All Apps and Add-ons

JMS modular input - MQ data format

julietjake
Explorer

I'm using the JMS modular input to read IBM MQ messages from a queue.

The majority of the messages are read correctly, but if there is a message with a blank 'Data Format' in the RFH2 header, the message is placed to the back out queue with the exception in splunkd.log:

/splunk/etc/apps/jms_ta/bin/jms.py" Examine the message data and ensure that it is of the correct format to be parsed as an MQJMS Message.

Of course I can look to amend the source system so that the data format is set, but is there anyway within Splunk I can force a default format like MQSTR?

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

This error is thrown by the underlying WAS MQ JMS provider jars.

So it is not something addressable in the JMS Modular Input code or Splunk.

It appears a non-JMS / non-parseable message was placed on the queue.

More info on this error , code JMSCMQ0018

View solution in original post

Damien_Dallimor
Ultra Champion

This error is thrown by the underlying WAS MQ JMS provider jars.

So it is not something addressable in the JMS Modular Input code or Splunk.

It appears a non-JMS / non-parseable message was placed on the queue.

More info on this error , code JMSCMQ0018

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...