# SNMP-trap OID escaping .0 for Queries

**URL:** <https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [October 15, 2015, 2:13pm UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282 "2015-10-15T14:13:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tom\_jonge](https://avatars.discourse-cdn.com/v4/letter/t/7ba0ec/32.png) [@tom\_jonge](https://discuss.elastic.co/u/tom_jonge)\
**Post date:** [October 15, 2015, 2:13pm UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/1 "2015-10-15T14:13:50Z")

</div>

Greetings,

I'm currently feeding SNMP traps into my ELK stack and have run into a problem with the translated OID's and trying to query them in a watch.

The watch in question:

```
/_watcher/watch/test_event
{
      "trigger": {
        "schedule": {
          "interval": "60s"
        }
      },
      "input": {
        "search": {
          "request": {
            "indices": [
              "logstash-*"
            ],
            "search_type": "query_then_fetch",
            "body": {
              "query": {
                "filtered": {
                  "query": {
                    "bool": {
                      "should": [
                        {
                          "match": {
                            "message": "test"
                          }
                        }
                      ]
                    }
                  },
                  "filter": {
                    "range": {
                      "@timestamp": {
                        "from": "{{ctx.trigger.scheduled_time}}||-60s",
                        "to": "{{ctx.trigger.triggered_time}}"
                      }
                    }
                  }
                }
              },
              "fields": [
                "RFC1213-MIB::sysName.0",
                "FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg.0",
                "FORTINET-FORTIGATE-MIB::fgIpsTrapSrcIp.0",
                "DISMAN-EXPRESSION-MIB::sysUpTimeInstance",
                "@timestamp"
              ],
              "sort": [
                {
                  "@timestamp": {
                    "order": "desc"
                  }
                }
              ]
            }
          }
        }
      },
      "throttle_period": "60s", 
      "condition": {
        "script": {
          "inline": "ctx.payload.hits.size() > 0 "
        }
      },
      "actions": {
          "send_email": {
            "email": {
              "to": "receiving@gmail.com",
              "subject": " Watcher Notification - Event: {{ctx.payload.hits.hits.0.fields.FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg.0}} ON DEVICE: {{ctx.payload.hits.hits.0.fields.RFC1213-MIB::sysName.0}} SRC IP: {{ctx.payload.hits.hits.0.fields.FORTINET-FORTIGATE-MIB::fgIpsTrapSrcIp.0}} AT: {{ctx.trigger.triggered_time}} UTC",
              "body": {
              "html": "<HTML><b>Trigger time: </b>{{ctx.trigger.triggered_time}} UTC<br><b>Event: </b>{{ctx.payload.hits.hits.0.fields.FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg.0}}<br><b>Device: </b>{{ctx.payload.hits.hits.0.fields.RFC1213-MIB::sysName.0}}<br><b>Src IP: </b>{{ctx.payload.hits.hits.0.fields.FORTINET-FORTIGATE-MIB::fgIpsTrapSrcIp.0}}<br><b>Uptime: </b>{{ctx.payload.hits.hits.0.fields.DISMAN-EXPRESSION-MIB::sysUpTimeInstance}}</HTML>"
              }
            }
          }
        }
      }'

```

As you can see, some of the OID's are being translated into fields ending with ".0".  
For example:

> FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg.0

Only the fields ending in ".0" remain empty. ctx.payload.hits.hits.0.fields.DISMAN-EXPRESSION-MIB::sysUpTimeInstance gives me the correct output. To me it seems like the ".0" is part of the OID but it seems the "." is being treated as another divider like the "." in ctx.payload.

Is there a way to escape the "."?  
I tried:

> FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg.0

But that gives me the following error:

> nested: JsonParseException[Unrecognized character escape '.' (code 46)\n at [Source: [B@60a0bd4; line: 39, column: 36]]; ","status":500}

Edit:

Double escaping like below does not work either.

> FORTINET-FORTIGATE-MIB::fgIpsTrapSigMsg\.0

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [October 15, 2015, 2:33pm UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/2 "2015-10-15T14:33:31Z")

</div>

Hi Tom,

Using dots in field names is not a good practice - it causes a lot of confusion and complexity, and this is just one example of why. In ES 2.0, you can [no longer create fields with dots in them](https://www.elastic.co/guide/en/elasticsearch/reference/2.0/_mapping_changes.html#_field_names_may_not_contain_dots), for many reasons..

Can you change the way you index these documents, perhaps by transforming them before they get to ES?

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![tom\_jonge](https://avatars.discourse-cdn.com/v4/letter/t/7ba0ec/32.png) [@tom\_jonge](https://discuss.elastic.co/u/tom_jonge)\
**Post date:** [October 15, 2015, 2:40pm UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/3 "2015-10-15T14:40:06Z")

</div>

Hi Steve,

Thanks for the speedy response. This is logstash's SNMP plugin translating OID's from the YAML MIB.  
I'm not too sure if I can just go ahead and remove the .0 part from the MIB's but it's worth a shot.

Edit:  
Seems I can't. So Logstash has SNMP support, but Watcher does not.  
Ill keep trying to get it to work.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [October 19, 2015, 8:59am UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/4 "2015-10-19T08:59:51Z")

</div>

Hey,

FYI, the logstash team is currently evaluating a migration strategy, you can check out the ticket at [https://github.com/elastic/logstash/issues/4015](https://github.com/elastic/logstash/issues/4015)

--Alex

---

<div class="post-metadata">

**Author:** ![tom\_jonge](https://avatars.discourse-cdn.com/v4/letter/t/7ba0ec/32.png) [@tom\_jonge](https://discuss.elastic.co/u/tom_jonge)\
**Post date:** [October 19, 2015, 11:02am UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/5 "2015-10-19T11:02:17Z")

</div>

Many thanks for the link. Will keep an eye on it. For now I've sorted the problem out by using a logstash filter mutation, but it's an ugly and time consuming workaround.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/snmp-trap-oid-escaping-0-for-queries/32282/6 "2017-07-06T13:48:20Z")

</div>


