Getting Data In

Why does Splunk ask me to restart when I create a new index?

gibba
Path Finder

Hi everyone,

I don't understand why, but when I create a new index, Splunk needs a restart.

Do you have best practice for this?

Thank a lot

Tags (3)
0 Karma
1 Solution

dineshraj
Explorer

Try using the rest endpoint to create indexes, it won't ask you for a restart. But you need to run the command on all your indexers -

curl -k -u : https://indexer:port/servicesNS///data/indexes -d name=

View solution in original post

0 Karma

somesoni2
Revered Legend
0 Karma

dineshraj
Explorer

Try using the rest endpoint to create indexes, it won't ask you for a restart. But you need to run the command on all your indexers -

curl -k -u : https://indexer:port/servicesNS///data/indexes -d name=

View solution in original post

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!