Splunk Search

Apache Web Server Load Balance Monitoring

kamaldsh
New Member

I have multiple web servers behind a load balancer. I am looking for a search query that can provide me a traffic distribution across the apache web servers and help in monitoring the equal distribution of load among web servers.

Tags (1)
0 Karma

mattymo
Splunk Employee
Splunk Employee

Hi kamaldsh,

Assuming that the count of access.log events points to distribution of http traffic, and that you are monitoring the apache access.log across all the servers,

Something this should work nicely:

| tstats count WHERE index=<yourApacheIndex> sourcetype=<yourApacheSourcetype> by host

This will count the number of apache access events by each webserver, assuming you have onboarded the data in a manner that ensures only your webservers are reporting this sourcetype in this index.

Be sure to update with the proper index and sourcetype for your apache data. Check out the addon for apache web server if you haven't already! https://splunkbase.splunk.com/app/3186/

As a former SRE type, I would also want platform stats from the webservers, either from Splunk TA Nix or nmon, or collectd, or snmp, whatver can get you a trend of traffic to the web server nics and cpu/mem/disk trending.

I would also want any load balancer stats regarding the pool and ditribution of traffic to it's members, etc.

Hope this helps!

- MattyMo
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...