SNMP Targets
Engineer or admin CRUD for SNMP polling targets. Each target associates a device with SNMP credentials and polling configuration for traffic monitoring.
Create SNMP Target
POST /api/v1/snmp-targets
Request body:
{
"device_id": "uuid",
"hostname": "10.0.0.1",
"port": 161,
"version": "2c",
"community": "public",
"v3_config": null,
"poll_interval_seconds": 30,
"enabled": true
}
Validation:
device_id and hostname are required
port defaults to 161 if omitted
version defaults to "v2c" if omitted. Canonical values: "v1", "v2c", "v3"; the bare spellings "1"/"2c"/"3" are accepted and normalized. Anything else is a 400.
community is required for version "1" and "2c"
v3_config is required for version "v3", with a non-empty user — enforced with a 400. Canonical keys: user, auth_proto, auth_pass, priv_proto, priv_pass, context_name; the alternative spellings (username, auth_protocol, auth_password, priv_protocol, priv_password) are accepted as aliases. security_level is accepted and ignored: the message flags are derived from which credentials are present (auth+priv → authPriv, auth only → authNoPriv, neither → noAuthNoPriv). auth_proto must be MD5 or SHA/SHA-224/SHA-256/SHA-384/SHA-512 and priv_proto DES or AES/AES-192/AES-256/AES-192C/AES-256C (the supported vocabulary); unknown values are a 400.
poll_interval_seconds defaults to 30 if omitted
enabled defaults to true if omitted
Response: 201 Created
{
"id": "uuid",
"device_id": "uuid",
"router_id": "10.0.0.1",
"hostname": "10.0.0.1",
"port": 161,
"version": "2c",
"community": "public",
"v3_config": null,
"poll_interval_seconds": 30,
"enabled": true,
"created_at": "2026-02-18T12:00:00Z",
"updated_at": "2026-02-18T12:00:00Z"
}
Error responses:
400 Bad Request -- Missing required fields or invalid request body
403 Forbidden -- Non-admin user
List SNMP Targets
GET /api/v1/snmp-targets?limit=100&offset=0
List all SNMP targets. The router_id field is joined from the associated device. Supports pagination.
Query parameters:
limit (optional) — Max items to return (default 100, max 1000)
offset (optional) — Items to skip (default 0)
Response: 200 OK — Paginated envelope
{
"data": [
{
"id": "uuid",
"device_id": "uuid",
"router_id": "10.0.0.1",
"hostname": "10.0.0.1",
"port": 161,
"version": "2c",
"community": "***",
"v3_config": null,
"poll_interval_seconds": 30,
"enabled": true,
"created_at": "2026-02-18T12:00:00Z",
"updated_at": "2026-02-18T12:00:00Z"
}
],
"total": 1,
"limit": 100,
"offset": 0
}
Notes:
router_id is the OSPF router ID from the associated device, joined at query time.
- Credential masking:
community, v3_config.auth_pass, and v3_config.priv_pass are always returned as "***" in API responses. On update, sending "***" preserves the existing value; send a new string to change it. Backup exports also redact credentials.
- These endpoints require the engineer or admin role; the
operator role receives 403. Credential masking applies to every role, including admins.
v3_config is null for non-v3 targets.
List Devices Without SNMP Coverage
GET /api/v1/snmp-targets/uncovered
Return the set of discovered devices that do not yet have an SNMP target configured. Used by the SNMP settings UI to surface candidates for bulk enrollment. Engineer or admin role required.
Response: 200 OK
{
"devices": [
{
"device_id": "uuid",
"router_id": "10.0.0.5",
"hostname": "",
"management_ip": "10.0.0.5",
"area_id": "uuid"
}
],
"total": 1
}
Notes:
- Uncovered = device row exists in topology (
device table) but no row in snmp_target references it.
- Companion endpoint to
POST /api/v1/snmp-targets/auto-discover, which enrolls candidates in bulk.
Error responses:
401 Unauthorized — Missing or invalid access token
403 Forbidden — Role below engineer
500 Internal Server Error — Database error
Get SNMP Target
GET /api/v1/snmp-targets/{targetID}
Get a single SNMP target by ID.
Path parameters:
targetID (required) -- UUID of the SNMP target
Response: 200 OK (single SNMP target object)
Error responses:
403 Forbidden -- Non-admin user
404 Not Found -- SNMP target does not exist
Update SNMP Target
PUT /api/v1/snmp-targets/{targetID}
Partial update of an SNMP target. Uses read-merge-write -- only fields present in the request body are updated; other fields are preserved. The device_id cannot be changed after creation.
Path parameters:
targetID (required) -- UUID of the SNMP target
Request body (all fields optional):
{
"hostname": "10.0.0.2",
"port": 1161,
"version": "3",
"community": null,
"v3_config": {
"username": "snmpuser",
"auth_protocol": "SHA",
"auth_password": "authpass123",
"priv_protocol": "AES",
"priv_password": "privpass123",
"security_level": "authPriv"
},
"poll_interval_seconds": 60,
"enabled": false
}
Response: 200 OK (updated SNMP target object)
Error responses:
400 Bad Request -- Invalid request body
403 Forbidden -- Non-admin user
404 Not Found -- SNMP target does not exist
Toggle SNMP Target
POST /api/v1/snmp-targets/{targetID}/toggle
Flips the enabled flag on an SNMP target without modifying any other fields. This is the preferred method for enabling/disabling targets, as it preserves credential profiles and inline credentials (unlike a partial update which may overwrite fields with zero values).
Path parameters:
targetID (required) -- UUID of the SNMP target
Request body: Empty JSON object {}
Response: 200 OK (updated SNMP target object with toggled enabled field)
Audit: Logs toggle action on snmp_target entity with {"enabled": <new_value>}.
Error responses:
403 Forbidden -- Non-admin user
404 Not Found -- SNMP target does not exist
Delete SNMP Target
DELETE /api/v1/snmp-targets/{targetID}
Delete an SNMP target. The SNMP poller stops polling the target immediately.
Path parameters:
targetID (required) -- UUID of the SNMP target
Response: 204 No Content
Error responses:
403 Forbidden -- Non-admin user
404 Not Found -- SNMP target does not exist
Auto-Discover SNMP Targets
POST /api/v1/snmp-targets/auto-discover
Automatically create SNMP targets for all devices that do not already have one. Devices with the is_collector flag set are skipped.
Request body:
{
"credential_profile_id": "uuid-of-profile",
"community": "public"
}
All fields are optional. Resolution order:
credential_profile_id from request body
snmp.default_credential_profile_id system setting
community from request body
snmp.default_community system setting
- Fallback:
"public"
When a credential profile is used, targets are created with the profile's version (v2c or v3) and linked via credential_profile_id. When using inline community, targets are created as v2c with the community string.
Response: 200 OK
{
"created": 12
}
Notes:
- The
created field indicates the number of new SNMP targets created.
- Each auto-created target uses the device's
router_id as the hostname, port 161, the resolved credentials, a default poll interval from snmp.default_poll_interval_seconds (default: 300s), and enabled: true.
- Devices that already have an SNMP target are silently skipped.
Error responses:
400 Bad Request -- Invalid credential profile ID
403 Forbidden -- Non-admin user