All Apps and Add-ons

Amazon Kinesis Modular Input: How to resolve "com.splunk.modinput.kinesis.KinesisModularInput$MessageReceiver.connect(Unknown Source)" errors?


Hi -
We have download the Amazon Kinesis Modular Input add-on from :
Unfortunately we are unable to get it to work. We are getting the following issues. Can you guide us in the right direction?

After configuring the Kinesis data input in our on-prem server, we are getting many errors like this :

11-14-2016 11:32:26.551 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/kinesis_ta/bin/"        at
11-14-2016 11:32:26.551 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/kinesis_ta/bin/"        at com.splunk.modinput.kinesis.KinesisModularInput$MessageReceiver.connect(Unknown Source)

We are trying to determine the issue? Can you assist ? Here is how our $SPLUNK_HOME/etc/apps/Splunk_TA_aws/local/aws_kinesis_tasks.conf file looks like :

account = AWS
encoding =
index = aws
init_stream_position = TRIM_HORIZON
region = us-east-1
sourcetype = aws:kinesis
stream_names = test

can you tell us what we are missing here? or what we are doing wrong? Thank you

0 Karma

Ultra Champion

The Amazon Kinesis Modular Input has nothing to do with Splunk_TA_aws , so it's an irrelevant comparison.

Regarding errors running Amazon Kinesis Modular Input......

Have you followed the docs correctly ? The troubleshooting steps are useful ie: correct Java version ?
What does your inputs.conf stanza look like ?

0 Karma


Thanks Damien for the reply , below is how the inputs.conf stanza look like . We need to figure out what is this error means and how to correct it . We are getting data from other sources of AWS thru the AWS app, so it is not the firewall issue. this is the error:
11-14-2016 17:19:42.194 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/kinesis_ta/bin/" at com.splunk.modinput.kinesis.KinesisMo
dularInput.startMessageReceiverThread(Unknown Source)

vi inputs.conf


connection settings

app_name = test
stream_name = test
kinesis_endpoint =


initial_stream_position = TRIM_HORIZON

aws_access_key_id = some key secret
aws_secret_access_key = some key secret

message reader settings

backoff_time_millis =
num_retries =
checkpoint_interval_millis =

message handler

message_handler_impl =
message_handler_params =

additional startup settings

additional_jvm_propertys =

data output

One of [stdout | hec ]. Defaults to stdout.

output_type = stdout

For hec(HTTP Event Collector) output

hec_port =

Defaults to 1

hec_poolsize =
hec_token =

1 | 0

hec_https = 0

1 | 0

hec_batch_mode = 0

numeric value

hec_max_batch_size_bytes =

numeric value

hec_max_batch_size_events =

in milliseconds

hec_max_inactive_time_before_batch_flush =
index = aws
sourcetype = aws:kinesis

0 Karma


Thank you Damien , Yes you are correct, JAVA was not in the path : now I put the java in the path of user that is running the splunk (which is root) , now I am no longer getting the above error , I am getting new error in the message : Unable to initialize modular input "kinesis" defined inside the app "kinesis_ta": Introspecting scheme=kinesis: script running failed (exited with code 1). Got this when I ran with scheme

/opt/splunk/etc/apps/Splunk_TA_aws/bin/ --scheme
Traceback (most recent call last):
File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/", line 9, in
from splunktalib.common import log
File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunktalib/common/", line 11, in
from splunktalib.splunk_platform import make_splunkhome_path
File "/opt/splunk/etc/apps/Splunk_TA_aws/bin/splunktalib/", line 86
res[section] = {item[0]: item[1] for item in parser.items(section)}
SyntaxError: invalid syntax

I will go thru the trouble shoot docs again .
[root@server~]# echo $PATH

0 Karma

Ultra Champion

You didn't answer this :

Have you followed the docs correctly ? The troubleshooting steps are useful ie: correct Java version ?

If you are the same person that emailed me a log dump , I am going to presume you do not have the correct Java version.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...