All Apps and Add-ons

Not able to get the data from AMPQ-ModularInput to Splunk

cyber_castle
Path Finder

Following are my AMPQ-ModularInput configuration details. For some reason I am not able to get the data from AMPQ-ModularInput to Splunk

12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.splunk.modinput.amqp.AMQPModularInput$MessageReceiver.run(Unknown Source)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.splunk.modinput.amqp.AMQPModularInput$MessageReceiver.connect(Unknown Source)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.rabbitmq.client.ConnectionFactory.newConnection(ConnectionFactory.java:612)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.rabbitmq.client.ConnectionFactory.newConnection(ConnectionFactory.java:588)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at com.rabbitmq.client.impl.FrameHandlerFactory.create(FrameHandlerFactory.java:32)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.Socket.connect(Socket.java:607)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:188)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:206)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:350)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" at java.net.PlainSocketImpl.socketConnect(Native Method)
12-09-2019 15:10:55.871 +0000 ERROR ExecProcessor - message from "python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py" Stanza amqp://Rabbit_MQ : Error connecting : java.net.ConnectException: Connection timed out (Connection timed out)
12-09-2019 15:01:56.435 +0000 INFO ExecProcessor - New scheduled exec process: python /apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py
12-09-2019 15:01:56.434 +0000 INFO ExecProcessor - Removing status item "/apps/splunk/splunk/etc/apps/amqp_ta/bin/amqp.py (isModInput=yes)


[amqp://Rabbit_MQ]
ack_messages = 0
activation_key = 1BE1C5DD7DA1CD8BFD93319BB9AA3A6A3974465751
exchange_name = CEE_Events
hec_batch_mode = 0
hec_https = 0
host = server01
hostname = 10.10.10.10
index = main
index_message_envelope = 1
index_message_propertys = 1
output_type = stdout
password = dummy_password
port = 5672
queue_name = CEPA
sourcetype = _json
use_ssl = 0
username = dummy_user

```xml

server01
https://127.0.0.1:8089
zN9dv8iBq6K5ly8qdLcl7f_KNdHAJ5IjcNKp8ErVfGyXXmH5lVIFrIOakKkp3^tS2U78oc1c2GeRUPpK9wrZhL7egy6qlioTB5Nna3QtyDOhlx7DFgr1^C
/apps/splunk/splunk/var/lib/splunk/modinputs/amqp

<stanza name="amqp://Rabbit_MQ" app="launcher">
  <param name="ack_messages">0</param>
  <param name="activation_key">1BE1C5DD7DA1CD8BFD93319BB9AA3A6A3974465751</param>
  <param name="exchange_name">CEE_Events</param>
  <param name="hec_batch_mode">0</param>
  <param name="hec_https">0</param>
  <param name="host">server01</param>
  <param name="hostname">10.10.10.10</param>
  <param name="index">main</param>
  <param name="index_message_envelope">1</param>
  <param name="index_message_propertys">1</param>
  <param name="output_type">stdout</param>
  <param name="password">dummy_password</param>
  <param name="port">5672</param>
  <param name="queue_name">CEPA</param>
  <param name="sourcetype">json</param>
  <param name="use_ssl">0</param>
  <param name="username">dummy_username</param>
</stanza>

```

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...