Splunk Search

Effect the change in Splunk

abhayneilam
Contributor

Hi,

Whenever I make any changes in the splunk configuation file, I need to restart splunk services to effect the changes made.

Do I have any alternative so that the changes will be effected without restarting splunk services ?

Please help !!

Many thanks for your kind support !!

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi abhayneilam,

As a rule of thumb you can go by: usually anything that affects indexing level changes require a splunk restart, while search level changes require a reload. Here's a good guideline on how to determine which is which.

http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime

So index creation or settings modifications, props.conf time stamp extractions, or transforms.conf indexed field modifications as well as most .conf manual changes will require a restart.

If you make changes with $SPLUNK_HOME/bin/splunk CLI changes or within the UI, it wont require a restart....unless of course you get prompted for a restart

hope this helps ...

cheers, MuS

View solution in original post

Rocket66
Communicator

You can also use the http://[SPLUNKSERVER]:8000/en-us/debug/refresh to reload conf-files 🙂

DavidHourani
Super Champion

It sure is a time saver 🙂

0 Karma

Rocket66
Communicator

Absolutly right, MuS - but in some cases very useful 🙂

0 Karma

MuS
SplunkTrust
SplunkTrust

be aware that this does not refresh all endpoints, only

data/ui/[manager|nav|views]

and admin endpoints:
conf-times
alert_actions
clusterconfig
commandsconf
conf-deploymentclient
conf-inputs
conf-times
conf-wmi
cooked
datamodel-files
datamodelacceleration
datamodeledit
deploymentserver
eventtypes
fields
fifo
fvtags
indexes
localapps
lookup-table-files
macros
manager
monitor
nav
passwords
pools
quickstart
raw
savedsearch
scheduledviews
script
sourcetypes
ssl
syslog
tcpout-default
tcpout-group
tcpout-server
transforms-extract
transforms-lookup
udp
ui-prefs
views
viewstates
workflow-actions

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi abhayneilam,

As a rule of thumb you can go by: usually anything that affects indexing level changes require a splunk restart, while search level changes require a reload. Here's a good guideline on how to determine which is which.

http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime

So index creation or settings modifications, props.conf time stamp extractions, or transforms.conf indexed field modifications as well as most .conf manual changes will require a restart.

If you make changes with $SPLUNK_HOME/bin/splunk CLI changes or within the UI, it wont require a restart....unless of course you get prompted for a restart

hope this helps ...

cheers, MuS

abhayneilam
Contributor

Thanks a lot for the prompt reply !!

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...