Splunk Enterprise

Does Splunk need a restart after a change to log.cfg?

splunkemly
New Member

Currently, we have this in /opt/splunkforwarder/etc/log.cfg:

appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log 

I want to change the logging location to /var/log and wondering if it can be done by doing this:

appender.A1.fileName=/var/log/splunk/splunkd.log

If so, Does splunk need to be restarted after this change to log.cfg?

0 Karma

renjith_nair
Legend

For any manual change in configs, splunk needs a restart

Ref : http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/Enabledebuglogging

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...