Ad Widget

Collapse

net-snmp > zabbix_traps.tmp fails extracting with some traps.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • jesras
    Junior Member
    • Dec 2022
    • 3

    #1

    net-snmp > zabbix_traps.tmp fails extracting with some traps.

    HI,
    I am new here - hope for an idea to fix a problem I have extracting snmptraps to zabbix.
    Been using snmp trap receiver works great, but discovered that a few snmptraps are not extracted to the /tmp/zabbix_traps.tmp, I use the standars perl script and it works well.
    My problem is that Traps send with DNS nane and not IP address seems not to be extracted to zabbix:traps.tmp all using IP does.
    ex snmp trap:
    NOT EXTRATCED : 11:00:03.326229 IP hidenat.xxxx.dk.3470 > zabbix.internal.cloudapp.net.snmp-trap:
    EXTRACTED OK : 10:55:00.043042 IP 51.144.xx.xxx.41756 > zabbix.internal.cloudapp.net.snmp-trap:

    Any ideas where to look and maybe why DNS is not working?

    Thanks​
  • Markku
    Senior Member
    Zabbix Certified SpecialistZabbix Certified ProfessionalZabbix Certified Expert
    • Sep 2018
    • 1781

    #2
    See the documentation about SNMP traps: https://www.zabbix.com/documentation...types/snmptrap

    5. For each trap Zabbix finds all "SNMP trapper" items with host interfaces matching the received trap address. Note that only the selected "IP" or "DNS" in host interface is used during the matching.
    So if you don't have a host called "hidenat.xxxx.dk" in Zabbix it won't match any host.

    Markku

    Comment


    • jesras
      jesras commented
      Editing a comment
      I have setup a host with snmp interface called hidenat.xxxx.dk so thats not the case.
  • jesras
    Junior Member
    • Dec 2022
    • 3

    #3
    Host interface:
    Click image for larger version

Name:	image.png
Views:	146
Size:	33.4 KB
ID:	455752

    Comment

    • Markku
      Senior Member
      Zabbix Certified SpecialistZabbix Certified ProfessionalZabbix Certified Expert
      • Sep 2018
      • 1781

      #4
      Can you clarify "not extracted to zabbix_traps.tmp", do you mean that the trap was not saved there?

      Is the SNMP trap community correctly configured?

      Markku

      Comment


      • jesras
        jesras commented
        Editing a comment
        The community is setup like other already working traps, difference is that they used ip not DNS for identification.
        I see the traps arriving with tcpdump port 162 together with other traps, traps using ip is written to zabbix_traps.tmp but not the once using DNS.
        The script used for this is all standard. (no modifications made)
    • Markku
      Senior Member
      Zabbix Certified SpecialistZabbix Certified ProfessionalZabbix Certified Expert
      • Sep 2018
      • 1781

      #5
      By looking at the script at https://git.zabbix.com/projects/ZBX/...ap_receiver.pl there are no selection statements: whatever comes in should also come out (to the file), but you are saying that some traps are saved but others are not.

      So you need to troubleshoot why your snmptrapd does not call the script in some cases. Or is your trap receiver script somehow faulty? (You haven't mentioned where the script has come from)

      How is your snmptrapd configured? For the reference, here is one example: https://majornetwork.net/2021/05/con...bix-on-debian/

      To be clear: this is not a Zabbix problem based on your problem description, this is an snmptrapd problem. I'm not sure what you mean "DNS for identification".

      Markku
      Last edited by Markku; 08-12-2022, 19:09.

      Comment

      • Markku
        Senior Member
        Zabbix Certified SpecialistZabbix Certified ProfessionalZabbix Certified Expert
        • Sep 2018
        • 1781

        #6
        Btw based on https://linux.die.net/man/8/snmptrapd there is -n option in snmptrapd to disable reverse name lookups if that helps you.

        Markku

        Comment

        Working...