Deployment Architecture

What is the best way to figure out if a configuration change will require a splunk restart?

muebel
SplunkTrust
SplunkTrust

If I make a change to a view in an app, I can activate that change by reloading the app. If I make a change to the savesearch.conf at the system level, it requires a splunk restart before the change takes effect.

Is there a simple and short way of knowing when a configuration change will go into effect? On reload of a view? On reload of server? etc?

1 Solution

Chris_R_
Splunk Employee
Splunk Employee

The rule of thumb we go by is usually anything that affects indexing level changes require a splunk restart, while search level changes require a reload. Here's a good guideline on how to determine which is which.
http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime

So index creation or settings modifications, props.conf timestamp extractions, or transforms.conf indexed field modifications as well as most .conf manual changes will require a restart.

If you make changes with $SPLUNK_HOME/bin/splunk CLI changes or within the UI, it wont require a restart.(unless of course you get prompted for a restart)

View solution in original post

Chris_R_
Splunk Employee
Splunk Employee

The rule of thumb we go by is usually anything that affects indexing level changes require a splunk restart, while search level changes require a reload. Here's a good guideline on how to determine which is which.
http://www.splunk.com/base/Documentation/latest/admin/Indextimeversussearchtime

So index creation or settings modifications, props.conf timestamp extractions, or transforms.conf indexed field modifications as well as most .conf manual changes will require a restart.

If you make changes with $SPLUNK_HOME/bin/splunk CLI changes or within the UI, it wont require a restart.(unless of course you get prompted for a restart)

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...