Hi to all - short question:
Do changes to the props.conf really require a restart of splunk?
Is there a way to apply the changes without restarting?
Yes. Per the documentation:
http://www.splunk.com/base/Documentation/latest/admin/Propsconf
To use one or more of these configurations, copy the configuration block into
props.conf in $SPLUNK_HOME/etc/system/local/. You must restart Splunk to enable configurations.
Yes. Per the documentation:
http://www.splunk.com/base/Documentation/latest/admin/Propsconf
To use one or more of these configurations, copy the configuration block into
props.conf in $SPLUNK_HOME/etc/system/local/. You must restart Splunk to enable configurations.
+1 to @Masa. This applies to props.conf changes in the user scope (e.g. etc/users/myusername/search/local/props.conf)
Most of the case, Yes.
However, Search time field extraction via props.conf, (and transforms.conf) does not require restarting Splunk.