LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-16-2016, 09:45 PM   #1
Xyue
LQ Newbie
 
Registered: Apr 2016
Posts: 7

Rep: Reputation: Disabled
Snmptrap message in syslog


Hi guys,

I have installed Rsyslog to collect the log from my network device and it will stored the log into the text file.

Besides the syslog, i get the snmp traps details also.

Currently my plan is to save the syslog into mysql database instead of text file so i would like to solve the snmp trap message log into syslog first.

Can anyone advise how to solve this ?

Thank you very much in advance.

Below shows sample syslog log file.
May 17 09:17:58 bigip1 err iControlPortal.cgi[6200]: Checking for FIPS card.. FIPS open failed.
May 17 09:18:40 2idf-45-sw1 1550: *May 17 08:58:53.360: %LINK-3-UPDOWN: Interface GigabitEthernet6/30, changed state to down
May 17 09:18:47 2idf-45-sw1 1551: *May 17 08:58:59.552: %LINK-3-UPDOWN: Interface GigabitEthernet6/30, changed state to up

May 17 09:26:41 zabsrv snmptrapd[2866]: 2016-05-17 09:26:41 2idf-45-sw1 [10.32.250.20] (via UDP: [10.32.250.20]:1032->[10.4.2.240]) TRAP, SNMP v1, community zabbix#012#011SNMPv2-SMI::enterprises.9.9.215.2 Enterprise Specific Trap (1) Uptime: 58 days, 16:50:51.59#012#011SNMPv2-SMI::enterprises.9.9.215.1.1.8.1.2.1 = Hex-STRING: 01 03 36 34 BD C8 2C 5D 22 00 2D 00 #011SNMPv2-SMI::enterprises.9.9.215.1.1.8.1.3.1 = INTEGER: 507185158

May 17 09:26:41 zabsrv snmptrapd[2866]: 2016-05-17 09:26:41 10.32.250.76(via UDP: [10.32.250.76]:61853->[10.4.2.240]) TRAP, SNMP v1, community zabbix#012#011SNMPv2-SMI::enterprises.9.9.215.2 Enterprise Specific Trap (1) Uptime: 256 days, 16:26:37.74#012#011SNMPv2-SMI::enterprises.9.9.215.1.1.8.1.2.1 = Hex-STRING: 01 03 41 08 D0 9F 9E 7C A8 00 83 01 00 E2 D4 C9 #012EF E5 32 1D 00 83 01 03 41 64 D8 14 A4 09 81 00 #01272 01 00 E2 D4 BE D9 42 A0 15 00 72 01 03 41 08 #012D0 9F 9E 7C A0 00 8E 00 #011SNMPv2-SMI::enterprises.9.9.215.1.1.8.1.3.1 = INTEGER: -2077207522
 
Old 05-17-2016, 06:51 PM   #2
kirukan
Senior Member
 
Registered: Jun 2008
Location: Eelam
Distribution: Redhat, Solaris, Suse
Posts: 1,278

Rep: Reputation: 148Reputation: 148
rsyslog server is receiving the logs from your network device so you supposed to exclude sending snmptraps to the rsyslog server. Tell your network device what are the logs need to be send out to syslog server.
 
Old 05-17-2016, 08:58 PM   #3
Xyue
LQ Newbie
 
Registered: Apr 2016
Posts: 7

Original Poster
Rep: Reputation: Disabled
Hi Kirukan,

Syslog was using port 514 and has been config to save the data in location A.
Snmptrap was using port 162 and has been config to save the data in location B.

I have manually put in the filter in syslog.

However, i was still curious why the snmptrap will will goes to location A.

Thanks anyway.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Additional custom string message with snmptrap with different OID type divyashree Linux - Newbie 3 03-06-2014 03:12 AM
syslog message format Xaver Solaris / OpenSolaris 2 04-04-2011 04:24 AM
Syslog-ng: filtering out a message ReefShark Linux - Server 0 07-30-2008 07:11 AM
Please Help on Reoccuring Message in SysLog Rufus330Ci Linux - Software 2 01-25-2006 01:57 PM
syslog error message saag Linux - Newbie 0 03-20-2004 03:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 02:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration