<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic monitoring TCP input status remotely in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-TCP-input-status-remotely/m-p/174147#M35056</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;is there anything pokeable from a load balancer over TCP to validate the availability of a TCP data input? I can potentially just rely on a TCP connection working or not to validate it's availability, but ideally I'd like to get something back to my BigIP load balancer to validate it's health to a deeper level. We have the option of doing some form of script to do a search against the splunk port I suppose, but in the first instance I'd like to stick with only using the TCP data input port itself, not going round the back.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 23 Oct 2014 16:04:26 GMT</pubDate>
    <dc:creator>acidkewpie</dc:creator>
    <dc:date>2014-10-23T16:04:26Z</dc:date>
    <item>
      <title>monitoring TCP input status remotely</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-TCP-input-status-remotely/m-p/174147#M35056</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;is there anything pokeable from a load balancer over TCP to validate the availability of a TCP data input? I can potentially just rely on a TCP connection working or not to validate it's availability, but ideally I'd like to get something back to my BigIP load balancer to validate it's health to a deeper level. We have the option of doing some form of script to do a search against the splunk port I suppose, but in the first instance I'd like to stick with only using the TCP data input port itself, not going round the back.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2014 16:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-TCP-input-status-remotely/m-p/174147#M35056</guid>
      <dc:creator>acidkewpie</dc:creator>
      <dc:date>2014-10-23T16:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: monitoring TCP input status remotely</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-TCP-input-status-remotely/m-p/174148#M35057</link>
      <description>&lt;P&gt;What Splunk component is hosting your TCP data input and what constitutes "health at a deeper level"?&lt;BR /&gt;&lt;BR /&gt;
I am pretty sure that if you can establish a TCP connection to a port assigned to a TCP input on an indexer, you could take that as a very good sign that this thing is up and running and will process data sent to it.&lt;/P&gt;

&lt;P&gt;I am not aware of any health probe message you could send which would respond with a predefined "I'm here, I'm good" message, nor am I aware that that was ever reason for concern.&lt;/P&gt;

&lt;P&gt;You cannot do searches against a splunk port setup to listen for a TCP (or UDP) input stream, but I maybe misunderstanding what you are saying. Is your "round the back" idea to send some eyecatcher message to the port, then run a search to see whether that message was indexed? If so, I would keep it simple.... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Oct 2014 04:54:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-TCP-input-status-remotely/m-p/174148#M35057</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2014-10-25T04:54:19Z</dc:date>
    </item>
  </channel>
</rss>

