Hi, Looks like the message that is being kept by s3 bucket upon new object is having some data which splunk is not able to parse it. Usually message will contain the metadata of which s3 , what is the key information and what is the size etc. please share the message details from sqs get message option. And also check if the messages are going to dlq if splunk is not able to parse and process, the messages will go to dlq to take the snapshot. I believe there might be some characters which splunk does not like in the s3 bucket name or object name.
... View more