# Logstash as SNMP Trap to GELF Converter, how to split message into seperate fields?

**URL:** <https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988>\
**Category:** Logstash\
**Created:** [January 14, 2020, 11:41am UTC](https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988 "2020-01-14T11:41:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Salve](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@Salve](https://discuss.elastic.co/u/Salve)\
**Post date:** [January 14, 2020, 11:41am UTC](https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988/1 "2020-01-14T11:41:54Z")

</div>

Hello,

I am new to logstash and I want to use it to convert SNMP Traps to GELF.

This is my very first (simple) pipeline.

```
input {
  snmptrap {
    id => "snmptrap"
    type => "snmptrap"
    port => 1162
  }
}
output {
  gelf {
    id => "gelf"
    host => "mygelfhost"
    port => 12201
  }
}

```

This is working, but I get all Trap OIDs in one message.

```
#<SNMP::SNMPv2_Trap:xx @request_id=xx, @error_index=0, @error_status=0, @source_ip="x.x.x.x", @varbind_list=[
#<SNMP::VarBind:xx @name=[1.3.6.1.2.1.1.3.0], @value=#<SNMP::TimeTicks:0x79d31b31 @value=7920439>>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.6.3.1.1.4.1.0], @value=[1.3.6.1.4.1.x.2.4.1.1.2.1]>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.2], @value=#<SNMP::TimeTicks:0x28115c7e @value=1578645869>>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.3], @value="xxx">, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.4], @value="xx">, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.5], @value=#<SNMP::IpAddress:xx @value="xx">>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.6], @value=#<SNMP::Integer:0x15364a1e @value=9006>>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.7], @value=#<SNMP::Integer:0x35b30466 @value=3>>, 
#<SNMP::VarBind:xx @name=[1.3.6.1.4.1.x.2.4.1.1.1.1.10], @value="xxxxx">]>

```

I want to have each splitted each OID into a seperate field.

If I use stdout as output, it looks very close. But with GELF (or syslog) output it does not. As I am very new to logstash I dont know how to proceed here. I think I have to use a filter to seperate this, but I dont know how to start. I played around with kv and split filters but I wasnt able to change this, now I am lost...

If anybody could me please point a direction to start?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 14, 2020, 3:42pm UTC](https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988/2 "2020-01-14T15:42:35Z")

</div>

Assuming that comes as a single event you could try starting with

```
# Extract the varbind_list
grok { match => { "message" => "@varbind_list=\[%{GREEDYDATA:[@metadata][varbind]}\]>$" } }
# and remove it
mutate { gsub => ["message", "@varbind_list=\[.*\]>$", "@varbind_list=[]" ] }
# Trim the leading noise
mutate { gsub => ["message", "^#<SNMP::SNMPv2_Trap:[^]+ ", "" ] }
kv { source => "message" field_split => "," value_split => "=" trim_key => " " }
ruby {
    code => '
        vb = event.get("[@metadata][varbind]")
        if vb
            # Extract the name and value pairs
            matches = vb.scan(/@name=([^]+), @value=([^,]+)(,|$)/)
            matches.each_index { |x|
                m2 = matches[x][1].scan(/@value=([^>]+)>/)
                # Is it "@value=#<SNMP::TimeTicks:0x28115c7e @value=1578645869>>" or "@value=7920439"
                if m2[0]
                    v = m2[0][0]
                else
                    v = matches[x][1]
                end
                # Remove trailing > and surrounding double quotes
                if v =~ />$/
                    v = v.gsub(/(.*)>$/, "\\1")
                end
                if v =~ /^"(.*)"$/
                    v = v.gsub(/^"(.*)"$/, "\\1")
                end
                event.set(matches[x][0], v)
            }
            event.set("matches", matches)
        end
    '
```

---

<div class="post-metadata">

**Author:** ![Salve](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@Salve](https://discuss.elastic.co/u/Salve)\
**Post date:** [January 16, 2020, 5:37am UTC](https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988/3 "2020-01-16T05:37:25Z")

</div>

Hi Badger,

that looks very nice. I need some time to test and understand this. But at this time, thank you so much for taking your time and give me this configuration.

Edit: I did testing, its working great! I have to convert some values (IP address, timeticks), but I want to learn so I will figure it out. Again, thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2020, 5:37am UTC](https://discuss.elastic.co/t/logstash-as-snmp-trap-to-gelf-converter-how-to-split-message-into-seperate-fields/214988/4 "2020-02-13T05:37:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
