Splunk Search

do you have to restart Splunk when you've added a custom search command?

piebob
Splunk Employee
Splunk Employee

if i create a custom search command as described in http://www.splunk.com/base/Documentation/latest/SearchReference/Aboutcustomsearchcommands do i have to restart Splunk before it'll work?

Tags (2)
1 Solution

npandith
Explorer

If you are trying to modify the commands.conf file then you no need to restart the splunk. If you are creating a new command then you need to restart the splunk for sure.

View solution in original post

npandith
Explorer

If you are trying to modify the commands.conf file then you no need to restart the splunk. If you are creating a new command then you need to restart the splunk for sure.

Lowell
Super Champion

Using the "getinfo" feature does reduce the need to restart splunk for certain parameter changes. For example, streaming, generating, preop, ... are all determine within the script (which can be changed at any time since splunk launches a new copy for each search). Take a look at splunk.Intersplunk.outputInfo() for more info. This has saved me from having to restart splunk a few times, but your millage may vary.

Genti
Splunk Employee
Splunk Employee

i think the rule of thumb is that if it is a *.conf file that is being edited you need a Splunk restart..(?)

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Not a very accurate rule of thumb. Editing many search-time configurations (regardless of the conf file) does not require a restart of Splunk to take effect. Some do, however, notably savedsearches.conf. I believe that creating a new command in commands.conf requires a restart. However, changing the command script or commands.conf parameters for an existing command do not require a restart.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...