Monitoring Splunk

Splunk search and indexer nodes health check url

dhavamanis
Builder

Can you please provide the Splunk search and indexer nodes health check url to use this for DNS / VIP level to check whether the nodes are active or not.

Tags (1)
1 Solution

grijhwani
Motivator

An HTTP poll to port 8089 (or whichever port you have configured) should return valid XML. This is, actually, a FAQ. Checking the presence of port 9997 (default) is a good indicator of a working indexer.

View solution in original post

grijhwani
Motivator

An HTTP poll to port 8089 (or whichever port you have configured) should return valid XML. This is, actually, a FAQ. Checking the presence of port 9997 (default) is a good indicator of a working indexer.

grijhwani
Motivator

Thanks for the up-vote, but it is better just to mark your question answered so it can be seen at a glance.

0 Karma

grijhwani
Motivator

Sorry. If not http, https.

If you log into your indexer, you should be able to see which ports with a netstat command.

0 Karma

dhavamanis
Builder

Thanks, Can you provide the sample url which will provide the xml response with default settings/port.

0 Karma

dhavamanis
Builder

i am getting the below response, Can you please provide the valid url,

[splunk@aozaplp00030 tmp]$ curl http://IPAddress:8089/
curl: (52) Empty reply from server

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...