본문 바로가기
WIKI 기술 지식 베이스

NDM 문제 해결 (NDM Troubleshooting)

원문 보기 위키 갱신

Datadog 네트워크 장치 모니터링(NDM) 문제를 해결하는 방법을 안내해요. 장치가 Datadog에 보이지 않거나, SNMP 오류가 발생하거나, 트랩·플로우를 수신하지 못하는 문제를 진단해요.

출처: 문서

본문

개요

아래 정보를 사용해 Datadog 네트워크 장치 모니터링의 문제를 해결해요. 추가 도움이 필요하면 Datadog support에 문의해요.

장치가 Datadog에 보이지 않는 경우

다음은 Datadog Agent v7.61.0+를 실행 중이라고 가정해요.

장치가 Devices 페이지에 보이지 않으면:

  1. datadog-agent status 명령을 실행하고 device의 모니터링 IP가 들어 있는 snmp 섹션을 확인해요. Agent를 시작한 후 개별 구성 장치를 NDM이 발견하는 데 최대 1분이 걸릴 수 있어요. Agent가 많은 수의 장치를 스캔하도록 설정된 경우 더 오래 걸릴 수 있어요. 출력은 대략 다음과 같아야 해요.

    snmp
    ----
      Instance ID: snmp:default:1.2.3.4.1:9a2df638d3ba38d6 [ERROR]
      Configuration Source: file:/etc/datadog-agent/conf.d/snmp.d/conf.yaml
      Total Runs: 1
      Metric Samples: Last Run: 6, Total: 6
      Events: Last Run: 0, Total: 0
      Network Devices Metadata: Last Run: 1, Total: 1
      Service Checks: Last Run: 1, Total: 1
      Average Execution Time : 0s
      Last Execution Date : 2024-11-13 13:12:09 PST / 2024-11-13 21:12:09 UTC (1731532329000)
      Last Successful Execution Date : Never
      Error: <ERROR MESSAGE>
      No traceback
    
  2. 장치가 나열되지 않았고 Autodiscovery를 사용 중이라면, Agent가 장치에 연결할 수 없다는 뜻일 가능성이 커요.

    • datadog-agent status 명령을 실행하고 autodiscovery 섹션이 모든 가능한 장치 IP를 스캔했음을 보고할 때까지 기다려요. 큰 네트워크에서는 몇 분이 걸릴 수 있어요. 출력은 대략 다음과 같아야 해요.
    Autodiscovery
    =============
    Subnet 127.0.0.1/24 is queued for scanning.
    No IPs found in the subnet.
    Scanning subnet 127.0.10.1/30... Currently scanning IP 127.0.10.2, 4 IPs out of 4 scanned.
    Found the following IP(s) in the subnet:
       - 127.0.10.1
       - 127.0.10.2
    Subnet 127.0.10.1/30 scanned.
    No IPs found in the subnet.
    

Autodiscovery가 완료됐는데도 장치가 여전히 Devices 페이지에 나타나지 않으면, Agent가 장치에 연결할 수 없다는 뜻이에요.

  • 장치의 관리 IP에서 snmp walk를 실행해 Agent가 장치에 연결할 수 없는 이유를 확인해요.

참고: 자격 증명을 CLI에 직접 제공해요. 자격 증명을 제공하지 않으면 Agent는 실행 중인 Agent 구성 파일에서 찾으려고 시도해요.

이 명령 실행에 대한 추가 정보는 공급업체별 문서를 참고해요.

Linux 탭

SNMP v2:

sudo -u dd-agent datadog-agent snmp walk <IP Address> -C <COMMUNITY_STRING>

SNMP v3:

sudo -u dd-agent datadog-agent snmp walk <IP Address> -A <AUTH_KEY> -a <AUTH_PROTOCOL> -X <PRIV_KEY> -x <PRIV_PROTOCOL>

Windows 탭

Agent 설치 디렉토리로 이동해요.

cd "c:\Program Files\Datadog\Datadog Agent\bin"

SNMP v2의 경우 실행해요.

"%ProgramFiles%\Datadog\Datadog Agent\bin\agent.exe" snmp walk -v 2 -C <community-string> <IP-Address>:<port>

SNMP v3의 경우 실행해요.

