Installation

Restart Splunk Search Head only in single host installation of Splunk Enterprise

adckia
New Member

Hello,
In a test environment, we have a single-host installation of Splunk Enterprise, i.e.
- License Master
- Indexer (single, no cluster)
- Deployment Server
- Search Head (single, no cluster)
- Monitoring Console
all run on the same machine.
The question is: How can we restart the Search Head (in order to have it reload the apps an saved searches from the file system) without stopping the other Splunk processes (in particular, we don't want the Indexer to stop)?
Thanks for any hints.

Tags (1)
0 Karma
1 Solution

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

View solution in original post

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

You can do a debug/refresh which will not stop the Splunk service:

http://localhost:8000/en-US/debug/refresh

However, an App install or particular changes may require a Splunk restart.

0 Karma

adckia
New Member

Thanks for the hint.
Does this also reload an app updated on the file system?

0 Karma

enicholson_splu
Splunk Employee
Splunk Employee

It will reload/refresh config changes. If it is a new App install or upgrade it may need a restart.

0 Karma

adckia
New Member

It works for my current purpose of reloading the alerts.
Thank you very much.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...