<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a way to send AMQP messages from Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-send-AMQP-messages-from-Splunk/m-p/272583#M190187</link>
    <description>&lt;P&gt;We need to publish messages based on events in Splunk. Is there a way to get Splunk to publish events using AMQP? At the moment, best I can come up with is triggering a script from an alert and writing custom code to handle publishing of messages.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2016 13:24:26 GMT</pubDate>
    <dc:creator>eugenek</dc:creator>
    <dc:date>2016-02-08T13:24:26Z</dc:date>
    <item>
      <title>Is there a way to send AMQP messages from Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-send-AMQP-messages-from-Splunk/m-p/272583#M190187</link>
      <description>&lt;P&gt;We need to publish messages based on events in Splunk. Is there a way to get Splunk to publish events using AMQP? At the moment, best I can come up with is triggering a script from an alert and writing custom code to handle publishing of messages.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2016 13:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-send-AMQP-messages-from-Splunk/m-p/272583#M190187</guid>
      <dc:creator>eugenek</dc:creator>
      <dc:date>2016-02-08T13:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to send AMQP messages from Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-send-AMQP-messages-from-Splunk/m-p/272584#M190188</link>
      <description>&lt;P&gt;Splunk doesn't have any built-in features to send messages to AMQP.&lt;/P&gt;

&lt;P&gt;There is a AMQP modular input, but that takes messages from AMQP and indexes them into Splunk, not the other way around. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/apps/#/page/1/search/amqp/order/relevance"&gt;https://splunkbase.splunk.com/apps/#/page/1/search/amqp/order/relevance&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Since there isn't an option in Splunkbase, you'll need to create something yourself.  In 6.3 Splunk added custom alert actions, which let you integrate your own alert responses into Splunk.  Yes you'd need to write a script, and the integrate that into Splunk.  Take a look at the links below.  There are many examples of other types of alert actions in Splunkbase that you can use to get started.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/AdvancedDev/ModAlertsIntro"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/AdvancedDev/ModAlertsIntro&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/apps/#/order/relevance/search/alert%2520action"&gt;https://splunkbase.splunk.com/apps/#/order/relevance/search/alert%2520action&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2016 14:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-send-AMQP-messages-from-Splunk/m-p/272584#M190188</guid>
      <dc:creator>Jeremiah</dc:creator>
      <dc:date>2016-02-08T14:00:47Z</dc:date>
    </item>
  </channel>
</rss>

