Ad Widget

Collapse

SNMPD redundants logs fill in my /var/

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Philippe bouyssou
    Junior Member
    • Jul 2024
    • 4

    #1

    SNMPD redundants logs fill in my /var/

    Hello to all and thanks for reading!

    Not sure if this is a specific zabbix problem but may be someone could help me.

    Since July 7, my /var/syslog (and daemon.log) are full of snmpd messages which look like :

    Code:
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: send response: Failure in sendto (error parsing snmp message version)
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.1.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.2.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.3.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.4.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.5.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.6.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.7.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.8.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.1
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.2
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.3
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.4
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.5
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.6
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.7
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.8
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.9
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.2.10
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.1
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.2
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.3
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.4
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.5
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.6
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.7
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.8
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.9
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.3.10
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.1
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.2
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.3
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.4
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.5
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.6
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.7
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.8
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.9
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.1.9.1.4.10
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.1.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.2.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.3.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.4.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.5.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.6.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.7.0
    Jul 7 22:08:10 <hostname> snmpd[<PID>]: -- iso.3.6.1.2.1.25.1.7.0
    Jul 7 22:08:11 <hostname> snmpd[<PID>]: send response: Failure in sendto
    0) <hostname> is the same machine that receives the logs where SNMPD and ZABBIX-AGENT are enable and active.

    1) this logs seem appear from 10/07/2024 but i can't find any change around this date on <hostname>.

    2) /etc/snmp/snmpd.conf was not modified since 2022...

    I have one:
    rocommunity <priv_xyz> <IP with no ping available>
    But this <IP with no ping available> was not avaible before logs which appear from 10/07/2024...


    Should i focus on error message of "Failure in sendto" ? or on "error parsing snmp message version" ?


    Of course any help would be welcome​... Thanks for reading!
    Philippe

Working...