All Apps and Add-ons

JMS Messaging Modular Input: How to resolve multiple Python errors such as "[Error 87] The parameter is incorrect" when adding a new modular input?

jdhruti
New Member

We have an issue when we add new JMS modular input. Everything looks ok but it still shows JMS errors connecting. Additionally it blocks messages from coming in for All the other modular inputs when i enable the new one.

Also we have tested this in our QA environment. It only doesn't work in Prod.

Inputs.conf:

[jms://queue/QUEUE_NAME]
browse_mode = all
browse_queue_only = 0
durable = 0
index = INDEXNAME
index_message_header = 0
index_message_properties = 0
init_mode = jndi
jms_connection_factory_name = SplunkQConnectionFactory
jndi_initialcontext_factory = com.sun.jndi.fscontext.RefFSContextFactory
jndi_provider_url = file:///F:/splunk/etc/apps/jms_ta/local/Hadoop/prod
sourcetype = hadoopmon_prod
strip_newlines = 0
jndi_user = USERNAME
jndi_pass = PASSWORD
disabled = 0
destination_pass = USERNAME
destination_user = PASSWORD
browse_frequency = -1
hec_batch_mode = 0
hec_https = 0
output_type = stdout

Error Message:

1/25/17 13:42:35.536 PM 01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py" Traceback (most recent call last):

1/25/17 13:42:35.536 PM 
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"   File "F:\Splunk\etc\apps\jms_ta\bin\jms.py", line 131, in 

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"     do_run()

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"   File 
"F:\Splunk\etc\apps\jms_ta\bin\jms.py", line 50, in do_run

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"     run_java()

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"   File "F:\Splunk\etc\apps\jms_ta\bin\jms.py", line 101, in run_java

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"     process = Popen(java_args)

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"   File "F:\Splunk\Python-2.7\Lib\subprocess.py", line 710, in __init__

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"     errread, errwrite)

1/25/17 1:42:35.536 PM  
01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"   File "F:\Splunk\Python-2.7\Lib\subprocess.py", line 958, in _execute_child

1/25/17 1:42:35.536 PM  

01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py"     startupinfo)

1/25/17 1:42:35.536 PM  

01-25-2017 13:42:35.536 -0500 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\jms_ta\bin\jms.py" WindowsError: [Error 87] The parameter is incorrect
0 Karma

Damien_Dallimor
Ultra Champion

Is Java installed and on the PATH or JAVA_HOME env variable set ?

Does the user you are running Splunk as have permission to execute Java ?

0 Karma

jdhruti
New Member

Yes. the user have permission to execute Java. Additionally i have noticed whenever i enable the new input, it kills the python process. Any idea why it would do that?

0 Karma

jdhruti
New Member

I would like to give more info regarding the environment that we have. So we have a jms-ta add-on on two of the heavy forwarders. We already have 23 inputs created on them which works completely fine. Now i am trying to add one more input and it won't work. All the binding files and the inputs seems right. And there are no errors regarding that as it's working in our lower environment.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...