Can someone give me an idea what this error message means in relation to the MQTT Modular Input?
10-23-2017 12:29:59.378 +1100 ERROR JsonLineBreaker - JSON StreamId:12467227541764018490 had parsing error:Unexpected character: ':' - data_source="mqtt://VM1", data_host="Libellium", data_sourcetype="_json"
Trying to set up a connection to an existing broker.
I suspect your JSON data does not wrap attribute names and values in double quotes, which is how Splunk expects it to pass json validation. But it's just a guess.
That is not an error message from the MQTT Mod Input.
The Splunk sourcetype "_json" , does not like something in your received JSON.
I'd try a custom sourcetype, see what gets indexed and what is possibly malformed in the JSON.