We have a long search running, and need to restart Splunk. Will a job that is "paused" be able to be restarted after a restart of Splunk?
I tested it briefly and the search (histogram, fields) reappears, but the events do not, and no more events are added to the search, even though it looks like it's running.
i checked with one of the search engineers and it's not supposed to be possible to restart a paused search across a restart of Splunk.
View solution in original post
that said, the UI shouldn't make it look as though you can, so i'll be harassing some folks about that 🙂