Splunk Enterprise Security

Splunk App for ES Health Check: How to add and list multiple indexers?

ronj_clark
Explorer

I have the Splunk App for ES Health Check running. In the configuration, I have the dedicated ES (Enterprise Security) Search Head listed, but only 1 of 3 indexers listed. How do I add the other 2 indexers and have the app still work?
I have tried entering in something like this in the UI: "indexer01","indexer02"

That only gave an error message in the app when I saved and reloaded.

Any idea if this is possible to list multiple indexers?

Thanks,
Ron C

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

There are macro definitions for the indexers and search heads in this app. You need to update these. Refer to docs here :

http://docs.splunk.com/Documentation/ESHealthCheck/1.0.0/UserGuide/Install

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...