All Apps and Add-ons

In Splunk Enterprise, can you help me set up the AMQP Modular Input?

New Member

Hello,

we are trying to pull in the JSON message from a rabbit server. However, we seem to be getting all the config from the queue before hand. Is there a way to just pull in the msg_body?

Here is an example of the events in Splunk

Fri Sep 28 12:55:36 BST 2018 name=amqp_msg_received event_id=null msg_queue=ES_queue msg_exchange=BMISG msg_body={"TIMESTAMP":"2018-09-27-18:14:26.727","MESSAGETYPE":"INFO","SYSTEM":"BMI","MODULE":"Prep Step","SUBMODULE":"unionData","MESSAGE":"Testing Data.","RUNID":"TEST_201806_064"}
0 Karma
1 Solution

Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

View solution in original post

Ultra Champion

Try adding a custom message handler : com.splunk.modinput.amqp.JSONMessageHandler

alt text

View solution in original post

New Member

Thanks Damien

0 Karma