# Parse SNMP table data

**URL:** <https://discuss.elastic.co/t/parse-snmp-table-data/226552>\
**Category:** Logstash\
**Created:** [April 5, 2020, 7:45am UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552 "2020-04-05T07:45:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sketchy](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Post date:** [April 5, 2020, 7:45am UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/1 "2020-04-05T07:45:08Z")

</div>

I am experimenting moving some snmp monitoring from telegraf to logstash snmp imput but having some problems with the layout of the output and cant figure out how to efficiently parse this into a useful format.

Currently my output looks like this when using the tables query and selecting the columns I want.

```auto
{
       "ifTable" => [
        [0] {
                 "ifDescr" => "lo",
             "ifOutOctets" => 1579659027,
              "ifInOctets" => 1579659027,
            "ifOperStatus" => 1,
                   "index" => "1"
        },
        [1] {
                 "ifDescr" => "ipsec0",
             "ifOutOctets" => 0,
              "ifInOctets" => 0,
            "ifOperStatus" => 1,
                   "index" => "2"
        },
        [2] {
                 "ifDescr" => "sit0",
             "ifOutOctets" => 0,
              "ifInOctets" => 0,
            "ifOperStatus" => 2,
                   "index" => "3"
        },
        [3] {
                 "ifDescr" => "ip6tnl0",
             "ifOutOctets" => 0,
              "ifInOctets" => 0,
            "ifOperStatus" => 2,
                   "index" => "4"
        },
        [4] {
                 "ifDescr" => "PortE0",
             "ifOutOctets" => 267486371,
              "ifInOctets" => 132144834,
            "ifOperStatus" => 1,
                   "index" => "5"
        },

```

I need to be able to efficiently filter/remove the interfaces I don't need, I have tried it a few different ways but cant get the result I am looking for.

I want it to look something like this.

```auto
"interfaces" : {
    "lo" {
       "ifOutOctets" => 1579659027,
       "ifInOctets" => 1579659027,
       "ifOperStatus" => 1,
        "index" => "1"
       }
    "ipsec0" {
        "ifOutOctets" => 0,
         "ifInOctets" => 0,
         "ifOperStatus" => 1,
         "index" => "2"
       }
       

```

Any help with getting this data into a more workable format would be great.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2020, 1:49pm UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/2 "2020-04-05T13:49:12Z")

</div>

You could do that in ruby. I haven't tested it, but something like

```
ruby {
    code => '
        h = {}
        event.get("ifTable").each { |x|
            k = [x]["ifDescr"]
            x.delete("ifDescr")
            h[k] = x
        }
        event.set("interfaces", h)
    '
 }

```

I am not sure what the conditions for including or excluding interfaces are. Perhaps add something like

```
if ["lo", "ipsec0"].include? (k) {
}

```

around the insertion into h.

---

<div class="post-metadata">

**Author:** ![Sketchy](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Post date:** [April 5, 2020, 3:17pm UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/3 "2020-04-05T15:17:08Z")

</div>

Hi Badger thanks for that, ruby code is bit above my skillset at the moment but I can kind of see what we are doing here. However I get this ruby exception.

` Ruby exception occurred: no implicit conversion of String into Integer`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2020, 4:15pm UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/4 "2020-04-05T16:15:26Z")

</div>

> [@Badger](#):
>
> ```
> k = [x]["ifDescr"]
> 
> ```

Make that

```
k = x["ifDescr"]

```

---

<div class="post-metadata">

**Author:** ![Sketchy](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Post date:** [April 5, 2020, 10:36pm UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/5 "2020-04-05T22:36:24Z")

</div>

That did it, thanks so much badger your a real life saver.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2020, 10:36pm UTC](https://discuss.elastic.co/t/parse-snmp-table-data/226552/6 "2020-05-03T22:36:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
