<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Effect the change in Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115247#M183854</link>
    <description>&lt;P&gt;Absolutly right, MuS - but in some cases very useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2014 14:39:59 GMT</pubDate>
    <dc:creator>Rocket66</dc:creator>
    <dc:date>2014-06-23T14:39:59Z</dc:date>
    <item>
      <title>Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115242#M183849</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Whenever I make any changes in the splunk configuation file, I need to restart splunk services to effect the changes made. &lt;/P&gt;

&lt;P&gt;Do I have any alternative so that the changes will be effected without restarting splunk services ?&lt;/P&gt;

&lt;P&gt;Please help !!&lt;/P&gt;

&lt;P&gt;Many thanks for your kind support !!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 09:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115242#M183849</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2014-06-23T09:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115243#M183850</link>
      <description>&lt;P&gt;Hi abhayneilam,&lt;/P&gt;

&lt;P&gt;As a rule of thumb you can go by: usually anything that affects indexing level changes require a splunk restart, while search level changes require a reload. Here's a good guideline on how to determine which is which.&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime" rel="nofollow"&gt;&lt;/A&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime"&gt;http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So index creation or settings modifications, props.conf time stamp extractions, or transforms.conf indexed field modifications as well as most .conf manual changes will require a restart.&lt;/P&gt;

&lt;P&gt;If you make changes with $SPLUNK_HOME/bin/splunk  CLI changes or within the UI, it wont require a restart....unless of course you get prompted for a restart&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 09:44:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115243#M183850</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-23T09:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115244#M183851</link>
      <description>&lt;P&gt;Thanks a lot for the prompt reply !!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 11:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115244#M183851</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2014-06-23T11:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115245#M183852</link>
      <description>&lt;P&gt;You can also use the http://[SPLUNKSERVER]:8000/en-us/debug/refresh to reload conf-files &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 13:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115245#M183852</guid>
      <dc:creator>Rocket66</dc:creator>
      <dc:date>2014-06-23T13:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115246#M183853</link>
      <description>&lt;P&gt;be aware that this does not refresh all endpoints, only&lt;/P&gt;

&lt;P&gt;data/ui/[manager|nav|views]&lt;/P&gt;

&lt;P&gt;and &lt;CODE&gt;admin&lt;/CODE&gt; endpoints:&lt;BR /&gt;
conf-times&lt;BR /&gt;
alert_actions&lt;BR /&gt;
clusterconfig&lt;BR /&gt;
commandsconf&lt;BR /&gt;
conf-deploymentclient&lt;BR /&gt;
conf-inputs&lt;BR /&gt;
conf-times&lt;BR /&gt;
conf-wmi&lt;BR /&gt;
cooked&lt;BR /&gt;
datamodel-files&lt;BR /&gt;
datamodelacceleration&lt;BR /&gt;
datamodeledit&lt;BR /&gt;
deploymentserver&lt;BR /&gt;
eventtypes&lt;BR /&gt;
fields&lt;BR /&gt;
fifo&lt;BR /&gt;
fvtags&lt;BR /&gt;
indexes&lt;BR /&gt;
localapps&lt;BR /&gt;
lookup-table-files&lt;BR /&gt;
macros&lt;BR /&gt;
manager&lt;BR /&gt;
monitor&lt;BR /&gt;
nav&lt;BR /&gt;
passwords&lt;BR /&gt;
pools&lt;BR /&gt;
quickstart&lt;BR /&gt;
raw&lt;BR /&gt;
savedsearch&lt;BR /&gt;
scheduledviews&lt;BR /&gt;
script&lt;BR /&gt;
sourcetypes&lt;BR /&gt;
ssl&lt;BR /&gt;
syslog&lt;BR /&gt;
tcpout-default&lt;BR /&gt;
tcpout-group&lt;BR /&gt;
tcpout-server&lt;BR /&gt;
transforms-extract&lt;BR /&gt;
transforms-lookup&lt;BR /&gt;
udp&lt;BR /&gt;
ui-prefs&lt;BR /&gt;
views&lt;BR /&gt;
viewstates&lt;BR /&gt;
workflow-actions&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 14:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115246#M183853</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-23T14:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115247#M183854</link>
      <description>&lt;P&gt;Absolutly right, MuS - but in some cases very useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 14:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115247#M183854</guid>
      <dc:creator>Rocket66</dc:creator>
      <dc:date>2014-06-23T14:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Effect the change in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115248#M183855</link>
      <description>&lt;P&gt;It sure is a time saver &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 14:42:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Effect-the-change-in-Splunk/m-p/115248#M183855</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2014-06-23T14:42:30Z</dc:date>
    </item>
  </channel>
</rss>

