How do I get a complete list of all indexers in my Splunk Enterprise environment?
The Inherited Deployment manual offers some suggestions. See https://docs.splunk.com/Documentation/Splunk/8.1.2/InheritedDeployment/MCdiscovery
There's no one perfect method for all environments. If you're lucky, the Monitoring Console is up-to-date and you can just look there.
If you're less fortunate, you can get many indexer names using SPL.
| tstats count where index=* by splunk_server | fields - count
The latter method most likely will yield only server names. You'll then need to use a method appropriate for your environment to map them to IP addresses.
The Inherited Deployment manual offers some suggestions. See https://docs.splunk.com/Documentation/Splunk/8.1.2/InheritedDeployment/MCdiscovery
There's no one perfect method for all environments. If you're lucky, the Monitoring Console is up-to-date and you can just look there.
If you're less fortunate, you can get many indexer names using SPL.
| tstats count where index=* by splunk_server | fields - count
The latter method most likely will yield only server names. You'll then need to use a method appropriate for your environment to map them to IP addresses.
Thank u very much as usual. I salute your dedication to this profession. Stay safe & blessed.