<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way not to restart entire splunk instance after making changes in .conf files? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372365#M165115</link>
    <description>&lt;P&gt;If its just a change to a search time transforms.conf, you could use the following SPL:&lt;BR /&gt;
     | extract reload=t&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2017 05:34:03 GMT</pubDate>
    <dc:creator>nickstone</dc:creator>
    <dc:date>2017-11-16T05:34:03Z</dc:date>
    <item>
      <title>Is there a way not to restart entire splunk instance after making changes in .conf files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372364#M165114</link>
      <description>&lt;P&gt;In general after we make changes in .conf files splunk instance should restart. If we deploy splunk  in production environment and after making changes in .conf files a restart of entire splunk  might be problem. so, is there any way we can resolve this problem?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 05:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372364#M165114</guid>
      <dc:creator>krishnakanthgup</dc:creator>
      <dc:date>2017-11-16T05:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way not to restart entire splunk instance after making changes in .conf files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372365#M165115</link>
      <description>&lt;P&gt;If its just a change to a search time transforms.conf, you could use the following SPL:&lt;BR /&gt;
     | extract reload=t&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 05:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372365#M165115</guid>
      <dc:creator>nickstone</dc:creator>
      <dc:date>2017-11-16T05:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way not to restart entire splunk instance after making changes in .conf files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372366#M165116</link>
      <description>&lt;P&gt;Thanks Nickstone. but what if it was a props.conf file?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 06:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372366#M165116</guid>
      <dc:creator>krishnakanthgup</dc:creator>
      <dc:date>2017-11-16T06:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way not to restart entire splunk instance after making changes in .conf files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372367#M165117</link>
      <description>&lt;P&gt;As per the &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf"&gt;props.conf&lt;/A&gt; documentation:&lt;BR /&gt;
    # You can enable configurations changes made to props.conf by typing the&lt;BR /&gt;
    # following search string in Splunk Web:&lt;BR /&gt;
    #&lt;BR /&gt;
    # | extract reload=T&lt;/P&gt;

&lt;P&gt;So yes that will work for props and transforms.conf&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 08:58:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-not-to-restart-entire-splunk-instance-after/m-p/372367#M165117</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-11-17T08:58:30Z</dc:date>
    </item>
  </channel>
</rss>

