Log Types: SNMPTrap

Overview

Servers and services capable of generating SNMPTrap data can send content to the Snare Central server for collection, monitoring and forensic archival.

Collection

Snare Central listens on the standard SNMPTrap ports (TCP and UDP) for trap messages.

Sample Events

iso.3.6.1.2.1.1.3.0 = 0:0:00:00.00 iso.3.6.1.6.3.1.1.4.1.0 = iso.3.6.1.4.1.8072.2.3.0.1 iso.3.6.1.4.1.8072.2.3.2.1 = 60 Heartbeat notification

Fields

Field

Description

Field

Description

DATE

Event date, in the format YYYY-MM-DD

TIME

Event time, in the format HH:MM:SS

SYSTEM

The source system

TABLE

SNMPTrap

STRINGS

The SNMPTrap message

Notes

-