Splunk Enterprise

config changes indexes.conf - restart query

goelt2000
Explorer

Hi All,

Do we need an indexer restart in non clustered search peers for these changes?

Is reloading not enough?

 https://docs.splunk.com/Documentation/Splunk/8.2.0/Indexer/Determinerestart

 

in particular "coldPath.maxDataSizeMB" and "Enabling or disabling an index that contains data"

I don't think Splunk throws any errors or blocks subsequent indexes.conf changes when this happens. I need to check the logs, when any change is made in coldPath.maxDataSizeMB. But I am sure when disabling an index, the things go smooth without a restart. Why do we need a restart then?

 

Thanks!

 

Labels (1)
Tags (1)
0 Karma

codebuilder
Influencer

If you push out a new index then a restart/rolling restart of the indexers is not necessary.

If you make any changes to indexes.conf (other than a new index) the a restart is required (rolling restart for indexer cluster).

For an indexer cluster you need to use the master for bundle verification and push.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

goelt2000
Explorer

Thanks for the reply. the indexes.conf documentation does not say to restart it though when we disable.

Am I missing something?

https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Indexesconf

Thanks!

 

0 Karma

codebuilder
Influencer

Disabling an index does not require a restart, along with creating a new one (as I mentioned). Those are the two exceptions. Any other parameter changes require restart. The master will let you know if rolling restart is required after bundle validation.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...