All Apps and Add-ons

JMS Messaging Modular Input: Why is nothing happening with my current inputs.conf configuration?

plarkin01
Explorer

I have the following configuration in the inputs.conf file, but nothing seems to be happening. I loaded up the bin folder with all the jars that are needed, but there is no logging to the $SPLUNK_HOME/var/log/splunk/splunkd.log. I am just kind of wondering how we are supposed to know if a connection was made or if errors are occurring. Thanks.

[jms://topic/EventTopic]
init_mode = jndi
jms_connection_factory_name = RemoteConnectionFactory
jndi_initialcontext_factory = org.jboss.naming.remote.client.InitialContextFactory
jndi_provider_url = remote://remote.testing:4447
durable = false
sourcetype = syslog
0 Karma

Damien_Dallimor
Ultra Champion

Any errors can be searched with : index=_internal ExecProcessor error jms.py

0 Karma

plarkin01
Explorer

I was able to do that search as well as look at the logs but the issue is nothing is being written. I know the values are correct and when I enter values that I know to be wrong I still do not get any errors. One would assume that if the JMS cannot connect to the topic an error would appear.

0 Karma

Damien_Dallimor
Ultra Champion

Perhaps you have a more systemic error , work through the troubleshooting steps in the docs : https://splunkbase.splunk.com/app/1317/#/documentation

0 Karma

plarkin01
Explorer

That could be the case. If I go through Splunk -> Settings -> Data Inputs -> JMS -> New is it supposed to add something to the input.conf? Currently the only way this is written to is if I open it up and manually add the configuration to it. Thanks .

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...