Splunk Search

Reloading Transforms from CLI?

s6a9d6u9s
New Member

"Enable configuration changes made to transforms.conf by typing the following search in Splunk Web: | extract reload=T"

Is it possible to reload transforms.conf from the CLI? Will restarting Splunk do it if there's no CLI extract reload command?

Tags (2)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

This is unnecessary and outdated documentation. transforms.conf is reloaded upon every search. Of course, if you are on an older (3.x or older) version where you need to do this, you can simply run a CLI search with that command.


Update:

If you're making index-time changes, then this doesn't work. Only for search-time configurations take effect immediately. You must generally restart splunkd for index-time changes to take effect. This is true for 4.1.x and earlier. I don't know enough about 4.2 to say for sure if that is the case.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

oh okay. If you're making index-time changes, then no. This is only for search-time configurations. You must generally restart splunkd for index-time changes to take effect. This is true for 4.1.x and earlier. I don't know enough about 4.2 to say for sure if that is the case.

0 Karma

s6a9d6u9s
New Member

i.e. splitting logs from multiple clients/environments into separate indexes like so: http://pastebin.com/J1xGX8RU

0 Karma

s6a9d6u9s
New Member

We are mainly using Transforms.conf to route raw syslog traffic specific indexes based on the source IP. So if we make changes to transforms.conf, incoming logs will immediately start being routed to the correct index too?

We're also having to update props.conf at the same time, maybe this question is moot if changing props.conf requires a restart anyway.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...