On This Page

Home / Stream/ Integrations/ Destinations/SNMP Trap Destination

SNMP Trap Destination

Cribl Stream supports forwarding of SNMP Traps out.

Type: Streaming | TLS Support: No | PQ Support: No

If you’ve modified SNMP trap events within the Pipeline, use the SNMP Trap Serialize Function to serialize compliant events into SNMP traps before sending them to an SNMP Trap Destination.

Configure Cribl Stream to Forward to SNMP Traps

  1. On the top bar, select Products, and then select Cribl Stream. Under Worker Groups, select a Worker Group. Next, you have two options:
    • To configure via QuickConnect, navigate to Routing > QuickConnect (Stream) or Collect (Edge). Select Add Destination and select the Destination you want from the list, choosing either Select Existing or Add New.
    • To configure via the Routes, select Data > Destinations or More > Destinations (Edge). Select the Destination you want. Next, select Add Destination.
  2. In the New Destination modal, configure the following under General Settings:
    • Output ID: Enter a unique name to identify this SNMP Trap definition. If you clone this Destination, Cribl Stream will add -CLONE to the original Output ID.
    • Description: Optionally, enter a description.
    • SNMP trap destinations: For each destination configured, enter the destination host Address and destination Port. Port: Defaults to 162. To specify additional SNMP trap destinations to forward traps to on new rows, select Add Destination.
  3. Next, you can configure the following Optional Settings:
    • Tags: Optionally, add tags that you can use to filter and group Destinations on the Destinations page. These tags aren’t added to processed events. Use a tab or hard return between (arbitrary) tag names.
  4. Optionally, you can adjust the Processing and Advanced settings outlined in the sections below.
  5. Select Save, then Commit & Deploy.

Processing Settings

Post-Processing

Pipeline: Pipeline or Pack to process data before sending the data out using this output.

Advanced Settings

DNS resolution period (sec): Specify the interval (in seconds) to re-resolve hostnames. This reduces the frequency of DNS lookups, improving performance. Use this setting to balance the overhead of DNS lookup calls with the expected frequency of changes in the DNS records. Defaults to 0 seconds, meaning DNS lookups occur for every outgoing trap.

Enable Source IP spoofing: This feature is available only for on-prem or hybrid Worker Groups (not available in Cribl.Cloud or on Cribl Edge Nodes). Toggle on to use the event Source IP and port for outgoing UDP packets.

This field preserves the event’s original IP address and port from the internal __srcIpPort field, rather than the Worker Process’s IP. This is useful when sending data to systems that rely on the Source IP to identify the original sender, such as SIEMs that use the device IP for event correlation. For the prerequisites, see udp-sender Helper Installation and Setup.

Maximum transmission unit (MTU): Displayed when Enable Source IP spoofing is enabled. Sets the maximum size of SNMP trap packets in bytes. The actual maximum payload size is the MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Defaults to 1500. When the packet length exceeds the MTU, the packet will be dropped.

Environment: If you’re using GitOps, optionally use this field to specify a single Git branch on which to enable this configuration. If empty, the config will be enabled everywhere.

udp-sender Helper Installation and Setup

Enabling IP spoofing requires creating raw network sockets, which demands elevated system privileges. To maintain the Cribl Stream security model, this operation is isolated into a dedicated helper program. IP spoofing is not available on Cribl Edge.

To enable IP spoofing, complete the following installation and privilege configuration steps on every Worker Node:

  1. Download the udp-sender helper binary. The source code and releases are available on the public GitHub repository: https://github.com/criblio/udp-sender/.

  2. Install the executable binary at the required path: /usr/bin/udp-sender

  3. Set permissions: A system administrator with root access must grant the binary the necessary Linux capability (CAP_NET_RAW). This allows the helper to construct and send raw network packets. Use the following command to set the capability:

    sudo setcap 'cap_net_raw+eip' /usr/bin/udp-sender

  4. If you are using package installers, the installation script will automatically create a custom udp-senders group and set the necessary capabilities on the binary using the setcap command. You will need to manually ensure the cribl user is added to this group.

If the udp-sender helper fails to start (for example, due to missing permissions), the Destination will enter an error state. Check the Worker Process logs for an error message indicating a failure to create a raw socket, which indicates that the CAP_NET_RAW capability was not correctly applied to the /usr/bin/udp-sender file.

For additional technical details on the binary’s function and installation, consult the README in the public GitHub repository.

Considerations for Working with SNMP Traps Data

  • It’s possible to work with SNMP metadata (i.e., we’ll decode the packet). Options include dropping, routing, etc. However, packets cannot be modified and sent to another SNMP Destination.

  • SNMP packets can be forwarded to non-SNMP Destinations (for example, Splunk, Syslog, S3, etc.).

  • SNMP packets can be forwarded to other SNMP Destinations. However, the contents of the incoming packet cannot be modified - i.e., we’ll forward the packets verbatim as they came in.

  • Non-SNMP input data cannot be sent to SNMP Destinations.

Troubleshooting

The Destination’s configuration modal has helpful tabs for troubleshooting:

Live Data: Try capturing live data to see real-time events as they flow through the Destination. On the Live Data tab, click Start Capture to begin viewing real-time data.

Logs: Review and search the logs that provide detailed information about the delivery process, including any errors or warnings that may have occurred.

Test: Ensures that the Destination is correctly set up and reachable. Verify that sample events are sent correctly by clicking Run Test.

You can also view the Monitoring page that provides a comprehensive overview of data volume and rate, helping you identify delivery issues. Analyze the graphs showing events and bytes in/out over time.