Splunk Dev

How do you add an external link in Splunk Monitoring Console Health Check checklist.conf

panguy
Contributor

I'm trying to figure out how do we add an external link to documentation in checklist.conf. This is for a healthcheck that will be run in the Splunk Monitoring Console.

Here is an example from the System Hardware provisioning assessment health check:

 

 

[system_hardware_provisioning_assessment]
title = System hardware provisioning assessment
category = System and Environment
tags = best_practices, capacity, scalability
description = This evaluates the hardware specifications of Splunk instances tasked with indexing and/or searching data, using reference hardware.
failure_text = One or more hosts has returned CPU or memory specifications that fall below reference hardware recommendations. This might adversely affect indexing or search performance.
suggested_action = If you are experiencing performance issues, consider upgrading hosts to meet or exceed the recommended hardware specs.
doc_link = healthcheck.hardware.reference
doc_title = recommended minimum hardware
applicable_to_groups = dmc_group_search_head,dmc_group_indexer
search = | rest $rest_scope$ /services/server/info \
| eval cpu_core_count = if(isnotnull(numberOfVirtualCores), numberOfVirtualCores, numberOfCores) \
| eval physical_memory_GB = round(physicalMemoryMB / 1024, 0) \
| fields splunk_server cpu_core_count physical_memory_GB \
| eval severity_level = case(cpu_core_count <= 4 OR physical_memory_GB <= 4, 2, cpu_core_count < 12 OR physical_memory_GB < 12, 1, cpu_core_count >= 12 AND physical_memory_GB >= 12, 0, true(), -1) \
| rename splunk_server AS instance cpu_core_count AS "cpu_core_count (current / recommended)" physical_memory_GB AS "physical_memory_GB (current / recommended)" \
| fieldformat cpu_core_count (current / recommended) = 'cpu_core_count (current / recommended)'." / 12" \
| fieldformat physical_memory_GB (current / recommended) = 'physical_memory_GB (current / recommended)'." / 12"

 

 

the doc_link isn't a URL but it does link to :

https://docs.splunk.com/Documentation/Splunk/9.0.4/Capacity/Referencehardware?ref=hk

 

How  can I link to an external doc?

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...