You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Logstash 7.17无法接收MikroTik的SNMP OID与Netflow数据求助

解决Logstash接收MikroTik SNMP与Netflow数据失败的问题

一、先修正Logstash配置的语法错误

你的filter段存在多余的闭合括号,会导致数据处理异常,修正后的完整配置如下:

input {
   snmp {
     hosts => [{host => "192.168.56.3:161" version => "3"}]
     get => ["1.3.6.1.2.1.25.3.3.1.2.1", "1.3.6.1.2.1.25.2.3.1.5.65536", "1.3.6.1.2.1.25.2.3.1.6.65536", "1.3.6.1.2.1.1.3.0", "1.3.6.1.2.1.31.1.1.1.7.1", "1.3.6.1.2.1.31.1.1.1.11.1", "1.3.6.1.2.1.1.1.0"]
     security_name => "snmp-v3"
     auth_protocol => "md5"
     auth_pass => "********"
     priv_protocol => "des"
     priv_pass => "********"
     security_level => "authPriv"
     type => "snmp"
     timeout => 10
     poll_interval => 60
   }

   udp {
     port => 9995
     codec => netflow {
       versions => [5, 9]
       templates_cache_size => 1000
       templates_ttl => 3600
     }
     type => "netflow"
   }
} 
filter {
    mutate {
        convert => { "[netflow][ipv4_src_addr]" => "string" }
    }
    geoip {
       source => "[netflow][ipv4_src_addr]"
    }
}
output{
  if [type] == "snmp" {
     elasticsearch {
        hosts => ["192.168.56.102:9200"]
        index => "snmp-metrics"
        user => "******"
        password => "*********"
     }
  }

 if [type] == "netflow" {
    elasticsearch {
      hosts => ["192.168.56.102:9200"]
      index => "logstash-netflow-analytics-%{+YYYY.MM.dd}"
      user => "******"
      password => "******"
    }
 }
}

二、解决SNMP请求超时问题

日志中的timeout sending snmp get request是核心问题,按以下步骤排查:

  • 验证网络连通性:在Logstash服务器执行ping 192.168.56.3确认能通,再用SNMP工具测试配置:
    snmpwalk -v3 -u snmp-v3 -l authPriv -a MD5 -A "你的真实auth密码" -x DES -X "你的真实priv密码" 192.168.56.3 1.3.6.1.2.1.1.1.0
    
    如果无法获取值,说明SNMPv3配置不匹配,检查MikroTik端设置。
  • 检查MikroTik的SNMPv3配置:
    1. 确认已创建SNMPv3用户:/snmp user add name=snmp-v3 authentication-protocol=md5 authentication-password=你的auth密码 encryption-protocol=des encryption-password=你的priv密码 security-level=auth-priv
    2. 确认SNMP服务已开启:/snmp set enabled=yes
    3. 确认允许Logstash服务器IP访问:如果设置了SNMP社区限制,需添加允许规则,或关闭限制。
  • 调整Logstash SNMP插件参数:
    • 将hosts格式改为192.168.56.3:161(去掉udp://前缀,部分版本插件不兼容)
    • 添加timeout => 10延长超时时间
    • 添加poll_interval => 60减少请求频率,避免被路由器限流

三、解决Netflow解码警告问题

日志中的Can't (yet) decode flowset id 256是因为未收到Netflow模板,按以下步骤处理:

  • 检查MikroTik的Netflow配置:
    1. 开启Netflow并指定目标:/ip traffic-flow set enabled=yes target=192.168.56.102 port=9995 version=9
    2. 配置采集接口:/ip traffic-flow interface add interface=all(确保覆盖所有需要采集的接口)
    3. 调整模板发送间隔:/ip traffic-flow set template-timeout=300(每5分钟发送一次模板)
  • 优化Logstash Netflow codec参数:
    添加templates_cache_size => 1000和templates_ttl => 3600,确保模板缓存足够且不过期过快

四、验证Elasticsearch输出权限

确认Logstash使用的Elasticsearch用户拥有写入snmp-metrics和logstash-netflow-analytics-*索引的权限,执行以下命令测试:

curl -u 你的ES用户名:你的ES密码 -XPOST http://192.168.56.102:9200/snmp-metrics/_doc -d '{"test":"data"}' -H "Content-Type: application/json"

如果返回成功,说明权限正常;否则需要在Elasticsearch中配置对应的角色权限。

内容的提问来源于stack exchange,提问作者Hanginium2412

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 20:14:56