Hi Damien,
Every time I enable your amqp app it retrieves approximately 800 messages from my RabbitMQ queue, but then it stops because of the following (from splunkd.log):
02-09-2015 17:13:07.305 +0100 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" Can't connect to Splunk REST API with the token [Splunk RhMYOWU5UveKs_nVWfsMYQM52waB5i7v6^jauWlhXf3FDmRz4xZYz_u^CBLzU1ED6ruqL^8aft8cZ3NG6Y_unl1bLHbCUGhqs2IV8Ds8gGp_enr2BaZNPy0], either the token is invalid or SplunkD has exited : null
02-09-2015 17:13:17.306 +0100 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" It has been determined via the REST API that all inputs have been disabled
So I have to enable/disable your app to import all my (30.000+) messages.
Do you have any idea of what might be causing this? I tried messing around with sslv3 vs tls etc. (as per looking at other answers on this page), but it remains the same.
Thank you in advance,
Teddy Strand
... View more