Installation

Restart Splunk Search Head only in single host installation of Splunk Enterprise

adckia
New Member

Hello,
In a test environment, we have a single-host installation of Splunk Enterprise, i.e.
- License Master
- Indexer (single, no cluster)
- Deployment Server
- Search Head (single, no cluster)
- Monitoring Console
all run on the same machine.
The question is: How can we restart the Search Head (in order to have it reload the apps an saved searches from the file system) without stopping the other Splunk processes (in particular, we don't want the Indexer to stop)?
Thanks for any hints.

Tags (1)
0 Karma
1 Solution

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

View solution in original post

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

View solution in original post

0 Karma

adckia
New Member

Thanks for the hint.
Does this also reload an app updated on the file system?

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

It will reload/refresh config changes. If it is a new App install or upgrade it may need a restart.

0 Karma

adckia
New Member

It works for my current purpose of reloading the alerts.
Thank you very much.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.