All Apps and Add-ons

SNMP Modular Input not showing remote IP

DoD_MI
New Member

Hi All,

I have just installed SNMP Modular Input and started to receive some SNMP traps. I can see some SNMP packets coming in but the problem is that the reporting IP is not shown in the output. I have no idea which remote IP is sending which traps. All I see is "host=None" in the snmp trap data.

Any suggestions as to what I am doing wrong would be gratefully received.

Tags (2)
0 Karma

nit123
Path Finder

This could be an issue with the fact that when you upgraded to splunk 'X' version and have an app installed which is not supported in that version. You should uninstall this X version of app and restart Splunk to see inputs

0 Karma

sirsyedian
New Member

I am having the same issue. Splunk is receivign SNMP traps for multiple servers but I can't seem to find a way to differentiate them as they all have 'host=None' in the data.
Did you find a way to find the remote server details from the events?

0 Karma

fab73
Path Finder

Just a suggestion : Try configureing trapping of the correct OID on the Switch (Object Names List : iso.org.dod.internet.mgmt.mib-2.system.... )

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...