I don't understand why, but when I create a new index, Splunk needs a restart.
Do you have best practice for this?
Thank a lot
Try using the rest endpoint to create indexes, it won't ask you for a restart. But you need to run the command on all your indexers -
curl -k -u : https://indexer:port/servicesNS///data/indexes -d name=
View solution in original post
This shohuld help