Free SNMP OID lookup: search 359 verified OIDs by number or name, then build snmpwalk, snmpget and snmpbulkwalk commands for v1, v2c and v3.
Paste a numeric OID such as 1.3.6.1.2.1.31.1.1.1.6.3 and this tool names it (IF-MIB::ifHCInOctets, interface index 3), shows its type, units, access and enum values, and builds the snmpwalk, snmpget, snmpbulkwalk and snmptable commands to query it with SNMP v1, v2c or v3. It works the other way too: search by name (ifHCInOctets, IF-MIB::ifName) or by words (cisco cpu, ups battery, lldp neighbour).
The database is a curated set of the OIDs network admins actually poll: MIB-2 system and interfaces, IF-MIB ifXTable 64-bit counters, IP-MIB, HOST-RESOURCES-MIB, ENTITY-MIB, BRIDGE-MIB and Q-BRIDGE-MIB MAC and VLAN tables, LLDP-MIB and CISCO-CDP-MIB neighbour tables, PoE, the SNMPv3 USM error counters, and vendor OIDs for Cisco, Juniper, HPE Aruba, Fortinet, Palo Alto Networks, MikroTik, Ubiquiti UniFi, APC and RFC 1628 UPSs, and printers. Every numeric OID was resolved from the published MIB files with net-snmp’s snmptranslate, not typed by hand. Everything runs in your browser; community strings and passphrases are never stored or added to the shareable link.
snmpwalk -v2c -c public 192.0.2.10 1.3.6.1.2.1.1
snmpget -v2c -c public 192.0.2.10 1.3.6.1.2.1.1.3.0
snmpbulkwalk -v2c -c public -Cr25 192.0.2.10 1.3.6.1.2.1.31.1.1
Walk the system group first: it proves SNMP works and tells you the device model (sysDescr) and vendor (sysObjectID). snmpget reads one value, so scalars need their .0 instance (sysUpTime.0). snmpbulkwalk uses GETBULK to fetch many rows per request, which is much faster on big tables; -Cr sets max-repetitions (default 10).
snmpwalk -v3 -l authPriv -u monitor -a SHA -A 'auth-passphrase' -x AES -X 'priv-passphrase' 192.0.2.10 1.3.6.1.2.1.1
-l sets the security level (noAuthNoPriv, authNoPriv or authPriv), -a/-A the authentication protocol and passphrase, and -x/-X the privacy protocol and passphrase. net-snmp 5.8 and later accept SHA-224, SHA-256, SHA-384 and SHA-512; AES-192 and AES-256 also need a build with --enable-blumenthal-aes, and Cisco devices usually need the AES-256-C variant because Cisco localises the longer keys differently. macOS still ships net-snmp 5.6.2.1, which only knows MD5/SHA and DES/AES.
snmpwalk -v2c -c public HOST 1.3.6.1.4.1.9.9.109.1.1.1.1.8 (cpmCPUTotal5minRev, one row per CPU or stack member).1.3.6.1.4.1.9.9.48.1.1.1.5 and .6 (ciscoMemoryPoolUsed and Free), or 1.3.6.1.4.1.9.9.221.1.1.1.1.18 and .20 (cempMemPoolHCUsed and HCFree) where the older table is empty.-c public@10; with v3 use the context, -n vlan-10. List the VLANs first with vtpVlanName (1.3.6.1.4.1.9.9.46.1.3.1.1.4).1.3.6.1.4.1.2636.3.1.13.1.8 (jnxOperatingCPU) and 1.3.6.1.4.1.2636.3.1.13.1.7 (jnxOperatingTemp), read alongside jnxOperatingDescr to see which row is the Routing Engine.1.3.6.1.4.1.12356.101.4.1.3 (fgSysCpuUsage), .4 (fgSysMemUsage) and .8 (fgSysSesCount, active sessions).1.3.6.1.4.1.25461.2.1.2.3.3 (panSessionActive) and 1.3.6.1.4.1.25461.2.1.2.1.11 (panSysHAState).hrProcessorLoad (1.3.6.1.2.1.25.3.3.1.2); temperature is 1.3.6.1.4.1.14988.1.1.3.10.0 in tenths of a degree.1.3.6.1.4.1.318.1.1.1.2.2.1.0 (battery capacity %), 1.3.6.1.4.1.318.1.1.1.2.2.3.0 (runtime remaining) and 1.3.6.1.4.1.318.1.1.1.4.1.1.0 (on line or on battery).1.3.6.1.4.1.2021.10.1.3 (load averages) and 1.3.6.1.4.1.2021.4 (memory); disks via hrStorageTable (1.3.6.1.2.1.25.2.3).1.3.6.1.2.1.43.10.2.1.4 (prtMarkerLifeCount, the page counter) and 1.3.6.1.2.1.43.11.1.1.9 (prtMarkerSuppliesLevel, toner).ifInOctets and ifOutOctets are 32-bit and wrap in about 34 seconds at 1 Gbit/s, which produces negative or wildly wrong graphs. Poll ifHCInOctets (1.3.6.1.2.1.31.1.1.1.6) and ifHCOutOctets (1.3.6.1.2.1.31.1.1.1.10) instead; bits per second is the counter delta × 8 ÷ seconds. Counter64 values cannot be carried by SNMPv1, so use v2c or v3. Use ifHighSpeed (Mbit/s) rather than ifSpeed on links faster than 4 Gbit/s, and ifName plus ifAlias to label the graph.
v2c authenticates with a community string sent in clear text and has no encryption; anyone who can capture the traffic can read the community. v3 adds per-user authentication (HMAC-MD5 or SHA) and encryption (DES or AES) and is what most security baselines require. v2c and v3 both support GETBULK and 64-bit counters; v1 supports neither. A wrong v1/v2c community produces no error at all, just a timeout, while v3 returns specific errors that tell you which part is wrong.
