Getting Data In

Is changing Class can affect indexing and Fishbucket CRC

michael_vi
Path Finder

Hi all,

A general question that I couldn't find an answer to...

If I change for the certain app class from one to another, and restart splunkd, will there be any affect on indexing?

I mean will it re-index the same data or a portion of it twice? 

Or, since it's the same a app and same source, maybe there is no need to restart splunkd?

Thanks 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @michael_vi ,

sorry but your question isn't so clear:

what do you mean with "app class"?

are you speaking od an add-on for iput data or what else?

Splunk doesn't reindex twice the same data even if you change the data filename.

The only way to reindex an already idexed data is if you used crcSal = <SOUCE> in your inputs.conf stanzas and you changed the data filename.

Final question: all the changes to a conf file (not by GUI) require a splunk restart on the machine.

Ciao.

Giuseppe

0 Karma

michael_vi
Path Finder

I mean, if I change a Server Class in Deployment Server from one to another.

Everything else stays the same.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @michael_vi ,

a ServerClass is a relation table between a list of hosts and a list of apps to be deployed to the hosts, so you can move apps between ServerClasses without any problem, putting obviously attention to cover all the hosts.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...