Getting Data In

Unable to index to Splunk server from MuleSoft

Venkat_16
Contributor

Greetings everyone!!!

We were trying to integrate Splunk with Mulesoft. we already had splunk plugins in Mulesoft. We gave heavy forwarder IP and 8089 as port number. But we are not getting data in main index.

Is this configuration correct or we need to give indexer IP and port 8089 in the mulesoft configuration...

Please guide us

0 Karma

Robertaacen
New Member

Hi Buddie,

I have also one doubt while using Mulesoft Studio for one of my usecase.

My scenario is to pass the database result as parameter dynamically to the soap web service. I am passing the Parameter via SetPayload component.

I am passing the parameter in this below format, I am getting argument mismatch error.
I tested this argument using logger payload[0][‘RATE’],payload[0][‘APPLICANT_NAME’], it retrieve the value perfectly. When I used this in set-payload I am getting argument mismatch error.

I am looking to resolve this problem.

Could you please advice any pointers, how did you managed to resolve your error?

Thanks in advance.
Robert.
,

0 Karma

jplumsdaine22
Influencer

Hi Venkat,

Port 8089 is the Splunk management port - it won't receive data there. I'm not familiar with mulesoft is it generating syslog events or writing its logs to a file?

Is this your first time using Splunk? I strongly recommend doing the Splunk tutorial, - it will take a few hours but it will greatly improve your splunk experience.

http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

0 Karma

Venkat_16
Contributor

Thanks for the answer

please refer the below documentation link where it suggests the default port to be configured as 8089

http://blogs.mulesoft.com/biz/mule/anypoint-runtime-manager-v1-2-monitoring-servers-and-apps-with-sp...

i believe we can get data through 8089 port if we are using API calls

0 Karma

jplumsdaine22
Influencer

Ah I understand now. It should be ok to use the heavy forwarder.
Did you configure the input as per the documentation here? https://docs.mulesoft.com/runtime-manager/sending-data-from-arm-to-external-monitoring-software#inte...

You need to create the sourcetype in Splunk before you send events.

Venkat_16
Contributor

Hey Thanks i didnt check this part, Thanks again!!!

0 Karma

Venkat_16
Contributor

Have configured the props.conf as directed in the mulesoft link:

[mule]
TRUNCATE = 0
LINE_BREAKER = ([\r\n]+)
SHOULD_LINEMERGE = false
INDEXED_EXTRACTIONS = JSON
KV_MODE = JSON
category = Mule Splunk Integration
description = Mule Agent event information

but still we are not able to view any of the logs in splunk.... any way to check to error logs...not error logs in _internal index

0 Karma

jplumsdaine22
Influencer

did you create the input as per the section "Configuring your Runtime Manager Account*" ?

0 Karma

Venkat_16
Contributor

Yes we choose the REST API method to configure the mulesoft
gave heavy forwarder IP and port number 8080 and created a user in heavy forwarder and as well in the Splunk search head and kept default values for the advance settings, Between thanks alot

0 Karma

santosh12
New Member

Hi Venkat,

Were you successful in sending data from Mulesoft via Heavy forwarder?

regards
Santosh

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...