Splunk Enterprise Security

Splunk App for ES Health Check: How to add and list multiple indexers?

ronj_clark
Explorer

I have the Splunk App for ES Health Check running. In the configuration, I have the dedicated ES (Enterprise Security) Search Head listed, but only 1 of 3 indexers listed. How do I add the other 2 indexers and have the app still work?
I have tried entering in something like this in the UI: "indexer01","indexer02"

That only gave an error message in the app when I saved and reloaded.

Any idea if this is possible to list multiple indexers?

Thanks,
Ron C

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

There are macro definitions for the indexers and search heads in this app. You need to update these. Refer to docs here :

http://docs.splunk.com/Documentation/ESHealthCheck/1.0.0/UserGuide/Install

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...