Hi!
I have the habit to develope TAs and Splunk Apps right on the Splunk server. You know, 2 screens: Splunk search head web frontend on the left and notepad++ on the right screen where I have props.conf and transforms.conf opened as well as some lookup CSVs. As soon as I make a (search-time!) change in props.conf and transforms.conf I would expect Splunk to use it when I try to search on the web frontend. This has worked flawlessly with Splunk v5.x
Unfortunately this stopped or at the very least started to work very strangely with Splunk v6.x.
I've tried almost all the magic refreshes like: /debug/refresh, |extract reload=t, switching back and forth apps, trying a new search. 2 times out of 10 it works but the vast majority of my tries just seems to be "cached". It does reload the .conf files after a while (usually 1-3 minutes) but as you can imagine this painfully slows down the development of TAs.
Does anyone know a reliable way to reload simple, basic, search time field extractions stored in props.conf and transforms.conf WITHOUT restarting Splunk and which works in Splunk 6?
I'm using Splunk 6.1.4 if it matters but seen this behaviour on all Splunk version since v6.0.
Many thanks,
Tamas
... View more