Splunk Enterprise

Deploying a simple TA to indexers - rolling restart required?

danielbb
Motivator

We want to add a TA (app) to our indexers at the path /opt/splunk/etc/master-apps by running the command /opt/splunk/bin/splunk apply cluster-bundle

My question is if we can deploy an indexer app without a restart of the indexer? The TA we want to deploy is an extension to the nix TA, and all it does is run some simple bash scripted inputs.

 

 

Labels (1)
0 Karma

danielbb
Motivator

Thank you so much, one of our stanzas looks like the following -

 

[script://./bin/ulimit.sh]
interval = 27 5 * * *
source = scripted_input
sourcetype = virtualization:sanity:ulimit
index = os
disabled = false

 

 

Based on the link you provided, a reload should be fine. How would we run a "reload"?

inputs.confhttpreload
inputs.confscriptreload
inputs.confmonitorreload
inputs.conf<modular_input>reload
inputs.confbatchreload
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...