Splunk must be restarted for changes to take effect. Contact Splunk Cloud Support to complete the restart.
But does not have the permission to raise a support ticket because still in the trial stage.
@jiangyj - In most cases, performing /debug/refresh should be equivalent to Splunk restart in most cases.
You can add /debug/refresh at the end of URL:
I hope this helps!!!
@VatsalJagani the above action is similar in some ways but doesn’t restart the daemon.
it will just refresh a specific set of config files.
@jiangyj there is no other option to restart. May be an enhancement or feature request will help us all out.
got Forbidden info when I run it.
@jiangyj - You need to have the admin role.
If it's still not working then you don't have any choice then to ask for support from the cloud.
unfortunately there is no way to do it on SC trial environment. Let's hope that in some day Splunk will offer solution for this.