We have search head clustering implemented which involves a deployer and 3 search heads.
On Navigating to "User Activity" page, under the "Search Head" drop-down, it only lists one search head. The other two are missing. When I check `splunk_health_overviews/lookups/all_servers.csv`, the CSV file is missing the two search heads as well.
How is this CSV populated? Can I populate it manually to add missing search heads? Do I need to populate it from the deployer and apply the shcluster bundle from there?
↧