All Apps and Add-ons

In Splunk Enterprise, can you help me set up the AMQP Modular Input?

lavster
Path Finder

Hello,

we are trying to pull in the JSON message from a rabbit server. However, we seem to be getting all the config from the queue before hand. Is there a way to just pull in the msg_body?

Here is an example of the events in Splunk

Fri Sep 28 12:55:36 BST 2018 name=amqp_msg_received event_id=null msg_queue=ES_queue msg_exchange=BMISG msg_body={"TIMESTAMP":"2018-09-27-18:14:26.727","MESSAGETYPE":"INFO","SYSTEM":"BMI","MODULE":"Prep Step","SUBMODULE":"unionData","MESSAGE":"Testing Data.","RUNID":"TEST_201806_064"}
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

View solution in original post

Damien_Dallimor
Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

lavster
Path Finder

Thanks Damien

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...