<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172258#M16533</link>
    <description>&lt;P&gt;Hello David - Were you able to find a solution to this? We see the exact problem you described. &lt;BR /&gt;
I don't have any other SQS queue or SNS topic besides the one for CloudTrail. &lt;/P&gt;</description>
    <pubDate>Fri, 13 Feb 2015 14:27:17 GMT</pubDate>
    <dc:creator>kkossery</dc:creator>
    <dc:date>2015-02-13T14:27:17Z</dc:date>
    <item>
      <title>Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172254#M16529</link>
      <description>&lt;P&gt;Hi All, Would appreciate some suggestions to a solution. Thanks!&lt;/P&gt;

&lt;P&gt;I am unable to collect any data from AWS SQS. Brand new AWS Linux OS(yum update) with Splunk Enterprise 6.2.1 and Add-on(Version 1.0.1) and App(Version 3.0) for AWS installed. splunk user in IAM has full permissions to SQS and S3. SQS subscribed to SNS topic and is showing messages in the queue. In addition, there is a index that was manually created called aws-cloudtrail for which is required by SplunkAppforAWS.&lt;/P&gt;

&lt;P&gt;**This is the output of my log file aws_cloudtrail.log&lt;/P&gt;

&lt;P&gt;2015-01-03 10:09:28,865 INFO pid=30098 tid=MainThread file=aws_cloudtrail.py::413 | STARTED: &lt;BR /&gt;
2015-01-03 10:09:28,865 DEBUG pid=30098 tid=MainThread file=aws_cloudtrail.py:stream_events:174 | Start streaming.&lt;BR /&gt;
2015-01-03 10:09:28,865 DEBUG pid=30098 tid=MainThread file=aws_cloudtrail.py:stream_events:192 | blacklist regex for eventNames is None&lt;BR /&gt;
2015-01-03 10:09:28,866 INFO pid=30098 tid=MainThread file=aws_cloudtrail.py:get_access_key_pwd_real:105 | get account name: splunk&lt;BR /&gt;
2015-01-03 10:09:28,887 DEBUG pid=30098 tid=MainThread file=aws_cloudtrail.py:stream_events:206 | Connect to S3 &amp;amp; Sqs sucessfully&lt;BR /&gt;
2015-01-03 10:09:28,981 CRITICAL pid=30098 tid=MainThread file=aws_cloudtrail.py:stream_events:282 | Outer catchall: ParseError: no element found: line 1, column 0&lt;BR /&gt;
2015-01-03 10:09:28,982 INFO pid=30098 tid=MainThread file=aws_cloudtrail.py::415 | EXITED: 1&lt;/P&gt;

&lt;P&gt;**I'm also seeing messages like this in the splunkd.log.&lt;BR /&gt;
01-03-2015 09:17:11.556 +0000 WARN  SearchOperator:inputcsv - Encountered 1 'inconsistent number of column' errors while reading input.&lt;BR /&gt;
01-03-2015 09:18:28.428 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_cloudtrail.py" ERRORno element found: line 1, column 0&lt;/P&gt;

&lt;P&gt;Any clues why?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:33:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172254#M16529</guid>
      <dc:creator>david_emind</dc:creator>
      <dc:date>2020-09-28T18:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172255#M16530</link>
      <description>&lt;P&gt;That usually indicates that it's pulling a message from SQS that isn't from CloudTrail. As of the latest 1.0.x it should write the message to a log and delete it, but if it doesn't have permission to delete it might get stuck on the same message.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2015 15:54:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172255#M16530</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-01-03T15:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172256#M16531</link>
      <description>&lt;P&gt;This is a fresh install and I didn't expect this to happen. What do you think the solution could be? I can try it out and get back to you.&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2015 18:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172256#M16531</guid>
      <dc:creator>david_emind</dc:creator>
      <dc:date>2015-01-03T18:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172257#M16532</link>
      <description>&lt;P&gt;Can you try deleting the SQS message which isn't from CloudTrail?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jan 2015 19:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172257#M16532</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-01-04T19:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172258#M16533</link>
      <description>&lt;P&gt;Hello David - Were you able to find a solution to this? We see the exact problem you described. &lt;BR /&gt;
I don't have any other SQS queue or SNS topic besides the one for CloudTrail. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 14:27:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172258#M16533</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-02-13T14:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172259#M16534</link>
      <description>&lt;P&gt;with the current 1.1.0 version of the Add-on, it should log that it's seeing messages that aren't CloudTrail format and delete them from the queue so that it can proceed with the CloudTrail data.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2015 00:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172259#M16534</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-29T00:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to collect data from AWS SQS with Splunk Add-On for AWS</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172260#M16535</link>
      <description>&lt;P&gt;Thanks! We were able to make it work earlier. &lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2015 17:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-collect-data-from-AWS-SQS-with-Splunk-Add-On-for-AWS/m-p/172260#M16535</guid>
      <dc:creator>kkossery</dc:creator>
      <dc:date>2015-03-29T17:54:51Z</dc:date>
    </item>
  </channel>
</rss>

