icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Amazon Kinesis Modular Input
SHA256 checksum (amazon-kinesis-modular-input_134.tgz) 405ae1a0b4fd8a2dd106842ab1f96cbcf1ce8ec463c087c613d8637cf0eabe6b SHA256 checksum (amazon-kinesis-modular-input_133.tgz) ccf2650b42695562aa9417f61496d9e6cbc8e15c72dc46fa6ee083ff257f6c02 SHA256 checksum (amazon-kinesis-modular-input_132.tgz) 1f77d64098da4211569c2542fefe77b580ac248f30ec7378b84126b406938c93 SHA256 checksum (amazon-kinesis-modular-input_131.tgz) 0964938291f97d063d7ec97f55986da0d613450e4f33ed33f0017be43b2c1176 SHA256 checksum (amazon-kinesis-modular-input_13.tgz) 953c6385df744564b899b0fb920e738a29acc6e04e16dffd5b1bc31a58cc2d46 SHA256 checksum (amazon-kinesis-modular-input_12.tgz) b986d3088291cea52e0c1cb09b87fa2f8a08fa9b6b305b11cd74199a47841758 SHA256 checksum (amazon-kinesis-modular-input_11.tgz) f71148374f87941430af8343a0c1285f2afa80a12e38dea03be5d5328693b96b SHA256 checksum (amazon-kinesis-modular-input_103.tgz) f46c6d286ada9b99975f46dce9e358ef0b6cdf122dacdfe4ace98f2e0a1ed475 SHA256 checksum (amazon-kinesis-modular-input_102.tgz) 7af16218e464755a0686245d1f10523bce2a076edb062701420e8a4b7b418467 SHA256 checksum (amazon-kinesis-modular-input_101.tgz) 54c1e017263b3924a40d60c6a3f5cc0213b37828c41c9d6dde691d20d2604f60 SHA256 checksum (amazon-kinesis-modular-input_10.tgz) 8689767be42c2099d2e5e6793fd87b0f4efca3fb31281b4a320a7fd8dd241383 SHA256 checksum (amazon-kinesis-modular-input_09.tgz) 954968463a863813b542e4b5cd7cca3bbac7c65e719be98332b7d4648a255ef4 SHA256 checksum (amazon-kinesis-modular-input_08.tgz) b896e3c9e9bb2a985f7f747440136c83b314136845b22b72fa2aa145d08cfc69 SHA256 checksum (amazon-kinesis-modular-input_07.tgz) 240ce85671afefacbe3513fc1a9205b201b65db7c278a7dbef191e8ebaa39e2d SHA256 checksum (amazon-kinesis-modular-input_06.tgz) 42eea6b7b1c1a64d9b17e26cffa99995d4f4d3c938aa3b74961c55bc02f11f4e SHA256 checksum (amazon-kinesis-modular-input_05.tgz) 55c7812371f669f1c99c5090e101a334d0388b55f66bd968a74cb421c3a8be1d
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Amazon Kinesis Modular Input

This is a Splunk Modular Input Add-On for indexing records from Amazon Kinesis

Splunk Amazon Kinesis Modular Input v1.3.4


This is a Splunk Modular Input Add-On for indexing records from Amazon Kinesis.

What is Kinesis ?



  • Splunk 5.0+
  • Java Runtime 1.7+
  • Supported on Windows, Linux, MacOS, Solaris, FreeBSD, HP-UX, AIX


  • Optionally set your JAVA_HOME environment variable to the root directory of your JRE installation.If you don't set this , the input will look for a default installed java executable on the path.
  • Untar the release to your $SPLUNK_HOME/etc/apps directory
  • Restart Splunk
  • If you are using a Splunk UI Browse to Settings -- Data Inputs -- Amazon Kinesis to add a new Input stanza via the UI
  • If you are not using a Splunk UI (ie: you are running on a Universal Forwarder) , you need to add a stanza to inputs.conf directly as per the specification in README/inputs.conf.spec. The inputs.conf file should be placed in a local directory under an App or User context.

