Getting Data In

CLI reload scripted input

EricPartington
Communicator

I have a number of scripted inputs on my linux servers. How do I use the cli to reload that input to update configurations after a script or config has been modified?

./splunk _internal call ...?

I am restarting the entire splunk installation currently and would like to avoid that if possible.

The inputs are also contained inside an app, so if reloading an app is easier then a CLI command to disable and enable an app would also be useful.

Tags (3)
0 Karma
1 Solution

Ayn
Legend

Splunk is running the script as it is each time, so if you modify the script, the changes will take effect the next time Splunk runs it.

View solution in original post

Ayn
Legend

Splunk is running the script as it is each time, so if you modify the script, the changes will take effect the next time Splunk runs it.

Ayn
Legend

Have a look at the CLI command edit. $SPLUNK_HOME/bin/splunk help edit

0 Karma

EricPartington
Communicator

Ok, i had edited the inputs.conf file to change the source value and that wasnt reflected in the output i was seeing on import into splunk.

Is there a way to enable or disable a particular input via CLI?
if disabled=0 for
[script:///app/splunk/etc/apps/lea-cma-o-international/bin/lea-loggrabber.sh]
how do i enable that particular input without using the GUI?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...