Deployment Architecture

How does a Search Head Cluster determine if a restart is necessary when a configuration bundle is applied?

muebel
SplunkTrust
SplunkTrust

A configuration bundle can be applied to a Search Head Cluster (SHC) from a Deployer with the command:

splunk apply shcluster-bundle

The documentation indicates that the cluster somehow determines if a rolling restart is necessary as part of the bundle application

Each cluster member applies the app tarballs locally. If a rolling restart is determined necessary, approximately 10% of the members then restart at a time, until all have restarted.

http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/PropagateSHCconfigurationchanges

How does the cluster determine if a rolling restart is necessary? I'm working with custom javascript/css, and have found that a rolling restart doesn't occur when pushing out new files, or new versions of the files.

0 Karma
1 Solution

somesoni2
Revered Legend

From the same page, (search for keyword 'app.conf'),

For information on which configuration changes trigger restart, see $SPLUNK_HOME/etc/system/default/app.conf. It lists the configuration files that do not trigger restart when changed. All other configuration changes trigger restart.

View solution in original post

somesoni2
Revered Legend

From the same page, (search for keyword 'app.conf'),

For information on which configuration changes trigger restart, see $SPLUNK_HOME/etc/system/default/app.conf. It lists the configuration files that do not trigger restart when changed. All other configuration changes trigger restart.

muebel
SplunkTrust
SplunkTrust

awesome. ty

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...