Activation Key

You require an activation key to use this App. Visit http://www.baboonbones.com/#activation to obtain a non-expiring key


Any log entries/errors will get written to $SPLUNK_HOME/var/log/splunk/splunkd.log

These are also searchable in Splunk : index=_internal error kinesis.py

JVM Heap Size

The default heap maximum is 64MB.
If you require a larger heap, then you can alter this in $SPLUNK_HOME/etc/apps/kinesis_ta/bin/kinesis.py on line 95

JVM System Properties

You can declare custom JVM System Properties when setting up new input stanzas.
Note : these JVM System Properties will apply to the entire JVM context and all stanzas you have setup

Customized Message Handling

The way in which the Modular Input processes the received Kinesis records is enitrely pluggable with custom implementations should you wish.

To do this you code an implementation of the com.splunk.modinput.kinesis.AbstractMessageHandler class and jar it up.

Ensure that the necessary jars are in the $SPLUNK_HOME/etc/apps/kinesis_ta/bin/lib directory.

If you don't need a custom handler then the default handler com.splunk.modinput.kinesis.DefaultMessageHandler will be used.

Code examples are on GitHub : https://github.com/damiendallimore/SplunkModularInputsJavaFramework/tree/master/kinesis/src/com/splunk/modinput/kinesis


  • JAVA_HOME environment variable is set or "java" is on the PATH for the user's environment you are running Splunk as
  • You are using Splunk 5+
  • You are using a 1.7+ Java Runtime
  • You are running on a supported operating system
  • Look for any errors in $SPLUNK_HOME/var/log/splunk/splunkd.log
  • Run this command as the same user that you are running Splunk as and observe console output : "$SPLUNK_HOME/bin/splunk cmd python ../etc/apps/kinesis_ta/bin/kinesis.py --scheme"


This project was initiated by Damien Dallimore , damien@baboonbones.com

Release Notes

Version 1.3.4
June 25, 2019

cosmetic fixes

Version 1.3.3
May 10, 2019

cosmetic fixes

Version 1.3.2
April 23, 2019

updated docs

Version 1.3.1
April 19, 2019

added trial key functionality

Version 1.3
March 28, 2019

docs updated

Version 1.2
June 3, 2018

minor manager xml ui tweak for 7.1

Version 1.1
May 27, 2018

Added an activation key requirement , visit http://www.baboonbones.com/#activation to obtain a free,non-expiring key
Docs updated
Splunk 7.1 compatible

Version 1.0.3
April 21, 2016

Added JSON Object parsing for Cloudwatch to the GZIP handler

Version 1.0.2
April 16, 2016

tweaks to gzip handler

Version 1.0.1
April 13, 2016

Pushed default charset decoding out of the main message processing flow and into custom handling , so custom handlers that you implement should in theory be able to process any binary or text payload.

Version 1.0
April 12, 2016

Can now pass the raw payload bytes to your custom message handler ie: if you want to decode binary data
Added a custom GZIP decoder , com.splunk.modinput.kinesis.GZIPDataRecordDecoderHandler

Version 0.9
Nov. 10, 2015

Tweaked the HEC transport.

Added a new custom handler that allows you to declare the fieldnames in the JSON that hold the time and host values of the event.

message_handler_impl = com.splunk.modinput.kinesis.JSONBodyWithFieldExtraction
message_handler_params = timefield=foo,hostfield=goo

Version 0.8
Sept. 22, 2015

Added support to optional output to Splunk via a HEC (HTTP Event Collector) endpoint

Version 0.7
Feb. 11, 2015

Enabled TLS1.2 support by default.
Made the core Modular Input Framework compatible with latest Splunk Java SDK
Please use a Java Runtime version 7+
If you need to use SSLv3 , you can turn this on in bin/kinesis.py

Version 0.6
Sept. 12, 2014

Added a custom message handler that just dumps the JSON body.

message_handler_impl = com.splunk.modinput.kinesis.JSONOnlyMessageHandler

Version 0.5
Aug. 30, 2014

Initial Beta release


Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2019 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.