What Splunk component is hosting your TCP data input and what constitutes "health at a deeper level"?
I am pretty sure that if you can establish a TCP connection to a port assigned to a TCP input on an indexer, you could take that as a very good sign that this thing is up and running and will process data sent to it.
I am not aware of any health probe message you could send which would respond with a predefined "I'm here, I'm good" message, nor am I aware that that was ever reason for concern.
You cannot do searches against a splunk port setup to listen for a TCP (or UDP) input stream, but I maybe misunderstanding what you are saying. Is your "round the back" idea to send some eyecatcher message to the port, then run a search to see whether that message was indexed? If so, I would keep it simple.... 😉
... View more