"%ProgramFiles%\Datadog\Datadog Agent\bin\agent.exe" snmp walk -v 3 -u <USER> -a <AUTH-PROTOCOL> -A <AUTH-KEY> -x <PRIV-PROTOCOL> -X <PRIV-KEY> <IP-Address>:<port>

참고: 다음 오류를 피하려면 Agent 설치 디렉토리에서 관리자로 명령을 실행해요.

Error: unable to read artifact: open C:\ProgramData\Datadog\auth_token: Access is denied.

SNMP 오류 문제 해결

SNMP 상태나 Agent walk에서 오류가 표시되면 다음 문제 중 하나를 나타낼 수 있어요.

권한 거부

에이전트 로그에서 포트 바인딩 중 권한 거부 오류가 발생하면, 지정한 포트 번호가 상승된 권한을 요구할 수 있어요. 1024 미만의 포트 번호에 바인딩하려면 Using the default SNMP Trap port 162를 참고해요.

도달 불가 또는 잘못 구성된 장치

오류:

Error: check device reachable: failed: error reading from socket: read udp 127.0.0.1:46068->1.2.3.4:161

해결 방법:

  1. 장치에 로그인해 SNMP가 활성화되고 포트 161에 노출되었는지 확인해요.

  2. 수집기 방화벽이 이그레스(egress)를 허용하는지 확인해요.

  3. 선택적으로, Linux 전용: iptables -L OUTPUT를 실행하고 deny 규칙이 없는지 확인해요.

    vagrant@agent-dev-ubuntu-22:~$ sudo iptables -L OUTPUT
    Chain OUTPUT (policy ACCEPT)
    target     prot opt source               destination
    DROP       all  --  anywhere             10.4.5.6
    
  4. 커뮤니티 문자열이 일치하는지 확인해요.

잘못된 SNMPv2 자격 증명

오류:

Error: an authentication method needs to be provided

해결 방법: SNMPv2를 사용 중이면 커뮤니티 문자열이 설정되어 있는지 확인해요.

잘못된 SNMPv3 개인 정보 보호 프로토콜

오류:

Error: check device reachable: failed: decryption error; failed to autodetect profile: failed to fetch sysobjectid: cannot get sysobjectid: decryption error; failed to fetch values: failed to fetch scalar oids with batching: failed to fetch scalar oids: fetch scalar: error getting oids `[1.3.6.1.2.1.1.1.0 1.3.6.1.2.1.1.2.0 1.3.6.1.2.1.1.3.0 1.3.6.1.2.1.1.5.0]`: decryption error

또는

Error: check device reachable: failed: wrong digest; failed to autodetect profile: failed to fetch sysobjectid: cannot get sysobjectid: wrong digest; failed to fetch values: failed to fetch scalar oids with batching: failed to fetch scalar oids: fetch scalar: error getting oids `[1.3.6.1.2.1.1.1.0 1.3.6.1.2.1.1.2.0 1.3.6.1.2.1.1.3.0 1.3.6.1.2.1.1.5.0]`: wrong digest

해결 방법: 다음 SNMPv3 구성 매개변수가 올바른지 확인해요.

  • user
  • authKey
  • authProtocol
  • privKey
  • privProtocol

트랩 또는 플로우가 전혀 수신되지 않는 경우

SNMP 트랩이나 NetFlow 트래픽이 누락된 경우, 흔한 원인은 UDP 패킷이 Agent에 도달하기 전에 차단하는 방화벽 규칙이에요. SNMP 트랩과 NetFlow 모두 UDP에 의존하며 datadog.yaml 구성에 정의된 포트를 사용해요.

Uncomplicated Firewall(UFW) 같은 로컬 방화벽은 허용적인 설정으로 구성돼도 트래픽을 차단할 수 있어요. 시스템 로그에서 차단된 패킷 항목을 확인해 보세요. 이는 트래픽이 네트워크 인터페이스에 도달했지만 운영 체제에 도달하기 전에 차단됐다는 것을 나타내는 경우가 많아요.

다음 플랫폼별 명령을 사용해 Agent에 도달하는 트래픽을 차단할 수 있는 방화벽 규칙을 확인해요.

Linux 탭: Linux에는 iptables, nftables, ufw 같은 여러 유형의 방화벽이 있어요. 사용 중인 것에 따라 다음 명령을 사용할 수 있어요.

