Getting Data In

Will | extract reload=true command refresh everything in props.conf?

watsm10
Communicator

Hi,

I've got four indexers and two search heads in a distributed environment. I've got a new sourcetype coming into my indexers from a forwarder which hasn't been configured yet.

When I define it in props.conf:

[mysourcetype]
TIME_PREFIX=starttime
blah blah blah

am I able to use | extract reload=true instead of a full splunkd restart? Will it have the same effect? I'm always hesitant to do a full restart of indexers as it is a critical component of our monitoring.

Thanks,

Matt

kristian_kolb
Ultra Champion

No, certain props.conf settings will require a restart of Splunk. That's settings that have impact on indexing, such as TIME_FORMAT, LINE_BREAKER, TRANSFORMS etc

Purely search-time stuff like FIELDALIAS and EXTRACT does not require restarts.

/K

watsm10
Communicator

Thanks guys! The debug/refresh has worked. No longer will I have to restart 😄 I love Splunk Base!

0 Karma

kristian_kolb
Ultra Champion

Good points. I believe I've strayed too far from the GUI, but not far enough... 🙂

sideview
SplunkTrust
SplunkTrust

If it can, then it will be refreshed if you hit http://SPLUNKHOST:8000/debug/refresh

Any manager entity that can be refreshed from disk without a restart registers itself such that basically it gets refreshed when that page is hit. Conversely, if hitting that page does not refresh some config, then it's a safe bet that it really does require a restart.

If you have Sideview Utils on the system note that there is a little form at /app/sideview_utils/refresh_entities that you can use to refresh one particular entity at a time.

watsm10
Communicator

There must be a way.. we can add to props.conf for index-time stuff through the GUI when adding new inputs. Is there a way we can replicate this? Maybe a custom view?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...