I made an edit to linebreaking in props.conf, then used the CLI "splunk add oneshot " to index a file, saw that new events were indexed, but still according to the old line-breaking scheme. After a splunk restart and another "add oneshot", the new linebreaking scheme was honored. Is a restart each time the only way to incorporate edits to props.conf?
... View more