<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Installation of Splunk again and again. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47101#M1409</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk, So while doing changes in input.conf or props.conf etc.
the changes are not taking place unless and untill. I reinstall the splunk.
Is there any other method ? &lt;/P&gt;

&lt;P&gt;Your help is appreciated..&lt;/P&gt;</description>
    <pubDate>Fri, 18 Feb 2011 18:43:51 GMT</pubDate>
    <dc:creator>msona</dc:creator>
    <dc:date>2011-02-18T18:43:51Z</dc:date>
    <item>
      <title>Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47101#M1409</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk, So while doing changes in input.conf or props.conf etc.
the changes are not taking place unless and untill. I reinstall the splunk.
Is there any other method ? &lt;/P&gt;

&lt;P&gt;Your help is appreciated..&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2011 18:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47101#M1409</guid>
      <dc:creator>msona</dc:creator>
      <dc:date>2011-02-18T18:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47102#M1410</link>
      <description>&lt;P&gt;Have you tried just restarting splunk?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME$/bin&amp;gt; splunk resart
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 Feb 2011 19:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47102#M1410</guid>
      <dc:creator>vaijpc</dc:creator>
      <dc:date>2011-02-18T19:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47103#M1411</link>
      <description>&lt;P&gt;You can pull in changes to props.conf with the not-so-intuitive search command (as admin):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;* | extract reload=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I think you only need to search a short time-window (like 5 minutes) for this to cause props.conf to be reloaded.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2011 23:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47103#M1411</guid>
      <dc:creator>rotten</dc:creator>
      <dc:date>2011-02-18T23:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47104#M1412</link>
      <description>&lt;P&gt;You mean restart, not reinstall, right?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2011 01:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47104#M1412</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-19T01:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47105#M1413</link>
      <description>&lt;P&gt;yes, tried but not working.&lt;BR /&gt;
I think the problem is, splunk already index the fields and can not delete the indexed data, if I change somthing input.conf or props.conf&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2011 10:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47105#M1413</guid>
      <dc:creator>msona</dc:creator>
      <dc:date>2011-02-21T10:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47106#M1414</link>
      <description>&lt;P&gt;its short time data like 1 day. But Can splunk changes the data which was already indexed before ?? after changes in props.conf.&lt;BR /&gt;
For example: Splunk taking some unnesessary field values from csv header. I wanna remove that. I am doing changes in conf files but changes taking place after reinstall the splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2011 10:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47106#M1414</guid>
      <dc:creator>msona</dc:creator>
      <dc:date>2011-02-21T10:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47107#M1415</link>
      <description>&lt;P&gt;Hello. How about it? (using CLI)&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Stop Splunk:&lt;/LI&gt;
&lt;PRE&gt;./splunk stop&lt;/PRE&gt;
&lt;LI&gt;Remove unnecessary data from indexes: (This example removes all data from all indexes.)&lt;/LI&gt;
&lt;PRE&gt;./splunk clean all -f&lt;/PRE&gt;
&lt;LI&gt;Restart Splunk:&lt;/LI&gt;
&lt;PRE&gt;./splunk restart&lt;/PRE&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 21 Feb 2011 15:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47107#M1415</guid>
      <dc:creator>Hajime</dc:creator>
      <dc:date>2011-02-21T15:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47108#M1416</link>
      <description>&lt;P&gt;Once the data is indexed it is written in stone.  Re-reading the props.conf applies to future events.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2011 21:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47108#M1416</guid>
      <dc:creator>rotten</dc:creator>
      <dc:date>2011-02-21T21:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47109#M1417</link>
      <description>&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2011 15:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47109#M1417</guid>
      <dc:creator>msona</dc:creator>
      <dc:date>2011-02-22T15:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Installation of Splunk again and again.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47110#M1418</link>
      <description>&lt;P&gt;As "rotten" mentioned, once the data has been indexed, it cannot be changed.  However, some things are not stored in the index.  Those things can be changed as you wish.  Below are the basics; look in the documentation for more details.&lt;/P&gt;

&lt;P&gt;Changes to &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; change how all new data will be indexed.  These changes do not affect data that has already been indexed.  If you want these changes to apply to all data, you will need to use the splunk &lt;STRONG&gt;clean&lt;/STRONG&gt; command, as was shown in one of the other answers.&lt;/P&gt;

&lt;P&gt;Changes to &lt;STRONG&gt;props.conf&lt;/STRONG&gt; &lt;EM&gt;may&lt;/EM&gt; change how data is indexed:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Setting the source, sourcetype or  host - these affect how the data is indexed.  Therefore, this is the same as changes to inputs.conf. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Defining field extractions - field definitions  are not indexed; fields are built during the search process.  These changes do &lt;STRONG&gt;not&lt;/STRONG&gt; require that you restart Splunk.  Any changes that you make to field extractions will apply to &lt;STRONG&gt;all&lt;/STRONG&gt; data, regardless of when it was indexed.  (BTW, you can do "index time field extractions" but don't.  Use the normal, search-time field extractions - this is what Splunk recommends.)&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If you are new to Splunk, I suggest that you use the web interface (the Splunk Manager) to set up your inputs, and the interactive field extractor to set up your fields.  One of the nice things about using the Splunk web interface is that it will tell you if you need to restart Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2011 19:18:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Installation-of-Splunk-again-and-again/m-p/47110#M1418</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2011-05-20T19:18:26Z</dc:date>
    </item>
  </channel>
</rss>

