Splunk Search

Updating eventgen.conf requires a Splunk restart

newportknight
Loves-to-Learn

Hi,

I am playing around with SA-Eventgen to generate data in a Dev environment but I find if I make a change to the eventgen.conf file I have to restart Splunk for it to take effect. (All I am doing is changing the date/time format)

Is there any other way to to make the change effective without having to carry out a restart? I have tried disabling and re-enabling via the Data input and also disabling and re-enabling the app itself but neither have the desired outcome.

Appreciate any help.

Cheers.

Paul.

Tags (1)
0 Karma

newportknight
Loves-to-Learn

Hi,

Thanks for replying.

I've tried using the URL suggested but it doesn't appear to have any effect.
There are no errors showing when I carry out a search using index="_internal" sourcetype="eventgen*"

Cheers.

Paul.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@newportknight

Is that any Errors in eventgen logs? Please execute below search for the eventgen log if you can found anything helpful.

index="_internal" sourcetype="eventgen*"
0 Karma

zahrasidhpuri
Engager

Hey Paul,
You can try doing this: http[s]://[splunkweb hostname]:[splunkweb port]/debug/refresh

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...