Best way to bring indexer back online following "splunk offline --enforce-counts" ?


Had to take an indexer down for several days while a SSD was replaced, I used the "splunk offline --enforce-counts" command to allow the data to replicate back out to the other indexers (we have replication factor of 1).  I'm curious now after the SSD has been replaced, what is the best option to rejoin this host back to the cluster?

Add the indexer as though it was brand new to the cluster then run a re-balance.

