Hello,
I have opened a case with Splunk regarding the AMQP input and received a response to post it on Answers page.
Added to address my questions to Damien (I should have done that first). I am trying to collect messages from Rabbit MQ. We have setup a Splunk instance with AMQP Messaging Modular Input and added the following configs
[amqp://xyz]
ack_messages = 1
hostname = 184.x.x.x
index = main
index_message_envelope = 1
index_message_propertys = 1
output_type = stdout
password = xyz
port = 5672
queue_name = xyz
sourcetype = amqp
use_ssl = 1
username = xyz
disabled = 0
virtual_host = xyz
basic_qos_limit = 20
hec_batch_mode = 0
hec_https = 0
It was added as a successful input but i have been told by the RabbitMQ team that they do not see any connections being made by Splunk on 5672. (Telnet to 5672 works btw so we can rule out the connectivity / Fire wall issues)
Here's what i found in the splunkd.log
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at sun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1105)
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:999)
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:153)
12-05-2016 14:58:40.643 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.splunk.HttpService.send(HttpService.java:367)
Here's the JAVA_HOME: /usr/lib/jvm/java-1.8.0-openjdk-1.8.0.101-3.b13.el6_8.x86_64/jre/
I should have 5 messages in the MQ but i do not see any in Splunk. Appreciate your help.
Thanks,
Raghav