The agent sent nothing back. A wrong community string, wrong SNMP version, blocked UDP port 161, a device ACL that does not include your IP, or an agent that is not running all look identical, because agents silently drop requests with a bad community. Check the community and version first, then the path. On the device, a rising snmpInBadCommunityNames counter (1.3.6.1.2.1.11.4) confirms a community mismatch.
The SNMPv3 user does not exist on the agent. User names are case-sensitive; on Cisco check show snmp user. If the device’s engine ID changed after the user was created, the localised keys are invalid and the user must be recreated.
The v3 user exists but the auth passphrase or the auth protocol (-a) does not match. net-snmp also rejects passphrases shorter than 8 characters.
Authentication succeeded but the privacy passphrase or protocol (-x) is wrong. For AES-192/256 on Cisco, try AES-256-C.
The credentials are valid but the view assigned to that community or v3 group does not include the OID. Widen the view (on Cisco, snmp-server view NAME iso included attached to the group).
The agent does not implement the object, usually because the model or firmware does not support that MIB. Walk the parent subtree to see what is there. No Such Instance currently exists at this OID means the object exists but not at that index, most often a scalar queried without .0. In SNMPv1 both cases appear as (noSuchName).
CDP is Cisco’s proprietary discovery protocol; LLDP (IEEE 802.1AB) is the vendor-neutral standard that Juniper, Aruba, MikroTik, Ubiquiti and Cisco all support. Both publish a neighbour table over SNMP, and walking it is the fastest way to see what is plugged into which port.
lldpRemSysName, 1.0.8802.1.1.2.1.4.1.1.9. The neighbour’s port is lldpRemPortId (.7) and description lldpRemPortDesc (.8). Note that the LLDP MIB lives under 1.0.8802, so a walk of 1.3.6.1 never reaches it.cdpCacheDeviceId, 1.3.6.1.4.1.9.9.23.1.2.1.1.6. The remote port is cdpCacheDevicePort (.7), the platform cdpCachePlatform (.8) and the management address cdpCacheAddress (.4, shown as hex bytes).ifIndex. LLDP rows are indexed by lldpLocPortNum, which is not always the ifIndex; resolve it through lldpLocPortId or lldpLocPortDesc.Paste a sysObjectID value into the lookup and it is matched to the vendor’s enterprise subtree: 1.3.6.1.4.1.9 is Cisco, .11 HP, .2636 Juniper, .12356 Fortinet, .25461 Palo Alto Networks, .14988 MikroTik, .41112 Ubiquiti, .318 APC and .14823 Aruba.
Windows has no built-in snmpwalk. The simplest route is WSL: sudo apt install snmp, then run the same commands. For a single SNMPv1 GET without installing anything, PowerShell can use the built-in OlePrn.OleSNMP COM object, which the builder generates for you.
Paste the numeric OID into the lookup. It matches exact OIDs, OIDs with an index on the end (1.3.6.1.2.1.31.1.1.1.6.3 is ifHCInOctets for interface 3) and vendor sysObjectID values, and shows the MIB, type, units and description. With net-snmp installed and the MIB loaded you can also run snmptranslate -Td OID.
snmpwalk -v3 -l authPriv -u USER -a SHA -A 'AUTH-PASSPHRASE' -x AES -X 'PRIV-PASSPHRASE' HOST OID. Use -l authNoPriv and drop -x/-X if the user has no privacy password. The builder generates the exact command for your protocols.
The agent sent nothing back. A wrong community string or SNMP version, a firewall blocking UDP 161, a device ACL that excludes your IP or a stopped agent all look the same, because agents silently drop requests with a bad community. Check community and version first.
snmpwalk issues one GETNEXT request per value. snmpbulkwalk uses GETBULK to fetch many values per request (10 by default, set with -Cr), so it is much faster on large tables. GETBULK needs SNMP v2c or v3.
The object exists but not at that index. Scalars such as sysUpTime need a .0 suffix (sysUpTime.0), and table columns need a real row index; walk the column first to see the indexes.
Use the 64-bit ifHCInOctets (1.3.6.1.2.1.31.1.1.1.6) and ifHCOutOctets (1.3.6.1.2.1.31.1.1.1.10). The 32-bit ifInOctets wraps in about 34 seconds at 1 Gbit/s. Bits per second is the counter delta times 8 divided by the interval. 64-bit counters need SNMP v2c or v3.
LLDP neighbour hostnames are lldpRemSysName, 1.0.8802.1.1.2.1.4.1.1.9 (note the 1.0.8802 root). CDP neighbour hostnames are cdpCacheDeviceId, 1.3.6.1.4.1.9.9.23.1.2.1.1.6, with the remote port in cdpCacheDevicePort (.7).
Walk cpmCPUTotal5minRev, 1.3.6.1.4.1.9.9.109.1.1.1.1.8, for the 5-minute CPU average (1minRev is .7). There is one row per CPU or stack member; cpmCPUTotalPhysicalIndex (.2) tells you which.
Your net-snmp build is too old or was built without the option. SHA-2 needs net-snmp 5.8 or newer, and AES-192/256 also need --enable-blumenthal-aes. macOS ships net-snmp 5.6.2.1, which only supports MD5/SHA and DES/AES. On Cisco, use AES-256-C.
Windows does not include one. Install the net-snmp tools under WSL (sudo apt install snmp) and use the same commands. For a single SNMPv1 GET, PowerShell can use the built-in OlePrn.OleSNMP COM object, which the builder generates.