Juniper Junos: send syslog, sFlow, IPFIX and SNMP traps to MobiObs

Updated 28 September 2026

This guide points a Junos device at a MobiObs collector for syslog, flow data and SNMP traps, using the non-privileged ports a mobile device can listen on, and shows how to confirm and then remove the configuration.

MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.

Before you start

The examples use 10.20.4.9 for the MobiObs device and 192.0.2.1 as an address on the Junos device (usually lo0 or the management interface). MobiObs listens on udp/5514 and tcp/5514 for syslog, udp/2055 for NetFlow and IPFIX, udp/6343 for sFlow and udp/1162 for traps.

The commands are in set format and were written for Junos OS 21.x to 23.x on EX, QFX, MX and SRX. Enter them in configuration mode and use commit confirmed 10 rather than a plain commit: if the change cuts you off, Junos rolls it back after ten minutes. Run commit again once you have checked the result, to make it permanent. If the device reaches MobiObs through the management instance, add routing-instance mgmt_junos where your release supports it for that host.

Syslog

Junos 21.x+: syslog to udp/5514

set system syslog host 10.20.4.9 any info
set system syslog host 10.20.4.9 port 5514
set system syslog host 10.20.4.9 structured-data
set system syslog host 10.20.4.9 source-address 192.0.2.1

structured-data switches the host to RFC 5424 format, which MobiObs parses including structured-data elements. Without it, Junos sends BSD (RFC 3164) messages, which also work. any info sends every facility at informational and above; narrow it with facilities such as authorization, interactive-commands or change-log if the device is busy.

Recent Junos releases also accept set system syslog host 10.20.4.9 transport tcp for TCP delivery to the same port. Support depends on the release, so verify it on yours; UDP is the safe default. On SRX, security (session) logs are configured separately under security log, where the stream host takes its own port option.

sFlow (EX and QFX)

Junos on EX / QFX: sFlow to udp/6343

set protocols sflow collector 10.20.4.9 udp-port 6343
set protocols sflow agent-id 192.0.2.1
set protocols sflow sample-rate ingress 2048
set protocols sflow polling-interval 20
set protocols sflow interfaces ge-0/0/0

MobiObs scales sampled bytes by the sampling rate, so the traffic figures reflect the real volume. Lower sample rates give more detail but more CPU and export traffic; 1 in 1024 to 1 in 4096 is common for access ports. Use the interface names of your platform, for example xe-0/0/10 or et-0/0/48 on QFX.

Inline IPFIX (MX)

MX routers with Trio line cards can export IPFIX from the line card (inline J-Flow). The outline below is for Junos 21.x and later on MX; the FPC slot, instance names and the need for a chassis sampling statement vary by platform, so check the flow-monitoring guide for your hardware. SRX and PTX use different configuration.

Junos on MX (inline J-Flow): IPFIX to udp/2055, verify on your release

set services flow-monitoring version-ipfix template MOBIOBS-V4 ipv4-template
set chassis fpc 0 sampling-instance MOBIOBS-SI
set forwarding-options sampling instance MOBIOBS-SI input rate 1000
set forwarding-options sampling instance MOBIOBS-SI family inet output flow-server 10.20.4.9 port 2055
set forwarding-options sampling instance MOBIOBS-SI family inet output flow-server 10.20.4.9 version-ipfix template MOBIOBS-V4
set forwarding-options sampling instance MOBIOBS-SI family inet output inline-jflow source-address 192.0.2.1
set interfaces ge-0/0/1 unit 0 family inet sampling input

SNMP traps (v2c and v3)

Junos: SNMPv2c traps to udp/1162

set snmp trap-group MOBIOBS-RO version v2
set snmp trap-group MOBIOBS-RO destination-port 1162
set snmp trap-group MOBIOBS-RO categories link
set snmp trap-group MOBIOBS-RO categories authentication
set snmp trap-group MOBIOBS-RO categories chassis
set snmp trap-group MOBIOBS-RO targets 10.20.4.9
set snmp trap-options source-address 192.0.2.1

On Junos the trap-group name is sent as the community string, so enter MOBIOBS-RO as the community in MobiObs. Without categories, all categories are sent.

Junos: SNMPv3 authPriv traps to udp/1162

set snmp v3 usm local-engine user mobiobs authentication-sha authentication-password "AuthPass-change-me"
set snmp v3 usm local-engine user mobiobs privacy-aes128 privacy-password "PrivPass-change-me"
set snmp v3 vacm security-to-group security-model usm security-name mobiobs group MOBIOBS-GRP
set snmp v3 vacm access group MOBIOBS-GRP default-context-prefix security-model usm security-level privacy notify-view MOBIOBS-ALL
set snmp view MOBIOBS-ALL oid .1 include
set snmp v3 target-address MOBIOBS address 10.20.4.9
set snmp v3 target-address MOBIOBS port 1162
set snmp v3 target-address MOBIOBS tag-list mobiobs-tag
set snmp v3 target-address MOBIOBS target-parameters MOBIOBS-TP
set snmp v3 target-parameters MOBIOBS-TP parameters message-processing-model v3
set snmp v3 target-parameters MOBIOBS-TP parameters security-model usm
set snmp v3 target-parameters MOBIOBS-TP parameters security-level privacy
set snmp v3 target-parameters MOBIOBS-TP parameters security-name mobiobs
set snmp v3 notify MOBIOBS-N type trap
set snmp v3 notify MOBIOBS-N tag mobiobs-tag

authentication-sha is SHA-1; releases that offer authentication-sha256 can use it instead, as MobiObs supports SHA-2. Configure the same user, protocols and passwords in MobiObs (SNMPv3 users are a Pro feature). Junos stores the passwords encrypted, so note them before you commit.

Verify on the device

Junos: operational-mode checks

show configuration system syslog
show sflow collector
show sflow interface
show services accounting flow inline-jflow fpc-slot 0
show snmp statistics
request snmp spoof-trap linkDown variable-bindings "ifIndex[500] = 500"

Any commit produces a UI_COMMIT syslog message, which is a quick end-to-end test. show sflow collector shows the number of samples sent, and show snmp statistics counts outgoing traps. request snmp spoof-trap sends a test trap from the device; the index value here is arbitrary. If counters rise but MobiObs shows nothing, work through the troubleshooting checklist.

Remove it afterwards

Junos: clean-up

delete system syslog host 10.20.4.9
delete protocols sflow collector 10.20.4.9
delete snmp trap-group MOBIOBS-RO
delete snmp v3 target-address MOBIOBS
delete snmp v3 target-parameters MOBIOBS-TP
delete snmp v3 notify MOBIOBS-N
delete snmp v3 vacm security-to-group security-model usm security-name mobiobs
delete snmp v3 vacm access group MOBIOBS-GRP
delete snmp v3 usm local-engine user mobiobs
delete snmp view MOBIOBS-ALL
commit

Remove the rest of the sFlow or sampling configuration as well if it was added only for this visit. show | compare rollback 1 before committing confirms that only the MobiObs lines change.