# \[SOLVED\] SNMP trap input plugin

**URL:** <https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742>\
**Category:** Logstash\
**Created:** [June 23, 2016, 6:49am UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742 "2016-06-23T06:49:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![def](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@def](https://discuss.elastic.co/u/def)\
**Post date:** [June 23, 2016, 6:49am UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742/1 "2016-06-23T06:49:57Z")

</div>

Hello,

I have a question :

Is it possible to limit the fields value for the output in logstash?

I'm using SNMP trap and I have a lot of different type of MIB, so I have a lot of indexed fields in Kibana and after few days, elasticsearch is not responding because there is a timeout.

**Here is a view from kibana (show the number of fields) :**

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a703073f1545d7e757e88f56a613fdc206c7b3d3.png)

**Here is my configuration for logstash :**

> ```
> input {
> snmptrap {
> type => snmptrap
> port => 1062
> codec => "json"
> yamlmibdir => "/opt/logstash/vendor/bundle/jruby/1.9/gems/snmp-1.2.0/data/ruby/snmp/mibs"
> }
> }
> filter {
> ruby {
> code => "event.to_hash.keys.each { |k| event[k.gsub('.','_')] = event.remove(k) if k.include?'.' }"
> }
> }output {
> elasticsearch {
> hosts => ['localhost:9200']
> }
> }
> 
> ```

I have add a mutate part in the filter like this :

> mutate {  
> gsub =\> ["message", "RFC1065-SMI::enterprises\_23916\_3\_1\_4\_1\_11\_[0-9]+", "RFC1065-SMI::enterprises\_23916\_3\_1\_4\_1\_11" ]  
> }

But it still doesn't work. Is there something wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2016, 6:23pm UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742/2 "2016-06-30T18:23:17Z")

</div>

Your mutate filter's gsub option acts on the contents of a field, but you want to rename the fields themselves and there's no stock filter for that. I think you need to write a small snippet of Ruby in a ruby filter to accomplish what you want.

---

<div class="post-metadata">

**Author:** ![def](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@def](https://discuss.elastic.co/u/def)\
**Post date:** [July 4, 2016, 8:31am UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742/3 "2016-07-04T08:31:27Z")

</div>

hello Magnus,

I have try to use ruby for that, but after a lot of tries I can remove the event, but I have not found how to rename a field name.

In this example, I have a field name like this :  
DOCS-CABLE-DEVICE-MIB::docsDevEvId\_72186  
and I liked to have a :  
DOCS-CABLE-DEVICE-MIB::docsDevEvId

I'm am new in Ruby, does Roby have a method rename or updateKey, or something else to do what I want?

Here is my solution for delete the event, but it is not my expected result

> ```
> event.to_hash.keys.each { |k|
> if k.start_with?('DOCS-CABLE-DEVICE-MIB::docsDevEvId')
> event.remove(k)
> end};
> 
> ```

---

<div class="post-metadata">

**Author:** ![def](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@def](https://discuss.elastic.co/u/def)\
**Post date:** [July 5, 2016, 11:32am UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742/4 "2016-07-05T11:32:33Z")

</div>

Hello,

I have a solution for my problem : I use pysnmp and a python program to remove values in fields.

I receive all SNMP trap with this program and simply forward them to logstash after processing.

So I can make better information and I have implemented an alarming when some SNMP trap are received.

Thanks for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/solved-snmp-trap-input-plugin/53742/5 "2017-07-06T04:49:30Z")

</div>


