How to decode snmpwalk output with a MIB
A raw snmpwalk is a long list of numbers. With the right MIB, every line tells you which object it is, which table row it belongs to, and what the value really means, including the scaling that is easy to miss.
1. Get a walk you can work with
# numeric OIDs (safest to share and to parse)
snmpwalk -v2c -c public -On 192.0.2.10 .1.3.6.1.4.1
# symbolic names, with the vendor MIB in the current directory
snmpwalk -v2c -c public -M +. -m +VENDOR-MIB 192.0.2.10 .1.3.6.1.4.1
# faster on large devices
snmpbulkwalk -v2c -c public -On 192.0.2.10 .1.3.6.1.4.1.318
Walk the vendor subtree (1.3.6.1.4.1.<enterprise number>) rather than only 1.3.6.1.2.1, which holds just the standard MIBs.
2. Read the OID
Take this line from an environmental monitor:
.1.3.6.1.4.1.52674.500.4.1.1.1.2.61 = INTEGER: 235
| Part | Meaning |
|---|---|
1.3.6.1.4.1 | iso.org.dod.internet.private.enterprises |
52674 | Enterprise number (the vendor) |
500.4.1.1 | Branch and table defined in the vendor MIB (tempSensorTable) |
.1 | The row object (tempSensorEntry) |
.2 | The column (tempSensorValue) |
.61 | The row index: which sensor this is |
The MIB lookup stops at the longest known OID (the column). Everything after it is the instance. For a scalar, the instance is always .0. Anything else on a scalar means the MIB and the device disagree.
3. Decode table indexes
The row's INDEX clause says how to read the instance. Each index object is encoded by its type:
| Index type | Encoding | Example |
|---|---|---|
| INTEGER / Unsigned32 | One sub-identifier | .61 → 61 |
| OCTET STRING (variable) | Length, then one sub-identifier per byte | .4.103.101.45.48 → "ge-0" |
| OCTET STRING with IMPLIED (last index) | Bytes without length | .103.101.45.48 → "ge-0" |
Fixed-size OCTET STRING, e.g. SIZE(6) | Exactly N bytes, no length | MAC address |
| IpAddress | Four sub-identifiers | .10.0.0.1 → 10.0.0.1 |
Composite indexes simply concatenate these, in the order of the INDEX clause. An index object defined in another MIB (for example ifIndex from IF-MIB) needs that MIB loaded to be decoded.
Indexes are not identities. Two identical devices can list the same sensor under different indexes. To compare devices or build monitoring, identify rows by a label, port or serial column, not by the index.
4. Apply the scaling
The value 235 above is not 235 degrees. The MIB explains why, in one of these places:
- DISPLAY-HINT on the textual convention:
"d-1"inserts one decimal, so 235 → 23.5. - UNITS clause:
UNITS "0.1 degrees Celsius"or"tenth Volts"means multiply by 0.1.UNITS "0.1 Hertz"turns 500 into 50.0 Hz. - DESCRIPTION: "in tenths of degrees Celsius", "expressed in hundredths", "multiplied by 10".
Watch for false friends. mHz is millihertz, not megahertz. A UNITS of "hours" on an object named ...StartHour is a time of day, not a duration.
5. Know the special types
| Walk type | How to read it |
|---|---|
INTEGER: critical(3) | Enumeration: the MIB lists the names. Only the number matters for monitoring. |
Timeticks: (123456) 0:20:34.56 | Hundredths of a second: 123456 → 1234.56 s |
Counter32 / Counter64 | Ever-increasing and wrapping. Only the rate between two polls is meaningful. Byte counters × 8 give bits per second. |
Gauge32 | A current level that can go up and down |
Hex-STRING: 00 1A 2B ... | Binary or non-ASCII bytes: MAC addresses, DateAndTime, or text with special characters |
No Such Instance | The object exists in the MIB but the device does not implement that row |
6. When OIDs stay unknown
- Enterprise number without a MIB: load the vendor MIB for that enterprise.
- Undefined column in a known table: the device firmware is newer than your MIB. Get the matching MIB version.
- Symbolic name from a module that is not loaded: load the imported module, such as IF-MIB or SNMPv2-MIB.
Decode a walk in seconds
MIB Decoder takes numeric or symbolic snmpwalk output together with your MIBs. It groups varbinds into tables and decodes every index. Values are shown with their enumeration names and units, and it explains each unknown OID. The same analysis feeds the Zabbix item and template generator.
Related: How to create a Zabbix SNMP template from a MIB · How to create PRTG lookups from a MIB