Splunk Search

Apache Web Server Load Balance Monitoring

kamaldsh
New Member

I have multiple web servers behind a load balancer. I am looking for a search query that can provide me a traffic distribution across the apache web servers and help in monitoring the equal distribution of load among web servers.

Tags (1)
0 Karma

mattymo
Splunk Employee
Splunk Employee

Hi kamaldsh,

Assuming that the count of access.log events points to distribution of http traffic, and that you are monitoring the apache access.log across all the servers,

Something this should work nicely:

| tstats count WHERE index=<yourApacheIndex> sourcetype=<yourApacheSourcetype> by host

This will count the number of apache access events by each webserver, assuming you have onboarded the data in a manner that ensures only your webservers are reporting this sourcetype in this index.

Be sure to update with the proper index and sourcetype for your apache data. Check out the addon for apache web server if you haven't already! https://splunkbase.splunk.com/app/3186/

As a former SRE type, I would also want platform stats from the webservers, either from Splunk TA Nix or nmon, or collectd, or snmp, whatver can get you a trend of traffic to the web server nics and cpu/mem/disk trending.

I would also want any load balancer stats regarding the pool and ditribution of traffic to it's members, etc.

Hope this helps!

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...