All Apps and Add-ons

AMQP Messaging Modular Input: Importing MQ messages into Splunk, why is the payload or body of the message empty?

spervaiz_splunk
Splunk Employee
Splunk Employee

We are using a RabbitMQ server (amqp) as data source. Our previous experiments led us to the Splunk AMQP Messaging Modular Input add-on and we have already received messages.
 
The RabbitMQ server is supplied on the other side by a Linux Syslog-ng service. This creates the AMQP message as follows.
 
An AMQP message is sent in which all relevant data are fed into the header data of the message properties.

DATE:       Oct 6 14:10:06
FACILITY:   syslog
HOST:       logserver
MESSAGE:    syslog-ng starting up; version='3.5.6'
PID:        1432
PRIORITY:   notice
PROGRAM:    syslog-ng
SEQNUM:     1
SOURCEIP:   127.0.0.1
TAGS:       .source.s_src

The payload or message body of the message, on the other hand, is empty. Splunk does not interpret this data easily.
 
We need the information as Splunk must be configured to correctly interpret the AMQP messages / Best practices if the application is known.

0 Karma

Damien_Dallimor
Ultra Champion

Post your inputs.conf stanza you setup.
Also post any log error messages : index=_internal error ExecProcessor amqp.py

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi spervaiz,

Seems you have already installed the AMQP Messaging Modular Input and received data through it. Have you configured the add-on properly? As this is a Modular Input , you can then configure your AMQP inputs via Manager->Data Inputs->AMQP. The field entry should be straightforward and intuitive for anyone with basic experience with AMQP.
If the add-on configuration does not work for your data format, you can also create your own custom sourcetype so that Splunk can correctly perform field extraction and transformation of your data.

Hope it helps. Thanks!
Hunter Shen

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Splunk Cloud Application Management in Terraform

Now On-Demand   We’re diving into how you can bring Infrastructure as Code (IaC) principles to your Splunk ...

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...