Splunk Enterprise

config changes indexes.conf - restart query

goelt2000
Explorer

Hi All,

Do we need an indexer restart in non clustered search peers for these changes?

Is reloading not enough?

 https://docs.splunk.com/Documentation/Splunk/8.2.0/Indexer/Determinerestart

 

in particular "coldPath.maxDataSizeMB" and "Enabling or disabling an index that contains data"

I don't think Splunk throws any errors or blocks subsequent indexes.conf changes when this happens. I need to check the logs, when any change is made in coldPath.maxDataSizeMB. But I am sure when disabling an index, the things go smooth without a restart. Why do we need a restart then?

 

Thanks!

 

Labels (1)
Tags (1)
0 Karma

codebuilder
Influencer

If you push out a new index then a restart/rolling restart of the indexers is not necessary.

If you make any changes to indexes.conf (other than a new index) the a restart is required (rolling restart for indexer cluster).

For an indexer cluster you need to use the master for bundle verification and push.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

goelt2000
Explorer

Thanks for the reply. the indexes.conf documentation does not say to restart it though when we disable.

Am I missing something?

https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Indexesconf

Thanks!

 

0 Karma

codebuilder
Influencer

Disabling an index does not require a restart, along with creating a new one (as I mentioned). Those are the two exceptions. Any other parameter changes require restart. The master will let you know if rolling restart is required after bundle validation.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...