Hello all,
Looking for a way to modify the Splunk Health Check for small buckets. Specifically, I would like the healthcheck to exclude certain indexes.
For example, I like knowing if I am getting too many small buckets... but not if it is for my test index.
I was looking into this today for a similar problem with a different health check. It turns out we can adjust the threshold for when the check turns yellow or red, but can't change the check itself. IOW, the search is hardcoded.