All Apps and Add-ons

JMS modular input - MQ data format

julietjake
Explorer

I'm using the JMS modular input to read IBM MQ messages from a queue.

The majority of the messages are read correctly, but if there is a message with a blank 'Data Format' in the RFH2 header, the message is placed to the back out queue with the exception in splunkd.log:

/splunk/etc/apps/jms_ta/bin/jms.py" Examine the message data and ensure that it is of the correct format to be parsed as an MQJMS Message.

Of course I can look to amend the source system so that the data format is set, but is there anyway within Splunk I can force a default format like MQSTR?

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

This error is thrown by the underlying WAS MQ JMS provider jars.

So it is not something addressable in the JMS Modular Input code or Splunk.

It appears a non-JMS / non-parseable message was placed on the queue.

More info on this error , code JMSCMQ0018

View solution in original post

Damien_Dallimor
Ultra Champion

This error is thrown by the underlying WAS MQ JMS provider jars.

So it is not something addressable in the JMS Modular Input code or Splunk.

It appears a non-JMS / non-parseable message was placed on the queue.

More info on this error , code JMSCMQ0018

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...