All Apps and Add-ons

SNMP Modular Input: Is it possible to listen for SNMP trap v2 and trap V3 at the same time on the same Splunk instance?

cafissimo
Communicator

Hello,

Please, I would like to know if it is possible to listen for snmp trap v2 AND snmp trap v3 on the same Splunk instance at the same time.

Thanks in advance.

0 Karma

Damien_Dallimor
Ultra Champion

You should be able to. Just setup 2 separate SNMP stanzas on different trap listening ports.

0 Karma

cafissimo
Communicator

Hello Damien,
thank you, but I need to set both listener (v2 and v3) on the same port, do you think this is feasible?
If not, is there any kind of workaround you suggest?
For example, I was thinking to create another network interface on the splunk host, then set v2 to listen on an interface, v3 on the other one and having packet forwarded via iptables from one interface to another.
With this config the v2 listener will discard v3 udp packets (but forward all traps to the other interface) and v3 listener will discard v2 packets and keep v3 packets.

0 Karma

Stevelim
Communicator

In case the SNMP Modular input dont work, check out Kepware's SNMP Driver. It is GUI driven, combined with the IDF, you can accquire and listen to the SNMP traps.

https://www.kepware.com/products/kepserverex/drivers/snmp/

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...