Skip to main content

SNMP Trap OID Is Not Translated by the Varbind Translation Pack with Cribl Stream or Cribl Edge

  • September 12, 2026
  • 0 replies
  • 2 views

Jessica Bracken

Symptom

An SNMP trap arrives in Cribl, but its notification OID remains numeric instead of being translated to a trap name or expected fields. Other standard or vendor-specific OIDs may translate successfully.

Environment

  • Cribl Stream or Cribl Edge
  • SNMP trap input
  • Cribl SNMP Trap Varbind Translation Pack

Resolution

  1. Record the exact trap OID and SNMP version.
  2. Capture the original trap payload before translation.
  3. Verify the OID against the authoritative MIB definition.
  4. Check whether a newer Pack version contains the mapping.
  5. Update the lookup in the pack.
  6. Deploy the approved lookup or Pack update.
  7. Test the target trap after a fresh event arrives.
  8. Verify that existing mappings remain unchanged.

Cause

This issue can occur when:

  • The installed Pack lookup does not contain the requested OID.
  • The OID is vendor-specific and its MIB is not included in the Pack.
  • The Pack version is older than the version containing the mapping.
  • The trap payload uses an OID format that does not match the lookup key.

Additional Information

A lookup can translate the notification name without translating associated varbinds. Verify both outcomes separately when testing a Pack update.