Deployment Architecture

Search Head Pooling - How to configure load balancer health monitor

zindain24
Path Finder

Hello,

We are using an F5-Bigip load balancer to host splunk.company.com for a pool of search heads.

Our internet services team is looking for a way to perform a health check on each pool member. Normally, they place a small html file in the document root and have the load balancer read it periodically. Has anyone had Splunk experience with this? Does anyone have any better idea for a health-check?

Also where is the web server "document root" in Splunk? We are running our servers on Linux.

Thanks!

1 Solution

zindain24
Path Finder

From the F5-Bigip perspective we just check for a tcp connection for each pool member. If a tcp connection fails on a pool member, it is removed from the global pool until availability is restored. We also robotically monitor Splunks response time and availability using an IBM product called ITCAM.http://www-03.ibm.com/software/products/en/compositeapplicationmanagerfortransactions

View solution in original post

zindain24
Path Finder

From the F5-Bigip perspective we just check for a tcp connection for each pool member. If a tcp connection fails on a pool member, it is removed from the global pool until availability is restored. We also robotically monitor Splunks response time and availability using an IBM product called ITCAM.http://www-03.ibm.com/software/products/en/compositeapplicationmanagerfortransactions

zindain24
Path Finder

From the F5-Bigip perspective we just check for a tcp connection for each pool member. If a tcp connection fails on a pool member, it is removed from the global pool until availability is restored. We also robotically monitor Splunks response time and availability using an IBM product called ITCAM.

http://www-03.ibm.com/software/products/en/compositeapplicationmanagerfortransactions

0 Karma

pwmcity
Path Finder

Can I ask if you found an answer to this? I'm about to set up the exact same thing

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...