Getting Data In

monitoring TCP input status remotely

acidkewpie
Path Finder

Hi,

is there anything pokeable from a load balancer over TCP to validate the availability of a TCP data input? I can potentially just rely on a TCP connection working or not to validate it's availability, but ideally I'd like to get something back to my BigIP load balancer to validate it's health to a deeper level. We have the option of doing some form of script to do a search against the splunk port I suppose, but in the first instance I'd like to stick with only using the TCP data input port itself, not going round the back.

Thanks!

Tags (3)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

What Splunk component is hosting your TCP data input and what constitutes "health at a deeper level"?

I am pretty sure that if you can establish a TCP connection to a port assigned to a TCP input on an indexer, you could take that as a very good sign that this thing is up and running and will process data sent to it.

I am not aware of any health probe message you could send which would respond with a predefined "I'm here, I'm good" message, nor am I aware that that was ever reason for concern.

You cannot do searches against a splunk port setup to listen for a TCP (or UDP) input stream, but I maybe misunderstanding what you are saying. Is your "round the back" idea to send some eyecatcher message to the port, then run a search to see whether that message was indexed? If so, I would keep it simple.... 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...