blob: 8f4a197d51e0e44e951cd2512b2f683801f97c6b [file] [log] [blame]
Wes Hardakerf2db9ff1999-02-27 00:06:49 +00001###############################################################################
Wes Hardakerc9b86761995-12-28 20:10:04 +00002#
Wes Hardakerf2db9ff1999-02-27 00:06:49 +00003# EXAMPLE.conf:
Dave Shieldae847052009-06-01 13:11:07 +00004# An example configuration file for configuring the Net-SNMP agent ('snmpd')
5# See the 'snmpd.conf(5)' man page for details
6#
7# Some entries are deliberately commented out, and will need to be explicitly activated
Wes Hardakerf2db9ff1999-02-27 00:06:49 +00008#
9###############################################################################
10#
Dave Shieldae847052009-06-01 13:11:07 +000011# AGENT BEHAVIOUR
Wes Hardakerc9b86761995-12-28 20:10:04 +000012#
Wes Hardakerc9b86761995-12-28 20:10:04 +000013
Dave Shieldae847052009-06-01 13:11:07 +000014# Listen for connections from the local system only
15agentAddress udp:127.0.0.1:161
16# Listen for connections on all interfaces (both IPv4 *and* IPv6)
17#agentAddress udp:161,udp6:[::1]:161
Wes Hardakerc0046361996-05-24 20:08:28 +000018
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000019
20
21###############################################################################
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000022#
Dave Shieldae847052009-06-01 13:11:07 +000023# SNMPv3 AUTHENTICATION
Wes Hardakerc2eafd11999-06-10 01:31:42 +000024#
Dave Shieldae847052009-06-01 13:11:07 +000025# Note that these particular settings don't actually belong here.
26# They should be copied to the file /var/net-snmp/snmpd.conf
27# and the passwords changed, before being uncommented in that file *only*.
28# Then restart the agent
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000029
Dave Shieldae847052009-06-01 13:11:07 +000030# createUser authOnlyUser MD5 "remember to change this password"
31# createUser authPrivUser SHA "remember to change this one too" DES
32# createUser internalUser MD5 "this is only ever used internally, but still change the password"
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000033
Dave Shieldae847052009-06-01 13:11:07 +000034# If you also change the usernames (which might be sensible),
35# then remember to update the other occurances in this example config file to match.
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000036
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000037
38
39###############################################################################
Dave Shieldae847052009-06-01 13:11:07 +000040#
41# ACCESS CONTROL
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000042#
43
Dave Shieldae847052009-06-01 13:11:07 +000044 # system + hrSystem groups only
45view systemonly included .1.3.6.1.2.1.1
46view systemonly included .1.3.6.1.2.1.25.1
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000047
Dave Shieldae847052009-06-01 13:11:07 +000048 # Full access from the local host
49#rocommunity public localhost
50 # Default access to basic system info
51 rocommunity public default -V systemonly
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000052
Dave Shieldae847052009-06-01 13:11:07 +000053 # Full access from an example network
54 # Adjust this network address to match your local
55 # settings, change the community string,
56 # and check the 'agentAddress' setting above
57#rocommunity secret 10.0.0.0/16
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000058
Dave Shieldae847052009-06-01 13:11:07 +000059 # Full read-only access for SNMPv3
60 rouser authOnlyUser
61 # Full write access for encrypted requests
62 # Remember to activate the 'createUser' lines above
63#rwuser authPrivUser priv
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000064
Dave Shieldae847052009-06-01 13:11:07 +000065# It's no longer typically necessary to use the full 'com2sec/group/access' configuration
66# r[ou]user and r[ow]community, together with suitable views, should cover most requirements
67
Wes Hardakerf2db9ff1999-02-27 00:06:49 +000068
69
70###############################################################################
Wes Hardakerc9b86761995-12-28 20:10:04 +000071#
Dave Shieldae847052009-06-01 13:11:07 +000072# SYSTEM INFORMATION
Wes Hardakerc9b86761995-12-28 20:10:04 +000073#
74
Dave Shieldae847052009-06-01 13:11:07 +000075# Note that setting these values here, results in the corresponding MIB objects being 'read-only'
76# See snmpd.conf(5) for more details
77sysLocation Sitting on the Dock of the Bay
78sysContact Me <me@example.org>
79 # Application + End-to-End layers
80sysServices 72
Wes Hardakerc9b86761995-12-28 20:10:04 +000081
Wes Hardakerc9b86761995-12-28 20:10:04 +000082
Wes Hardakerc9b86761995-12-28 20:10:04 +000083#
Dave Shieldae847052009-06-01 13:11:07 +000084# Process Monitoring
Wes Hardakerc9b86761995-12-28 20:10:04 +000085#
Dave Shieldae847052009-06-01 13:11:07 +000086 # At least one 'mountd' process
87proc mountd
88 # No more than 4 'ntalkd' processes - 0 is OK
89proc ntalkd 4
90 # At least one 'sendmail' process, but no more than 10
91proc sendmail 10 1
92
93# Walk the UCD-SNMP-MIB::prTable to see the resulting output
94# Note that this table will be empty if there are no "proc" entries in the snmpd.conf file
Wes Hardakerc9b86761995-12-28 20:10:04 +000095
96
Dave Shieldae847052009-06-01 13:11:07 +000097#
98# Disk Monitoring
99#
100 # 10MBs required on root disk, 5% free on /var, 10% free on all other disks
101disk / 10000
102disk /var 5%
103includeAllDisks 10%
104
105# Walk the UCD-SNMP-MIB::dskTable to see the resulting output
106# Note that this table will be empty if there are no "disk" entries in the snmpd.conf file
107
108
109#
110# System Load
111#
112 # Unacceptable 1-, 5-, and 15-minute load averages
113load 12 10 5
114
115# Walk the UCD-SNMP-MIB::laTable to see the resulting output
116# Note that this table *will* be populated, even without a "load" entry in the snmpd.conf file
117
Wes Hardakerc9b86761995-12-28 20:10:04 +0000118
Wes Hardakerf2db9ff1999-02-27 00:06:49 +0000119
120###############################################################################
Dave Shieldae847052009-06-01 13:11:07 +0000121#
122# ACTIVE MONITORING
Wes Hardakerc9b86761995-12-28 20:10:04 +0000123#
124
Dave Shieldae847052009-06-01 13:11:07 +0000125 # send SNMPv1 traps
126 trapsink localhost public
127 # send SNMPv2c traps
128#trap2sink localhost public
129 # send SNMPv2c INFORMs
130#informsink localhost public
Wes Hardakerc9b86761995-12-28 20:10:04 +0000131
Dave Shieldae847052009-06-01 13:11:07 +0000132# Note that you typically only want *one* of these three lines
133# Uncommenting two (or all three) will result in multiple copies of each notification.
