<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS SQS Input -  Unable to parse message in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/557045#M65952</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp; Was anyone able to figure this out?&amp;nbsp; I'm encountering the same issue with all my SQS-based S3 inputs.&amp;nbsp; Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jun 2021 22:05:17 GMT</pubDate>
    <dc:creator>jmatthews</dc:creator>
    <dc:date>2021-06-24T22:05:17Z</dc:date>
    <item>
      <title>AWS SQS Input -  Unable to parse message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/537660#M64740</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have set some SQS inputs on Splunk Add-on for AWS, but the following error is occurring:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-01-28 13:25:08,541 level=CRITICAL pid=3271 tid=Thread-2 logger=splunk_ta_aws.modinputs.sqs_based_s3.handler pos=handler.py:_process:268 | datainput="SQS_INPUT" start_time=1611850827, created=1611851108.54 message_id="MESSAGE_ID" ttl=600 job_id=JOB_ID | message="An error occurred while processing the message." 
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunk_ta_aws/modinputs/sqs_based_s3/handler.py", line 247, in _process
    records = self._parse(message)
  File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunk_ta_aws/modinputs/sqs_based_s3/handler.py", line 315, in _parse
    raise ValueError("Unable to parse message.")
ValueError: Unable to parse message.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two inputs running into this issue, one is using Custom Data Type and the other one is using Cloudfront Access Logs. Also, I have some other SQS inputs that are running with no errors.&lt;/P&gt;&lt;P&gt;Does anyone has any hints on how to solve this "Unable to parse message" errors?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/537660#M64740</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2021-01-28T16:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: AWS SQS Input -  Unable to parse message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/547234#M65335</link>
      <description>&lt;P&gt;I have the same issue with ELB&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 16:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/547234#M65335</guid>
      <dc:creator>J_lo</dc:creator>
      <dc:date>2021-04-08T16:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: AWS SQS Input -  Unable to parse message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/557045#M65952</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp; Was anyone able to figure this out?&amp;nbsp; I'm encountering the same issue with all my SQS-based S3 inputs.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 22:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/557045#M65952</guid>
      <dc:creator>jmatthews</dc:creator>
      <dc:date>2021-06-24T22:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: AWS SQS Input -  Unable to parse message</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/557180#M65963</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235759"&gt;@jmatthews&lt;/a&gt;, I have not found much information about this errors, but in my case I was able to solve it because the issue was on KMS permissions for the Splunk role I was using for reading the SQS messages / S3 objects.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 11:23:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AWS-SQS-Input-Unable-to-parse-message/m-p/557180#M65963</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2021-06-25T11:23:28Z</dc:date>
    </item>
  </channel>
</rss>

