2023, 9:34pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062/2 "2023-01-26T21:34:37Z")

</div>

Looking at the [code](https://github.com/logstash-plugins/logstash-input-snmp/blob/b0f827623cc5e7c3ba2733622fb9484947da6065/lib/logstash/inputs/snmp.rb#L201), it looks like the plugin does not return an event unless there is data. If you enable --log.level debug you should see messages indicating where it is deciding there is no data.

---

<div class="post-metadata">

**Author:** ![scantron](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scantron/32/114018_2.png) [@scantron](https://discuss.elastic.co/u/scantron)\
**Post date:** [January 27, 2023, 4:56pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062/3 "2023-01-27T16:56:28Z")

</div>

Hi Badger, Thanks for the response! Thank you for getting to the bottom of it! Question: I am using docker compose to deploy. Where can I escalate the log level to debug, and if I do, will errors and warnings still come through? Thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062/4 "2023-02-24T16:57:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
