We are seeing a lot of SNMP login errors on some of our HP Synergy blades. The weird thing is that these nodes are not monitored or added to our Solarwinds environment.
When I look at the firewall, I can see the SNMP traffic generated from my primary poller to a few nodes but they are not added or managed in Solarwinds NPM. I use SAM, NPM 2023.3.1
How can identify how, where or why this traffic is being generated from my polling server?
I started digging some more and notice that even Nodes are managed and use WMI or ICMP only polling, still show SNMP traffic from my primary poller. Why would that be when the node is added and configured to use ICMP only traffic but still see the SNMP traffic? Even stranger to me was that this specific node set to ICMP polling, is actually being polled via a different poller. When I checked the traffic from this other poller, I saw only the ICMP traffic we expect. When I check it against my primary poller (which is not set as the polling engine for this node), I see SNMP traffic again amongst other.
Any ideas?
I don't typically use SNMP polling, mostly WMI for Windows or ICMP for Linux nodes.