Installation

Restart Splunk Search Head only in single host installation of Splunk Enterprise

adckia
New Member

Hello,
In a test environment, we have a single-host installation of Splunk Enterprise, i.e.
- License Master
- Indexer (single, no cluster)
- Deployment Server
- Search Head (single, no cluster)
- Monitoring Console
all run on the same machine.
The question is: How can we restart the Search Head (in order to have it reload the apps an saved searches from the file system) without stopping the other Splunk processes (in particular, we don't want the Indexer to stop)?
Thanks for any hints.

Tags (1)
0 Karma
1 Solution

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

View solution in original post

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

0 Karma

adckia
New Member

Thanks for the hint.
Does this also reload an app updated on the file system?

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

It will reload/refresh config changes. If it is a new App install or upgrade it may need a restart.

0 Karma

adckia
New Member

It works for my current purpose of reloading the alerts.
Thank you very much.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...