I'm trying to use the write_http plugin for collectd to send the metrics to Splunk so that I can use the Splunk collectd app to view the results.
I can see the data in Splunk by querying index=collectd and that's fine.
The collectd index is in my default list of searchable indices.
My write_http stanza looks like:
Plugin write_http
Node "node-http-1"
URL "https://xxx..xxx.xxx.xxx:9989/services/collector/raw?channel=f3d00af7-d987-49a8-be4d-f3c605b0dda5"
Header "Authorization: Splunk f3d00af7-d987-49a8-be4d-f3c605b0dda5"
Format "JSON"
Metrics true
StoreRates true
VerifyPeer false
VerifyHost false
LogHttpError true
Node
Plugin
How can I confirm that collectd is sending to the Splunk server on port 9989?
And I do have iptables turned off.
Both machines are Linux servers:
Linux nfldevspc01 2.6.32-696.18.7.el6.x86_64 #1 SMP Thu Dec 28 20:15:47 EST 2017 x86_64 x86_64 x86_64 GNU/Linux
I guess i wasn't clear about my question.
I know the data is getting to the Splunk server and is being ingested by Splunk (since I get data if a query index=collectd).
However, I don't get any results if I use the collectd app.
Jeff
You can use nestats
command.