# SNMP input, table index becomes separated

**URL:** <https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081>\
**Category:** Logstash\
**Created:** [October 1, 2024, 9:47am UTC](https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081 "2024-10-01T09:47:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Billiam](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@Billiam](https://discuss.elastic.co/u/Billiam)\
**Post date:** [October 1, 2024, 9:47am UTC](https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081/1 "2024-10-01T09:47:55Z")

</div>

I've got the SNMP input configured to poll a number of Cisco devices pulling back interfaces stats from the following OIDs:

```auto
              "1.3.6.1.2.1.2.2.1.1",
              "1.3.6.1.2.1.2.2.1.2",
              "1.3.6.1.2.1.2.2.1.3",
              "1.3.6.1.2.1.2.2.1.5",
              "1.3.6.1.2.1.2.2.1.7",
              "1.3.6.1.2.1.2.2.1.8",
              "1.3.6.1.2.1.2.2.1.13",
              "1.3.6.1.2.1.2.2.1.14",
              "1.3.6.1.2.1.2.2.1.19",
              "1.3.6.1.2.1.2.2.1.20",
              "1.3.6.1.2.1.31.1.1.1.6",
              "1.3.6.1.2.1.31.1.1.1.10",
              "1.3.6.1.2.1.31.1.1.1.15"

```

Initially the data looks fine and a single entry shows per line:

```auto
{"ifInDiscards":0,"ifType":6,"ifHCOutOctets":200094875917,"ifOutDiscards":50,"ifHighSpeed":1000,"ifInErrors":0,"ifDescr":"TenGigabitEthernet0/0/0","ifOutErrors":0,"ifSpeed":1000000000,"index":"1","ifHCInOctets":168193171726,"ifAdminStatus":1,"ifOperStatus":1,"ifIndex":1},

```

but after a while it starts to split into 2 entries, with the same index value:

```auto
{"index":"19","ifHighSpeed":1000,"ifHCInOctets":433048048,"ifHCOutOctets":595866704},
{"ifInDiscards":0,"ifType":131,"ifOutDiscards":0,"ifInErrors":0,"ifDescr":"Tunnel1","ifOutErrors":0,"ifSpeed":1000000000,"index":"19","ifAdminStatus":1,"ifOperStatus":1,"ifIndex":19},

```

This then causes issues when using queries as the data has become disjointed.

What I don't get is why the data starts to split within the table returned.

Any ideas?

---

<div class="post-metadata">

**Author:** ![Billiam](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@Billiam](https://discuss.elastic.co/u/Billiam)\
**Post date:** [October 3, 2024, 9:00am UTC](https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081/2 "2024-10-03T09:00:19Z")

</div>

Found this as a known issue with a ruby filter script to workaround the problem:

[Ensure responses with large tables produce a single array with no duplicated elements · Issue #30](https://github.com/logstash-plugins/logstash-integration-snmp/issues/30)
