Schaatsbergen, Chris
2010-03-23 15:06:19 UTC
Greetings,
I am a relative new Linux user and have been given the task to implement Splunk. Splunk can unfortunately not directly read SNMP traps and thus I am using snmptrapd to write the snmp traps into a logfile that Splunk is very good at interpreting. But Splunk needs some kind of timestamp to get some order in chaos. After some reading up I found the snmptrapd.conf file and adjusted settings. Everything is working, the snmp traps get logged in the logfile, but without the formatting I added in the snmptrapd.conf. Unfortunately since I am not using the default output, I seem unable to pass the format parameter to snmptrapd itself either.
We am running Debian server, net-snmp version 5.4.1. The snmptrapd.conf file currently:
format1 '%y-%m-%l ?%h:%j:%k ?%b ?%P ?%N ?%W ?%v\n'
format2 '%y-%m-%l ?%h:%j:%k ?%b ?%P ?%N ?%W ?%v\n'
authCommunity log Cisco
logOption f /var/run/snmp-traps
But I tried loads of different settings for the formats already.
Can anyone please guide me in the right direction?
Chris Schaatsbergen
--
aleo solar Deutschland GmbH
Chris Schaatsbergen
IT-Projekte / IT-Projects
Osterstraße 15, 26122 Oldenburg
Tel: +49 441/21988-288
Fax: +49 441/21988-150
c<mailto:***@aleo-solar.de>***@aleo-solar.de
http://www.aleo-solar.de<http://www.aleo-solar.de/>
Geschäftsführer: Dipl.-Oec. Jakobus Smit, Betriebswirt (WA) Heinrich Willers; Sitz der Gesellschaft: Oldenburg (Oldb), Handelregister Oldenburg, HRB 4947
I am a relative new Linux user and have been given the task to implement Splunk. Splunk can unfortunately not directly read SNMP traps and thus I am using snmptrapd to write the snmp traps into a logfile that Splunk is very good at interpreting. But Splunk needs some kind of timestamp to get some order in chaos. After some reading up I found the snmptrapd.conf file and adjusted settings. Everything is working, the snmp traps get logged in the logfile, but without the formatting I added in the snmptrapd.conf. Unfortunately since I am not using the default output, I seem unable to pass the format parameter to snmptrapd itself either.
We am running Debian server, net-snmp version 5.4.1. The snmptrapd.conf file currently:
format1 '%y-%m-%l ?%h:%j:%k ?%b ?%P ?%N ?%W ?%v\n'
format2 '%y-%m-%l ?%h:%j:%k ?%b ?%P ?%N ?%W ?%v\n'
authCommunity log Cisco
logOption f /var/run/snmp-traps
But I tried loads of different settings for the formats already.
Can anyone please guide me in the right direction?
Chris Schaatsbergen
--
aleo solar Deutschland GmbH
Chris Schaatsbergen
IT-Projekte / IT-Projects
Osterstraße 15, 26122 Oldenburg
Tel: +49 441/21988-288
Fax: +49 441/21988-150
c<mailto:***@aleo-solar.de>***@aleo-solar.de
http://www.aleo-solar.de<http://www.aleo-solar.de/>
Geschäftsführer: Dipl.-Oec. Jakobus Smit, Betriebswirt (WA) Heinrich Willers; Sitz der Gesellschaft: Oldenburg (Oldb), Handelregister Oldenburg, HRB 4947