  • sudo iptables -S
  • sudo nft list ruleset
  • sudo ufw status

구성된 포트에서 UDP 트래픽을 차단하는 규칙을 확인해요.

Windows 탭: 버전 7.67부터 Agent의 agent.exe diagnose 명령이 차단 방화벽 규칙을 자동으로 확인하고 발견되면 경고를 표시해요.

방화벽 규칙을 수동으로 검사하려면:

Get-NetFirewallRule -Action Block | ForEach-Object {
    $rule = $_
    Get-NetFirewallPortFilter -AssociatedNetFirewallRule $rule | Select-Object
        @{Name="Name"; Expression={$rule.Name}},
        @{Name="DisplayName"; Expression={'"' + $rule.DisplayName + '"'}},
        @{Name="Direction"; Expression={$rule.Direction}},
        @{Name="Protocol"; Expression={$_.Protocol}},
        @{Name="LocalPort"; Expression={$_.LocalPort}},
        @{Name="RemotePort"; Expression={$_.RemotePort}}
} | Format-Table -AutoSize

다음 규칙을 찾아요:

  • Direction이 인바운드(inbound)
  • Protocol이 UDP
  • LocalPort가 구성된 포트 중 하나와 일치

MacOS 탭: Packet Filter(pf) 규칙을 검토하려면 다음 명령을 실행해요.

sudo pfctl -sr

구성된 포트에서 UDP 트래픽을 차단하는 규칙이 있는지 확인해요. 예:block drop in proto udp from any to any port = <CONFIG_PORT>.

장치에 대한 트랩이 수신되지 않는 경우

  1. Datadog agent.log 파일을 확인해 트랩 포트에 바인딩할 수 있는지 확인해요. 다음 오류는 트랩 포트에 바인딩할 수 없다는 것을 나타내요.

    Failed to start snmp-traps server: error happened when listening for SNMP Traps: listen udp 0.0.0.0:162: bind: permission denied
    

해결 방법: Agent 바이너리에 net bind 기능을 추가해 예약 포트에 바인딩할 수 있게 해요.

sudo setcap 'cap_net_bind_service=+ep' /opt/datadog-agent/bin/agent/agent

트랩 형식 오류

  1. NDM의 문제 해결 대시보드로 이동해요.

  2. Traps 위젯까지 아래로 스크롤해 Traps incorrectly formatted 그래프를 확인해요. 이 값이 0이 아니면 NDM 수집기와 장치의 인증이 일치하지 않는다는 뜻일 가능성이 커요.

해결 방법: datadog.yaml 파일의 다음 구성이 트랩이 누락된 장치의 트랩 설정과 일치하는지 확인해요.

 ## @param community_strings - list of strings - required
 ## A list of known SNMP community strings that devices can use to send traps to the Agent.
 ## Traps with an unknown community string are ignored.
 ## Enclose the community string with single quote like below (to avoid special characters being interpreted).
 ## Must be non-empty.
 #
 # community_strings:
 #   - '<COMMUNITY_1>'
 #   - '<COMMUNITY_2>'

 ## @param users - list of custom objects - optional
 ## List of SNMPv3 users that can be used to listen for traps.
 ## Each user can contain:
 ##  * user         - string - The username used by devices when sending Traps to the Agent.
 ##  * authKey      - string - (Optional) The passphrase to use with the given user and authProtocol
 ##  * authProtocol - string - (Optional) The authentication protocol to use when listening for traps from this user.
 ##                            Available options are: MD5, SHA, SHA224, SHA256, SHA384, SHA512.
 ##                            Defaults to MD5 when authKey is set.
 ##  * privKey      - string - (Optional) The passphrase to use with the given user privacy protocol.
 ##  * privProtocol - string - (Optional) The privacy protocol to use when listening for traps from this user.
 ##                            Available options are: DES, AES (128 bits), AES192, AES192C, AES256, AES256C.
 ##                            Defaults to DES when privKey is set.
 #
 # users:
 # - user: <USERNAME>
 #   authKey: <AUTHENTICATION_KEY>
 #   authProtocol: <AUTHENTICATION_PROTOCOL>
 #   privKey: <PRIVACY_KEY>
 #   privProtocol: <PRIVACY_PROTOCOL>

더 알아보기 (Learn more)