All Apps and Add-ons

AMQP Messaging Modular Input: How to troubleshoot why RabbitMQ AMQP data is not getting indexed in Splunk?

dinosaur_giraff
New Member

Hi Team,

I have set up an AMQP Messaging data input to collect data from our RabbitMQ instance.

The input appears to be configured properly, however, the only way to get messages from the queue is to disable and re enable the input.

This will pull any queued logs, but then promptly 'break' again and stop pulling through any new entries.

After re-enabling the AMPQ input, we receive the following Internal Error in the logging:

05-04-2016 10:00:02.945 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" Probing socket connection to SplunkD failed.Either SplunkD has exited ,or if not, check that your DNS configuration is resolving your system's hostname (splunk-ent01) correctly : *HOSTNAME*

Along with

05-04-2016 10:00:22.955 +1000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/amqp_ta/bin/amqp.py" Determined that Splunk has probably exited, HARI KARI.

Any help would be greatly appreciated.

Regards,
Ben

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Have you addressed the information in the error ?

check that your DNS configuration is
resolving your system's hostname
(splunk-ent01) correctly

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Have you addressed the information in the error ?

check that your DNS configuration is
resolving your system's hostname
(splunk-ent01) correctly

0 Karma

dinosaur_giraff
New Member

Hi Damien,

Thanks for the reply, I hadn't yet edited the hostfile for splunk-ent01. All is working now, cheers.

Regards,
Ben

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...