All Apps and Add-ons

6.5 error "tooBig"

pbalsley
Path Finder

I am running splunk 6.5.0. Trying to poll a cisco ASA firewall. I am getting this error message:

ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/snmpmod/bin/snmpif.py" file="snmpif.py" line=191 stanza="snmpif://gateway.xx.net" error=pdu msg="tooBig at ?" interfaces=15

Trying to figure out the cause. I am able to graph/poll via MRTG the same device.

0 Karma

pbalsley
Path Finder

Solution was to comment out some of the OIDs that were being used to poll the device with.
In snmpif.py I commented out some of the OIDs in "interface_mibs".

Not sure if this is specific to using a cisco ASA or splunk 6.5.0.

Otherwise app works great!.

0 Karma

gokadroid
Motivator

Till the time help arrives from the app developer maybe this might be of some help and might lead you to the cause you are looking for:
https://community.helpsystems.com/forums/intermapper/snmp-probes/2f7f53db-fa83-e511-80cf-0050568460e...

Excerpt:

A "tooBig" response simply means that the SNMP agent tried to generate a response with all of its OID's, but the response grew too big for its buffer. The limit is 50 OIDs per-request. However, the probe writer is responsible for setting the limit lower if it asks for too many variables at a time and receives a 'tooBig' response in return
0 Karma

pbalsley
Path Finder

Thank you, that was helpful in finding the answer.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...