![]() Consult the documentation for each app you are installing. Installing some apps may require a restart.Changing the time zone in the OS of a Splunk Enterprise instance (Splunk Enterprise retrieves its local time zone from the underlying OS at startup).Changes to General settings (e.g., port settings).Changes to general indexer settings (minimum free disk space, default server name, etc.).Turning on or off role-based field filtering.Splunk Enterprise native authentication changes, such as user-to-role mappings.Ĭhanges that affect the system settings or server state require restart, such as:.Changes to existing roles, such as settings for role-based field filters or search filters (see Manage an existing role in Securing the Splunk Platform).LDAP configurations (If you make these changes in Splunk Web you can reload the changes without restarting.).Note: When settings that affect indexing are changed through Splunk Web and the CLI, they do not require restarts and take place immediately.Īny user and role changes made in configuration files require a restart, including: In addition, for information on configuration bundle changes that initiate a restart, see Update common peer configurations and apps in Managing Indexers and Clusters of Indexers. You must restart splunkweb to enable or disable SSL for Splunk Web access.Īs a general rule, restart splunkd after making the following types of changes.įor information on changes to nf settings that necessitate a restart, see Determine which nf changes require restart in Managing Indexers and Clusters of Indexers. ![]() If the changes are part of a deployed app already configured to restart after changes, then the forwarder restarts automatically. If you make a configuration file change to a heavy forwarder, you must restart the forwarder, but you do not need to restart the receiving indexer. See List of configuration files in this manual. For a full list of configuration files and an overview of the area each file covers, ![]() Always check the configuration file or its reference topic to see whether a particular change requires a restart. Whether a change requires a restart depends on a number of factors, and this topic does not provide a definitive authority. This topic provides guidelines to help you determine whether to restart after a change. This is because the instance automatically reloads the changed configurations after such updates. Note: Updates made through Splunk Web, REST API endpoints, or the CLI are less likely to require restarts. When you make changes to a Splunk Enterprise instance by manually editing the configuration files, you might need to restart Splunk Enterprise for the changes to take effect. When to restart Splunk Enterprise after a configuration file change
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |