<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk ingestion from queues in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451211#M55475</link>
    <description>&lt;P&gt;Yes. This is very clearly and thoroughly described in :  &lt;A href="https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html"&gt;https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html&lt;/A&gt; , have you tried reading the blog and trying it out  for yourself yet ?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Aug 2018 21:07:40 GMT</pubDate>
    <dc:creator>Damien_Dallimor</dc:creator>
    <dc:date>2018-08-29T21:07:40Z</dc:date>
    <item>
      <title>splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451203#M55467</link>
      <description>&lt;P&gt;I am using Splunk heavy forwarder to read data from the MQ/Solace queues. For this I am using app "Splunk JMS modular input". &lt;/P&gt;

&lt;P&gt;But when the data read from queues is indexed, It is converting the new lines in the message to series of white spaces. i.e. it is simply converting multi line event to single line event. May I know how to handle this scenario without parsing the events further.&lt;/P&gt;

&lt;P&gt;Ex: &lt;BR /&gt;
&lt;STRONG&gt;Actual event:&lt;/STRONG&gt;&lt;BR /&gt;
how are you&lt;BR /&gt;
hi&lt;BR /&gt;
good to know&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Indexed event:&lt;/STRONG&gt;&lt;BR /&gt;
how are you       hi       good to know&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 19:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451203#M55467</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-07-18T19:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451204#M55468</link>
      <description>&lt;P&gt;Have you tried unchecking that default option.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5397iFF801665AEDA6A15/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 00:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451204#M55468</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2018-07-19T00:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451205#M55469</link>
      <description>&lt;P&gt;Hi Damien, &lt;BR /&gt;
Thank you for the response. Is it possible to remove the header for every message which is added by splunk JMS when read the message from queue.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Example.&lt;/STRONG&gt;&lt;BR /&gt;
Thu Jul 19 13:10:13 CDT 2018 name=QUEUE_msg_received event_id=ID:xxxxx msg_dest=xxx msg_body=&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451205#M55469</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2020-09-29T20:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451206#M55470</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/671924/get-only-the-message-body-from-jms-messaging-modul.html"&gt;https://answers.splunk.com/answers/671924/get-only-the-message-body-from-jms-messaging-modul.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 20:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451206#M55470</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2018-07-19T20:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451207#M55471</link>
      <description>&lt;P&gt;thank you &lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 20:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451207#M55471</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-07-19T20:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451208#M55472</link>
      <description>&lt;P&gt;@Damien Dallimore , Splunk JMS app UI is basically showing to enter connection details for connecting solace queues. In case if I have to connect to MQ queue(where wee have host, serverchannel etc), May I know how to enter the values on UI. I tried to enter key value pairs in JNDI properties input box, but it is not working.&lt;/P&gt;

&lt;P&gt;It would be a great help.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 14:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451208#M55472</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-08-28T14:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451209#M55473</link>
      <description>&lt;P&gt;No , the JMS configuration page provides fields for connecting to &lt;STRONG&gt;ANY&lt;/STRONG&gt; JMS provider. It is not specific to any particular JMS provider (such as Solace).&lt;/P&gt;

&lt;P&gt;Maybe this blog will help you : &lt;A href="https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html"&gt;https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 01:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451209#M55473</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2018-08-29T01:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451210#M55474</link>
      <description>&lt;P&gt;Hi @Damien Dallimore ,  Instead of using bindings file for MQ setup,&lt;/P&gt;

&lt;P&gt;Can we provide property values like host name, serverchannel, queuemanager to connect to queue via JMS UI.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 19:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451210#M55474</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-08-29T19:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451211#M55475</link>
      <description>&lt;P&gt;Yes. This is very clearly and thoroughly described in :  &lt;A href="https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html"&gt;https://www.splunk.com/blog/2013/04/11/splunking-websphere-mq-queues-and-topics.html&lt;/A&gt; , have you tried reading the blog and trying it out  for yourself yet ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 21:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451211#M55475</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2018-08-29T21:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451212#M55476</link>
      <description>&lt;P&gt;Hi Damien, the blog explains to create a binding file to connect to MQ. But it does not explain , how to connect without the binding file. Sorry, If I am missing something from the blog that I need to consider. Basically I dont have binding file and looking for options to create connection without bindings file&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 21:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451212#M55476</guid>
      <dc:creator>ankith_nt</dc:creator>
      <dc:date>2018-08-29T21:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ingestion from queues</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451213#M55477</link>
      <description>&lt;P&gt;The JMS App requires that the JMS objects are registered in a JNDI namespace (ldap, file etc..)  and looked up by way of your configuration, rather than by building the JMS objects locally by way of setting properties at runtime.&lt;/P&gt;

&lt;P&gt;This is because the JMS App does not use provider specific classes (such as MQ classes) , the code is asbstracted at the JMS interface level which allows the app to work with any JMS Provider.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 01:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/splunk-ingestion-from-queues/m-p/451213#M55477</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2018-08-30T01:49:28Z</dc:date>
    </item>
  </channel>
</rss>

