Some of our Linux nodes (and maybe all of them) seem to generate tens to hundreds SNMP requests per second from Solarwinds - while being polled for the usual thinks like a fe volumes, CPU-memory, plus hardware health and one process monitor.
Is this normal? If so, how do I convince our network engineers this is not a threat? They're turning off snmp services on some of the critical nodes for fear "flooding our network with SNMP traffic".
Thanks!
Image may be NSFW.
Clik here to view.
Sampling of entries from /var/log/messages/ logs:
Aug 14 03:45:35 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:38044->[127.0.0.1] Aug 14 03:45:35 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:36210->[127.0.0.1] Aug 14 03:45:35 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:39611->[127.0.0.1] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:46 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:45:50 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:39377->[127.0.0.1] Aug 14 03:45:50 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:39377->[127.0.0.1] Aug 14 03:45:50 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:46720->[127.0.0.1] Aug 14 03:45:50 LinuxNodeHP snmpd[6915]: Connection from UDP: [127.0.0.1]:52632->[127.0.0.1] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192] Aug 14 03:46:02 LinuxNodeHP snmpd[6915]: Connection from UDP: [10.11.12.218]:49919->[10.11.12.192]