All Apps and Add-ons

In Splunk Enterprise, can you help me set up the AMQP Modular Input?

lavster
Path Finder

Hello,

we are trying to pull in the JSON message from a rabbit server. However, we seem to be getting all the config from the queue before hand. Is there a way to just pull in the msg_body?

Here is an example of the events in Splunk

Fri Sep 28 12:55:36 BST 2018 name=amqp_msg_received event_id=null msg_queue=ES_queue msg_exchange=BMISG msg_body={"TIMESTAMP":"2018-09-27-18:14:26.727","MESSAGETYPE":"INFO","SYSTEM":"BMI","MODULE":"Prep Step","SUBMODULE":"unionData","MESSAGE":"Testing Data.","RUNID":"TEST_201806_064"}
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

View solution in original post

Damien_Dallimor
Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

lavster
Path Finder

Thanks Damien

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...