Ad Widget

Collapse

snmp trapper - invalid trap data found

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Robvil
    Junior Member
    • Sep 2017
    • 12

    #1

    snmp trapper - invalid trap data found

    Hi,

    I have setup Zabbix to receive snmp traps with snmptt.
    Some basic alerts is working, but when receiving alerts from my Watchguard firewalls, I get the below error on Zabbix server log file:

    invalid trap data found "04:01:46 2018/03/09 .1.3.6.1.4.1.3097.2.3.0.1 Normal "Status Events" 172.16.1.2 - An alarm was raised by Monitoring Agent of this bovpn event Fri Mar 09 05:01:49 2018 (CET) Webshop-HA2 BOVPN tunnel 'TunnelToAKKontorAarhus' local 172.16.1.0/255.255.255.0 remote 10.227.253.0/255.255.255.0 under gateway 'AK-KontorAarhus' is down

    How do i get Zabbix to parse these messages correct?

    Regards
    Robert
  • Robvil
    Junior Member
    • Sep 2017
    • 12

    #2
    No one?

    I´m running zabbix 3.4.7 on ubuntu 14.04.05 lts.

    I´m testning with traps from a firewall:
    29079:20180315:144845.816 invalid trap data found "14:48:44 2018/03/15 wgAlarmTrap Normal "Status Events" 172.16.1.2 - An alarm was raised by Monitoring Agent of this spoofing_dos Thu Mar 15 15:48:46 2018 (CET) Webshop-HA2 IP spoofing: Traffic detected from 169.0.0.28 to 224.0.0.251.
    "
    29079:20180315:144852.820 invalid trap data found "14:48:50 2018/03/15 wgAlarmTrap Normal "Status Events" 172.16.1.2 - An alarm was raised by Monitoring Agent of this spoofing_dos Thu Mar 15 15:48:53 2018 (CET) Webshop-HA2 IP spoofing: Traffic detected from 169.0.0.28 to 224.0.0.251.
    "
    29079:20180315:144904.829 invalid trap data found "14:49:03 2018/03/15 wgAlarmTrap Normal "Status Events" 172.16.1.2 - An alarm was raised by Monitoring Agent of this spoofing_dos Thu Mar 15 15:49:05 2018 (CET) Webshop-HA2 IP spoofing: Traffic detected from 169.0.0.28 to 169.0.255.255.

    What is the invalid data?

    Comment

    • Robvil
      Junior Member
      • Sep 2017
      • 12

      #3
      I changed from using snmptt to a perl script (http://whatizee.blogspot.dk/2015/12/...abbix.html?m=1) instead, and now i get a bit futher.

      Sending a trap test message from a Dell server (dont have the right MIBs loaded yet):
      29079:20180317:095256.943 unmatched trap received from "172.16.1.221": 09:52:55 2018/03/17 PDU INFO:
      community public
      notificationtype TRAP
      messageid 0
      errorstatus 0
      receivedfrom UDP: [172.16.1.221]:54134->[172.16.1.217]:162
      transactionid 13
      errorindex 0
      requestid 1616987702
      version 1
      VARBINDS:
      DISMAN-EVENT-MIB::sysUpTimeInstance type=67 value=Timeticks: (2205493147) 255 days, 6:22:11.47
      SNMPv2-MIB::snmpTrapOID.0 type=6 value=OID: DELL-SNMP-UPS-MIB::dell.10892.5.3.2.5.0.10395
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.1.0 type=4 value=STRING: "TST001"
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.2.0 type=4 value=STRING: "The iDRAC generated a test trap event in response to a user request."
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.3.0 type=2 value=INTEGER: 3
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.4.0 type=4 value=STRING: "G2C19F2"
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.5.0 type=4 value=STRING: "Host1"
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.6.0 type=4 value=""
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.7.0 type=4 value=""
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.8.0 type=4 value=""
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.9.0 type=4 value=STRING: "G2C19F2"
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.10.0 type=4 value=STRING: "Main System Chassis"
      DELL-SNMP-UPS-MIB::dell.10892.5.3.1.11.0 type=4 value=STRING: "idrac-G2C19F2"

      But i keep getting "unmatched trap received", so i cannot figure out, what i do wrong.
      I have 2 Itens created like snmptrap[] and snmptrap.fallback. And i have "Log unmatched SNMP traps" enabled.

      Why do Zabbix still believe it´s a unmatched trap?

      Comment

      • daro1337
        Junior Member
        • May 2018
        • 1

        #4
        Did you resolve this issue? I have same problem "invalid trap data found" zabbix 3.4.7 & ubuntu 16LTS. Strange thing, traps worked for me on this version. Problem occurs on perl script and traphandle default snmptthandler

        7921:20180512:222746.616 invalid trap data found "2018-05-12 22:27:45 0.0.0.0(via UDP: [127.0.0.1]:46614->[127.0.0.1]:162) TRAP, SNMP v1, community public
        iso.3.6.1.6.3.1.1.5.3 Enterprise Specific Trap (33) Uptime: 0:00:00.55
        iso.3.6.1.6.3.1.1.5.3 = STRING: "teststring000"

        Comment

        Working...