# Logstash: parsing snmp traps

**URL:** <https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208>\
**Category:** Logstash\
**Created:** [October 9, 2017, 9:58am UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208 "2017-10-09T09:58:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert.I](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@Robert.I](https://discuss.elastic.co/u/Robert.I)\
**Post date:** [October 9, 2017, 9:58am UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208/1 "2017-10-09T09:58:20Z")

</div>

Hello All,

At this moment, all the traps that i received in Logstash that have the error code, will write in elastic and in a file:  
output {  
if [type] == "snmptrap" {  
elasticsearch { hosts =\> ["[myhost.domain.com:9200](http://myhost.domain.com:9200)"]  
user =\> user  
password =\> pass  
index =\> "logstash-snmp-%{+YYYY.MM.dd}"  
}  
if [snmp OID] =="ERROR" {  
file {  
path =\> "/var/spool/logstash/snmp.log"  
codec =\> json\_lines {}  
}  
}  
}

How i can parsing the snmp trap before write in the output file??

Thanks for your help,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 10, 2017, 6:33pm UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208/2 "2017-10-10T18:33:53Z")

</div>

You're not describing in what way you want it parsed so it's impossible to help. What do your SNMP events currently look like? How would you like them to look instead?

---

<div class="post-metadata">

**Author:** ![Robert.I](https://avatars.discourse-cdn.com/v4/letter/r/a8b319/32.png) [@Robert.I](https://discuss.elastic.co/u/Robert.I)\
**Post date:** [October 11, 2017, 7:44am UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208/3 "2017-10-11T07:44:43Z")

</div>

Hello magnus,  
Thanks a lot for your respond,  
What i want is, write in a file ( "/var/spool/logstash/snmp.log" ) if the "SNMPv2-SMI::enterprises.2.6.212.10.1.5] =="ERROR"", but in a " human" language, because now, doing this:  
file {  
path =\> "/var/spool/logstash/snmp.log"  
codec =\> json\_lines {}  
}  
In the file are all the SNMP trap information with all the OIDs, and my goal is change the all the "SNMPv2-SMI::enterprises.2.6.212.10.1.X" by a string like:  
filter{  
mutate {  
gsub =\> [  
# replace all forward slashes with underscore  
"message", "SNMPv2-SMI::enterprises.2.6.212.10.1.1", "CLUSTER\_ID"  
]  
}  
}

Thanks a lot for your help.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 12, 2017, 5:14am UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208/4 "2017-10-12T05:14:17Z")

</div>

That mutate filter looks like something that could work (but you should escape the periods since they are metacharacters in regexps). What are you having trouble with?

For best results avoid describing what you want to accomplish. Show examples instead, like what an event looks like now (using a `stdout { codec => rubydebug }` output) and what the desired outcome.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2017, 5:14am UTC](https://discuss.elastic.co/t/logstash-parsing-snmp-traps/103208/5 "2017-11-09T05:14:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
