We are using Message Broker to drop messages into MQ Queue and Splunk uses JMS Input to read messages out of these queue.
Recently we have started noticing that some of the messages are missing from splunk. Though those messages are dropped into the MQ queue and Splunk reads out of it, we do not see those messages in Splunk.
For eg: if we drop 5 messages related to 5 different IDs, Splunk displays 1 or 2 messages and the remaining messages are missing.
This behavior is intermittent. Sometimes Splunk shows all 5 messages, but other times it displays different messages, even though the same set of messages (content wise) is dropped again and again.
We are not sure why these messages go missing. Is there any way to increase JMS Input log level? We checked the default Splunk system log and did not find any clues there.
Can anyone help us out?
... View more