Wes Hardakerc9b86761995-12-28 20:10:04 +0000134
Dave Shieldae847052009-06-01 13:11:07 +0000135
Wes Hardakerc9b86761995-12-28 20:10:04 +0000136#
Dave Shieldae847052009-06-01 13:11:07 +0000137# Event MIB - automatically generate alerts
Wes Hardakerc9b86761995-12-28 20:10:04 +0000138#
Dave Shieldae847052009-06-01 13:11:07 +0000139 # Remember to activate the 'createUser' lines above
140iquerySecName internalUser
141rouser internalUser
142 # generate traps on UCD error conditions
143defaultMonitors yes
144 # generate traps on linkUp/Down
145linkUpDownNotifications yes
Wes Hardakerc9b86761995-12-28 20:10:04 +0000146
Wes Hardakerc9b86761995-12-28 20:10:04 +0000147
Wes Hardakerf2db9ff1999-02-27 00:06:49 +0000148
149###############################################################################
Dave Shieldae847052009-06-01 13:11:07 +0000150#
151# EXTENDING THE AGENT
Wes Hardakerc9b86761995-12-28 20:10:04 +0000152#
153
Wes Hardakerc9b86761995-12-28 20:10:04 +0000154#
Dave Shieldae847052009-06-01 13:11:07 +0000155# Arbitrary extension commands
Wes Hardakerc9b86761995-12-28 20:10:04 +0000156#
Dave Shieldae847052009-06-01 13:11:07 +0000157 extend test1 /bin/echo Hello, world!
158 extend-sh test2 echo Hello, world! ; echo Hi there ; exit 35
159#extend-sh test3 /bin/sh /tmp/shtest
Wes Hardakerc9b86761995-12-28 20:10:04 +0000160
Dave Shieldae847052009-06-01 13:11:07 +0000161# Note that this last entry requires the script '/tmp/shtest' to be created first,
162# containing the same three shell commands, before the line is uncommented
163
164# Walk the NET-SNMP-EXTEND-MIB tables (nsExtendConfigTable, nsExtendOutput1Table
165# and nsExtendOutput2Table) to see the resulting output
166
167# Note that the "extend" directive supercedes the previous "exec" and "sh" directives
168# However, walking the UCD-SNMP-MIB::extTable should still returns the same output,
169# as well as the fuller results in the above tables.
170
171
Wes Hardakerc9b86761995-12-28 20:10:04 +0000172#
Dave Shieldae847052009-06-01 13:11:07 +0000173# "Pass-through" MIB extension command
Wes Hardakerc9b86761995-12-28 20:10:04 +0000174#
Dave Shieldae847052009-06-01 13:11:07 +0000175#pass .1.3.6.1.4.1.8072.2.255 /bin/sh PREFIX/local/passtest
176#pass .1.3.6.1.4.1.8072.2.255 /usr/bin/perl PREFIX/local/passtest.pl
177
178# Note that this requires one of the two 'passtest' scripts to be installed first,
179# before the appropriate line is uncommented.
180# These scripts can be found in the 'local' directory of the source distribution,
181# and are not installed automatically.
182
183# Walk the NET-SNMP-PASS-MIB::netSnmpPassExamples subtree to see the resulting output
184
185
Wes Hardakerc9b86761995-12-28 20:10:04 +0000186#
Dave Shieldae847052009-06-01 13:11:07 +0000187# AgentX Sub-agents
Wes Hardaker781380f1997-02-03 09:03:10 +0000188#
Dave Shieldae847052009-06-01 13:11:07 +0000189 # Run as an AgentX master agent
190 master agentx
191 # Listen for network connections (from localhost)
192 # rather than the default named socket /var/agentx/master
193#agentXSocket tcp:localhost:705