All Apps and Add-ons

AMQP Messaging Modular Input: How to troubleshoot why RabbitMQ AMQP data is not getting indexed in Splunk?

dinosaur_giraff
New Member

Hi Team,

I have set up an AMQP Messaging data input to collect data from our RabbitMQ instance.

The input appears to be configured properly, however, the only way to get messages from the queue is to disable and re enable the input.

This will pull any queued logs, but then promptly 'break' again and stop pulling through any new entries.

After re-enabling the AMPQ input, we receive the following Internal Error in the logging:

05-04-2016 10:00:02.945 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" Probing socket connection to SplunkD failed.Either SplunkD has exited ,or if not, check that your DNS configuration is resolving your system's hostname (splunk-ent01) correctly : *HOSTNAME*

Along with

05-04-2016 10:00:22.955 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" Determined that Splunk has probably exited, HARI KARI.

Any help would be greatly appreciated.

Regards,
Ben

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Have you addressed the information in the error ?

check that your DNS configuration is
resolving your system's hostname
(splunk-ent01) correctly

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Have you addressed the information in the error ?

check that your DNS configuration is
resolving your system's hostname
(splunk-ent01) correctly

0 Karma

dinosaur_giraff
New Member

Hi Damien,

Thanks for the reply, I hadn't yet edited the hostfile for splunk-ent01. All is working now, cheers.

Regards,
Ben

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...