Splunk Search

Updating eventgen.conf requires a Splunk restart

newportknight
Loves-to-Learn

Hi,

I am playing around with SA-Eventgen to generate data in a Dev environment but I find if I make a change to the eventgen.conf file I have to restart Splunk for it to take effect. (All I am doing is changing the date/time format)

Is there any other way to to make the change effective without having to carry out a restart? I have tried disabling and re-enabling via the Data input and also disabling and re-enabling the app itself but neither have the desired outcome.

Appreciate any help.

Cheers.

Paul.

Tags (1)
0 Karma

newportknight
Loves-to-Learn

Hi,

Thanks for replying.

I've tried using the URL suggested but it doesn't appear to have any effect.
There are no errors showing when I carry out a search using index="_internal" sourcetype="eventgen*"

Cheers.

Paul.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@newportknight

Is that any Errors in eventgen logs? Please execute below search for the eventgen log if you can found anything helpful.

index="_internal" sourcetype="eventgen*"
0 Karma

zahrasidhpuri
Engager

Hey Paul,
You can try doing this: http[s]://[splunkweb hostname]:[splunkweb port]/debug/refresh

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...