Splunk Enterprise Security

Splunk App for ES Health Check: How to add and list multiple indexers?

ronj_clark
Explorer

I have the Splunk App for ES Health Check running. In the configuration, I have the dedicated ES (Enterprise Security) Search Head listed, but only 1 of 3 indexers listed. How do I add the other 2 indexers and have the app still work?
I have tried entering in something like this in the UI: "indexer01","indexer02"

That only gave an error message in the app when I saved and reloaded.

Any idea if this is possible to list multiple indexers?

Thanks,
Ron C

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

There are macro definitions for the indexers and search heads in this app. You need to update these. Refer to docs here :

http://docs.splunk.com/Documentation/ESHealthCheck/1.0.0/UserGuide/Install

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...