Splunk Enterprise

Does Splunk need a restart after a change to log.cfg?

splunkemly
New Member

Currently, we have this in /opt/splunkforwarder/etc/log.cfg:

appender.A1.fileName=${SPLUNK_HOME}/var/log/splunk/splunkd.log 

I want to change the logging location to /var/log and wondering if it can be done by doing this:

appender.A1.fileName=/var/log/splunk/splunkd.log

If so, Does splunk need to be restarted after this change to log.cfg?

0 Karma

renjith_nair
Legend

For any manual change in configs, splunk needs a restart

Ref : http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/Enabledebuglogging

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...