Logstash 7.17无法接收MikroTik的SNMP OID与Netflow数据求助
解决Logstash接收MikroTik SNMP与Netflow数据失败的问题
一、先修正Logstash配置的语法错误
你的filter段存在多余的闭合括号,会导致数据处理异常,修正后的完整配置如下:
input { snmp { hosts => [{host => "192.168.56.3:161" version => "3"}] get => ["1.3.6.1.2.1.25.3.3.1.2.1", "1.3.6.1.2.1.25.2.3.1.5.65536", "1.3.6.1.2.1.25.2.3.1.6.65536", "1.3.6.1.2.1.1.3.0", "1.3.6.1.2.1.31.1.1.1.7.1", "1.3.6.1.2.1.31.1.1.1.11.1", "1.3.6.1.2.1.1.1.0"] security_name => "snmp-v3" auth_protocol => "md5" auth_pass => "********" priv_protocol => "des" priv_pass => "********" security_level => "authPriv" type => "snmp" timeout => 10 poll_interval => 60 } udp { port => 9995 codec => netflow { versions => [5, 9] templates_cache_size => 1000 templates_ttl => 3600 } type => "netflow" } } filter { mutate { convert => { "[netflow][ipv4_src_addr]" => "string" } } geoip { source => "[netflow][ipv4_src_addr]" } } output{ if [type] == "snmp" { elasticsearch { hosts => ["192.168.56.102:9200"] index => "snmp-metrics" user => "******" password => "*********" } } if [type] == "netflow" { elasticsearch { hosts => ["192.168.56.102:9200"] index => "logstash-netflow-analytics-%{+YYYY.MM.dd}" user => "******" password => "******" } } }
二、解决SNMP请求超时问题
日志中的timeout sending snmp get request是核心问题,按以下步骤排查:
- 验证网络连通性:在Logstash服务器执行
ping 192.168.56.3确认能通,再用SNMP工具测试配置:
如果无法获取值,说明SNMPv3配置不匹配,检查MikroTik端设置。snmpwalk -v3 -u snmp-v3 -l authPriv -a MD5 -A "你的真实auth密码" -x DES -X "你的真实priv密码" 192.168.56.3 1.3.6.1.2.1.1.1.0 - 检查MikroTik的SNMPv3配置:
- 确认已创建SNMPv3用户:
/snmp user add name=snmp-v3 authentication-protocol=md5 authentication-password=你的auth密码 encryption-protocol=des encryption-password=你的priv密码 security-level=auth-priv - 确认SNMP服务已开启:
/snmp set enabled=yes - 确认允许Logstash服务器IP访问:如果设置了SNMP社区限制,需添加允许规则,或关闭限制。
- 确认已创建SNMPv3用户:
- 调整Logstash SNMP插件参数:
- 将hosts格式改为
192.168.56.3:161(去掉udp://前缀,部分版本插件不兼容) - 添加
timeout => 10延长超时时间 - 添加
poll_interval => 60减少请求频率,避免被路由器限流
- 将hosts格式改为
三、解决Netflow解码警告问题
日志中的Can't (yet) decode flowset id 256是因为未收到Netflow模板,按以下步骤处理:
- 检查MikroTik的Netflow配置:
- 开启Netflow并指定目标:
/ip traffic-flow set enabled=yes target=192.168.56.102 port=9995 version=9 - 配置采集接口:
/ip traffic-flow interface add interface=all(确保覆盖所有需要采集的接口) - 调整模板发送间隔:
/ip traffic-flow set template-timeout=300(每5分钟发送一次模板)
- 开启Netflow并指定目标:
- 优化Logstash Netflow codec参数:
添加templates_cache_size => 1000和templates_ttl => 3600,确保模板缓存足够且不过期过快
四、验证Elasticsearch输出权限
确认Logstash使用的Elasticsearch用户拥有写入snmp-metrics和logstash-netflow-analytics-*索引的权限,执行以下命令测试:
curl -u 你的ES用户名:你的ES密码 -XPOST http://192.168.56.102:9200/snmp-metrics/_doc -d '{"test":"data"}' -H "Content-Type: application/json"
如果返回成功,说明权限正常;否则需要在Elasticsearch中配置对应的角色权限。
内容的提问来源于stack exchange,提问作者Hanginium2412
相关产品推荐
相关产品推荐

