In general if we make changes in .conf files we need to restart splunk. Suppose splunk is deployed in production environment and if the changes are made in .conf restarting entire splunk might cause a problem. is there any way instead of restarting entire splunk?
HI
You can hit below URL to reload configuration file..
http[s]://[splunkweb hostname]:[splunkweb port]/debug/refresh
If you are working with extractions (props.conf / transform.cong) then below will work.
YOUR_SEARCh | extract reload=true
Happy Splunking
HI
You can hit below URL to reload configuration file..
http[s]://[splunkweb hostname]:[splunkweb port]/debug/refresh
If you are working with extractions (props.conf / transform.cong) then below will work.
YOUR_SEARCh | extract reload=true
Happy Splunking
Hi @kanamarlapudi,
When you make changes to Splunk Enterprise using the configuration files, you might need to restart Splunk Enterprise for the changes to take effect.
When to restart splunkd:
As a general rule, anything that modifies:
Splunk Enterprise changes that do not require a restart
Please check below link for detail information.
http://docs.splunk.com/Documentation/Splunk/6.0/Admin/Configurationfilechangesthatrequirerestart
Happy Splunking
Thank You Kamlesh. It's really helpful.
Hi @kanamarlapudi,
Glad to help you. Please accept the answer to close this question and upvote my comment which helps you.
Happy Splunking
Hi @kanamarlapudi,
Can you please let us know which .conf files you are talking about because some of the .conf files requires restart. For example : if you are removing index from indexes.conf then you need to restart splunk.