# Logstash SNMP plugin

**URL:** <https://discuss.elastic.co/t/logstash-snmp-plugin/360825>\
**Category:** Logstash\
**Created:** [June 5, 2024, 6:42am UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825 "2024-06-05T06:42:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [June 5, 2024, 6:42am UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/1 "2024-06-05T06:42:44Z")

</div>

Hello everyone,  
Can I install a plugin on my Logstash server to receive SNMP messages when my Logstash server is completely disconnected from the internet?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 5, 2024, 8:39am UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/2 "2024-06-05T08:39:50Z")

</div>

Yes, you can, there are steps for the [offline installation](https://www.elastic.co/guide/en/logstash/current/offline-plugins.html).

---

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [June 5, 2024, 12:35pm UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/3 "2024-06-05T12:35:00Z")

</div>

I downloaded the Elasticsearch original plugin "logstash-input-snmp" version 1.3.3 from rubygems and tried to install it locally according to the guide you sent, but I am getting an error during the installation process stating that it cannot connect to the Rubygems service.  
As a reminder, I do not have internet access on the server.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 5, 2024, 1:18pm UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/4 "2024-06-05T13:18:43Z")

</div>

Which version of Logstash are you using? The `snmp` input is **bundled** in Logstash, at least on recent versions, there is no need to install it as it is already installed.

Check the documentation [here](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-snmp.html), there is no _Installation_ part on it, which means that there is no need to install this plugin as it is already bundled in Logstash.

---

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [June 5, 2024, 1:34pm UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/5 "2024-06-05T13:34:44Z")

</div>

My Logstash server version is 8.11.3. Is it already built-in in this version?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 5, 2024, 2:04pm UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/6 "2024-06-05T14:04:20Z")

</div>

Yes, just check the documentation, you can see the documentation for any major version by changing it on the left side menu in the documentation.

---

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [June 6, 2024, 5:23am UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/7 "2024-06-06T05:23:46Z")

</div>

I found it, thank you.  
I configured it according to the documentation:

```auto
input {
  snmptrap {
    id => "snmptrap"
  }
}

```

I'm sending an SNMP trap to the server's address on the default port 1062.  
I can see the message being received using tcpdump, but Logstash itself isn't receiving the message, neither in the log file nor anywhere else.

---

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [July 2, 2024, 9:59am UTC](https://discuss.elastic.co/t/logstash-snmp-plugin/360825/8 "2024-07-02T09:59:15Z")

</div>

Continue discussion on the following topic:

> [@Logstash snmptrap](https://discuss.elastic.co/t/logstash-snmptrap/361403):
>
> Hello everyone, I enabled receiving SNMP traps as input on my Logstash server with the following addition to the configuration: input { snmptrap { id =\> "snmptrap" } } I am sending an SNMP trap to the server. I can see that the message is received by the server itself when I sniff the network traffic on port 1062 (default), but the Logstash service running on the server does not log the message, and there is no indication in the log that a message was received. What could be my mista…
