Symptom
An SNMP trap arrives in Cribl, but its notification OID remains numeric instead of being translated to a trap name or expected fields. Other standard or vendor-specific OIDs may translate successfully.
Environment
- Cribl Stream or Cribl Edge
- SNMP trap input
- Cribl SNMP Trap Varbind Translation Pack
Resolution
- Record the exact trap OID and SNMP version.
- Capture the original trap payload before translation.
- Verify the OID against the authoritative MIB definition.
- Check whether a newer Pack version contains the mapping.
- Update the lookup in the pack.
- Deploy the approved lookup or Pack update.
- Test the target trap after a fresh event arrives.
- Verify that existing mappings remain unchanged.
Cause
This issue can occur when:
- The installed Pack lookup does not contain the requested OID.
- The OID is vendor-specific and its MIB is not included in the Pack.
- The Pack version is older than the version containing the mapping.
- The trap payload uses an OID format that does not match the lookup key.
Additional Information
A lookup can translate the notification name without translating associated varbinds. Verify both outcomes separately when testing a Pack update.
