Splunk Enterprise

config changes indexes.conf - restart query

goelt2000
Explorer

Hi All,

Do we need an indexer restart in non clustered search peers for these changes?

Is reloading not enough?

 https://docs.splunk.com/Documentation/Splunk/8.2.0/Indexer/Determinerestart

 

in particular "coldPath.maxDataSizeMB" and "Enabling or disabling an index that contains data"

I don't think Splunk throws any errors or blocks subsequent indexes.conf changes when this happens. I need to check the logs, when any change is made in coldPath.maxDataSizeMB. But I am sure when disabling an index, the things go smooth without a restart. Why do we need a restart then?

 

Thanks!

 

Labels (1)
Tags (1)
0 Karma

codebuilder
Influencer

If you push out a new index then a restart/rolling restart of the indexers is not necessary.

If you make any changes to indexes.conf (other than a new index) the a restart is required (rolling restart for indexer cluster).

For an indexer cluster you need to use the master for bundle verification and push.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

goelt2000
Explorer

Thanks for the reply. the indexes.conf documentation does not say to restart it though when we disable.

Am I missing something?

https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Indexesconf

Thanks!

 

0 Karma

codebuilder
Influencer

Disabling an index does not require a restart, along with creating a new one (as I mentioned). Those are the two exceptions. Any other parameter changes require restart. The master will let you know if rolling restart is required after bundle validation.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...