Installation

Restart Splunk Search Head only in single host installation of Splunk Enterprise

adckia
New Member

Hello,
In a test environment, we have a single-host installation of Splunk Enterprise, i.e.
- License Master
- Indexer (single, no cluster)
- Deployment Server
- Search Head (single, no cluster)
- Monitoring Console
all run on the same machine.
The question is: How can we restart the Search Head (in order to have it reload the apps an saved searches from the file system) without stopping the other Splunk processes (in particular, we don't want the Indexer to stop)?
Thanks for any hints.

Tags (1)
0 Karma
1 Solution

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

View solution in original post

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

0 Karma

adckia
New Member

Thanks for the hint.
Does this also reload an app updated on the file system?

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

It will reload/refresh config changes. If it is a new App install or upgrade it may need a restart.

0 Karma

adckia
New Member

It works for my current purpose of reloading the alerts.
Thank you very much.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...