All,
I've been able to successfully create a *.py file from a *.mib file in order to use the SNMP Modular Input. I dropped it the file in the proper directory instructed. Apparently the new version doesn't require it to be egg'd, so I just left it as it was.
However, the device still isn't correctly polling. The splunkd.log shows this error:
10-09-2013 16:34:24.456 -0600 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\snmp_ta\bin\snmp.py"" Exception polling attributes [Errno 10057] A request to send or receive data was disallowed because the socket is not connected and (when sending on a datagram socket using a sendto call) no address was supplied
Could anyone give any insight in fixing this problem?
It is possible that the account you are running Splunk under does not have permissions to open the specified network ports.
I should note that I realize I have ipv6 enabled here, but I was just trying anything at the time.
I am working on the same issue, i think it is the same error message. For me though, I am not able to access the snmp port. When I attempt to telnet into the port I get errors.
I should also note I'm using Splunk 6. Could that be a problem?
[snmp://ROOMALERT12E]
destination= 10.200.0.90
port= 161
ipv6= 1
snmp_version= 2C
object_names= .1.3.6.1.4.1.20916.1.9.1.1, .1.3.6.1.4.1.20916.1.9.1.1.1
do_bulk_get= 1
split_bulk_output= 1
non_repeaters= 0
max_repetitions= 25
communitystring= avtech
snmpinterval= 30
listen_traps= 1
trap_port= 162
trap_host= localhost
mib_names= ROOMALERT12E
index= avtech
sourcetype= temp
Can you share your inputs.conf stanza that is causing this error.