This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6
The most effective way to index SNMP events is to use snmptrapd to write them to a file.
First, configure snmptrapd to write to a file on disk.
# touch /var/run/snmp-traps # snmptrapd -Lf /var/run/snmp-traps
Then, configure the Splunk server to add the file as an input.