# How to parse snmptrap "message" part

**URL:** <https://discuss.elastic.co/t/how-to-parse-snmptrap-message-part/177789>\
**Category:** Logstash\
**Created:** [April 22, 2019, 4:20am UTC](https://discuss.elastic.co/t/how-to-parse-snmptrap-message-part/177789 "2019-04-22T04:20:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [April 22, 2019, 4:20am UTC](https://discuss.elastic.co/t/how-to-parse-snmptrap-message-part/177789/1 "2019-04-22T04:20:53Z")

</div>

hello,

i’m trying to filter a field from snmptrap. as i posted below, the "message" value seems to be creepy and not clear to grok.

how can i parse them. please advise.

```
GET vcenter_alarm_20190422/_search
{
  "query": {
    "match_all": {}
  },
  "size": 10,
  "sort": [
    {
      "@timestamp": {
        "order": "desc"
      }
    }
  ],
  "_source": "message"
}

```

result shown as below. below is one sample from entire output.

```
{
  "took" : 2,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 69,
    "max_score" : null,
    "hits" : [
      {
        "_index" : "g2_vcenter_alarm_20190422",
        "_type" : "_doc",
        "_id" : "cwQ4Q2oBbVhBoHFXmPZY",
        "_score" : null,
        "_source" : {
          "message" : """#<SNMP::SNMPv1_Trap:0x12b073b2 @enterprise=[1.3.6.1.4.1.6876.4.3], @timestamp=#<SNMP::TimeTicks:0x76e4342e @value=214738955>, @varbind_list=[#<SNMP::VarBind:0x6c8d4f2a @name=[1.3.6.1.4.1.6876.4.3.308.0], @value=#<SNMP::Integer:0x7d319cea @value=4>>, #<SNMP::VarBind:0x2a239226 @name=[1.3.6.1.4.1.6876.4.3.304.0], @value="Green">, #<SNMP::VarBind:0x3e683716 @name=[1.3.6.1.4.1.6876.4.3.305.0], @value="Yellow">, #<SNMP::VarBind:0x381acbee @name=[1.3.6.1.4.1.6876.4.3.306.0], @value="alarm.VsphereClientHealthAlarm - Event: Status change (2499178)\nSummary: vsphere-client status changed from green to yellow\nDate: 04/22/19 04:05:42\nArguments:\n componentId = vsphere-client\n componentName = vsphere-client\n newStatus = yellow\n oldStatus = green\n serviceId = vsphere-client\n">, #<SNMP::VarBind:0x493dd6cb @name=[1.3.6.1.4.1.6876.4.3.307.0], @value="Datacenters">], @specific_trap=203, @source_ip="172.30.119.12", @agent_addr=#<SNMP::IpAddress:0x7fb9df68 @value="\xAC\x1Ew\f">, @generic_trap=6>"""
        },
        "sort" : [
          1555905943309
        ]
      },
```

---

<div class="post-metadata">

**Author:** ![jasony](https://avatars.discourse-cdn.com/v4/letter/j/a3d4f5/32.png) [@jasony](https://discuss.elastic.co/u/jasony)\
**Post date:** [April 22, 2019, 4:23am UTC](https://discuss.elastic.co/t/how-to-parse-snmptrap-message-part/177789/2 "2019-04-22T04:23:41Z")

</div>

> [@jasony](#):
>
> "message" : """#\<SNMP::SNMPv1\_Trap:0x12b073b2 @enterprise=[1.3.6.1.4.1.6876.4.3], @timestamp=#\<SNMP::TimeTicks:0x76e4342e @value=214738955\>, @varbind\_list=[#\<SNMP::VarBind:0x6c8d4f2a @name=[1.3.6.1.4.1.6876.4.3.308.0], @value=#\<SNMP::Integer:0x7d319cea @value=4\>\>, #\<SNMP::VarBind:0x2a239226 @name=[1.3.6.1.4.1.6876.4.3.304.0], @value="Green"\>, #\<SNMP::VarBind:0x3e683716 @name=[1.3.6.1.4.1.6876.4.3.305.0], @value="Yellow"\>, #\<SNMP::VarBind:0x381acbee @name=[1.3.6.1.4.1.6876.4.3.306.0], @value="alarm.VsphereClientHealthAlarm - Event: Status change (2499178)\nSummary: vsphere-client status changed from green to yellow\nDate: 04/22/19 04:05:42\nArguments:\n componentId = vsphere-client\n componentName = vsphere-client\n newStatus = yellow\n oldStatus = green\n serviceId = vsphere-client\n"\>, #\<SNMP::VarBind:0x493dd6cb @name=[1.3.6.1.4.1.6876.4.3.307.0], @value="Datacenters"\>], @specific\_trap=203, @source\_ip="172.30.119.12", @agent\_addr=#\<SNMP::IpAddress:0x7fb9df68 @value="\xAC\x1Ew\f"\>, @generic\_trap=6\>"""

i am asking about "message" field's value to parse or grok pattern.

"message" : """#\<SNMP::SNMPv1\_Trap:0x12b073b2 @enterprise=[1.3.6.1.4.1.6876.4.3], @timestamp=#\<SNMP::TimeTicks:0x76e4342e @value=214738955\>, @varbind\_list=[#\<SNMP::VarBind:0x6c8d4f2a @name=[1.3.6.1.4.1.6876.4.3.308.0], @value=#\<SNMP::Integer:0x7d319cea @value=4\>\>, #\<SNMP::VarBind:0x2a239226 @name=[1.3.6.1.4.1.6876.4.3.304.0], @value="Green"\>, #\<SNMP::VarBind:0x3e683716 @name=[1.3.6.1.4.1.6876.4.3.305.0], @value="Yellow"\>, #\<SNMP::VarBind:0x381acbee @name=[1.3.6.1.4.1.6876.4.3.306.0], @value="alarm.VsphereClientHealthAlarm - Event: Status change (2499178)\nSummary: vsphere-client status changed from green to yellow\nDate: 04/22/19 04:05:42\nArguments:\n componentId = vsphere-client\n componentName = vsphere-client\n newStatus = yellow\n oldStatus = green\n serviceId = vsphere-client\n"\>, #\<SNMP::VarBind:0x493dd6cb @name=[1.3.6.1.4.1.6876.4.3.307.0], @value="Datacenters"\>], @specific\_trap=203, @source\_ip="172.30.119.12", @agent\_addr=#\<SNMP::IpAddress:0x7fb9df68 @value="\xAC\x1Ew\f"\>, @generic\_trap=6\>"""

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2019, 4:23am UTC](https://discuss.elastic.co/t/how-to-parse-snmptrap-message-part/177789/3 "2019-05-20T04:23:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
