All Apps and Add-ons

SNMP Modular Example

DerekKing
Path Finder

Hi,

Would it be possible for someone who has this working to show an example please. I'm not too familiar with SNMP MIBs and OIDs etc but I would like to poll Cisco switches to get interface name and utilization figures out of them.

Thanks for any help.
Derek

Tags (1)
1 Solution

Damien_Dallimor
Ultra Champion

You may be able to use the following OIDs from the "Interface MIB" (IF-MIB) for polling the Cisco switch interface utilization.

Inbound

1.3.6.1.2.1.2.2.1.10

http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=1.3.6.1.2.1.2.2.1.10&translate=Trans...

Outbound

1.3.6.1.2.1.2.2.1.16

http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=1.3.6.1.2.1.2.2.1.16&translate=Trans...

And the setup for the SNMP Modular Input stanza would be quite simple :

Example of configuration from inputs.conf

[snmp://my_cisco_switch]
destination = myswitchhostname
do_bulk_get = 1
ipv6 = 0
listen_traps = 0
mib_names = IF-MIB
object_names = 1.3.6.1.2.1.2.2.1.10,1.3.6.1.2.1.2.2.1.16
snmp_version = 2C
sourcetype = foo
index = foo
split_bulk_output = 0
disabled = 0

Screenshot of setup page in Splunk Manager

alt text

View solution in original post

Damien_Dallimor
Ultra Champion

You may be able to use the following OIDs from the "Interface MIB" (IF-MIB) for polling the Cisco switch interface utilization.

Inbound

1.3.6.1.2.1.2.2.1.10

http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=1.3.6.1.2.1.2.2.1.10&translate=Trans...

Outbound

1.3.6.1.2.1.2.2.1.16

http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=1.3.6.1.2.1.2.2.1.16&translate=Trans...

And the setup for the SNMP Modular Input stanza would be quite simple :

Example of configuration from inputs.conf

[snmp://my_cisco_switch]
destination = myswitchhostname
do_bulk_get = 1
ipv6 = 0
listen_traps = 0
mib_names = IF-MIB
object_names = 1.3.6.1.2.1.2.2.1.10,1.3.6.1.2.1.2.2.1.16
snmp_version = 2C
sourcetype = foo
index = foo
split_bulk_output = 0
disabled = 0

Screenshot of setup page in Splunk Manager

alt text

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...