Splunk Search

Splunk with MQ Series

vherilier
Engager

Hi,

As said in Splunk's Application Management Solutions page, IBM MQ Series belongs to typical data sources. But I do not succeed to find how to catch MQ Series data and how use them next.
Does someone could help me to understand how to work with MQ Series data ?

Thanks

Regards

Vincent

Tags (3)

matt_batterham
New Member

It's possible to feed all IBM MQ Status, Statistics, Events and usage data into SPLUNK using a tool called Lamaxu, www.queuemetrix.com/2015/12/21/how-to-integrate-lamaxu-with-splunk/

Lamaxu supports queue managers deployed to all platforms, including AIX, Linux, iSeries, Windows and ZOS etc, as well as MQ message volume statistics and dataset usage from Mainframe ZOS managers.

alt text

alt text

0 Karma

Damien_Dallimor
Ultra Champion

You could use this new modular input , available from Splunkbase :

http://splunk-base.splunk.com/apps/69562/jms-messaging-modular-input

0 Karma

bmacias84
Champion

@vherilier, IBM MQ use Java Message Service (JMS), so you would be able to use JMX for Splunk to pull mbean metrics and stats. Have your MQ log data sent directly to splunk. How you index parses your data is done case by case. For working or learning about MQ data you probably refer to IBM MQ forum.

Quote from IMB Website: "In addition to this de facto standard interface, WebSphere MQ also fully implements the industry standard Java Message Service (JMS) interface, including support for publish and subscribe messaging."

Damien_Dallimor
Ultra Champion

Just to add :

Splunk for JMX will work for monitoring Websphere MQ Queues/Queue Managers via the exposed MBeans.

If you want to monitor the actual messages coming off MQ queues and topics , then currently you'd have to script a custom input.This might use JMS or Native MQ (MQI).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...