<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: All Splunk internal indexes were disabled with red lock icons in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549619#M5696</link>
    <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For disk usage:&lt;/P&gt;&lt;P&gt;/dev/sda1 used around 11% only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the screen capture for the index like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coweatgrass14_0-1619616744198.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13947i987A4B3FB09E7E9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coweatgrass14_0-1619616744198.png" alt="coweatgrass14_0-1619616744198.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to read the error log message but there are tone of lines.... and failed to find useful error log....&lt;/P&gt;</description>
    <pubDate>Wed, 28 Apr 2021 13:35:08 GMT</pubDate>
    <dc:creator>coweatgrass14</dc:creator>
    <dc:date>2021-04-28T13:35:08Z</dc:date>
    <item>
      <title>All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549308#M5675</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;All of the internal indexes of Splunk,&amp;nbsp;(_audit, _internal, _introspection, _metrics, _telemetry, _thefishbucket and splunklogger) were disabled with&amp;nbsp; red lock icons.&lt;/P&gt;&lt;P&gt;I have tried:&lt;/P&gt;&lt;P&gt;1) restart the splunkd;&lt;/P&gt;&lt;P&gt;2) followed the method in the following link (delete the entire _audit folder but no luck)&lt;BR /&gt;URL:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Archive/audit-index-remains-disabled/m-p/98864" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Archive/audit-index-remains-disabled/m-p/98864&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Please help me.&amp;nbsp; Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 08:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549308#M5675</guid>
      <dc:creator>coweatgrass14</dc:creator>
      <dc:date>2021-04-26T08:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549311#M5676</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233822"&gt;@coweatgrass14&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can your share the message error?&lt;/P&gt;&lt;P&gt;if possible you have low space on your splunk partition?&lt;/P&gt;&lt;P&gt;let me know&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 08:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549311#M5676</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-26T08:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549619#M5696</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For disk usage:&lt;/P&gt;&lt;P&gt;/dev/sda1 used around 11% only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the screen capture for the index like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="coweatgrass14_0-1619616744198.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13947i987A4B3FB09E7E9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="coweatgrass14_0-1619616744198.png" alt="coweatgrass14_0-1619616744198.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to read the error log message but there are tone of lines.... and failed to find useful error log....&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 13:35:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549619#M5696</guid>
      <dc:creator>coweatgrass14</dc:creator>
      <dc:date>2021-04-28T13:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549654#M5697</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233822"&gt;@coweatgrass14&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;looks like disabled, can you check this conf file?&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/default/indexes.conf&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf&lt;/P&gt;&lt;P&gt;check if the indexes are disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 15:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549654#M5697</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-28T15:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549804#M5701</link>
      <description>&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf&lt;/P&gt;&lt;P&gt;(I tried to rename the indexes.conf to o_indexes.conf and restart the splunk )&lt;BR /&gt;&lt;BR /&gt;In addition, I try to upgrade to latest version of splunk and still no luck. &amp;lt;&amp;gt;_&amp;lt;&amp;gt;&lt;/P&gt;&lt;P&gt;[_audit]&lt;BR /&gt;archiver.enableDataArchive = 0&lt;BR /&gt;bucketRebuildMemoryHint = 0&lt;BR /&gt;compressRawdata = 1&lt;BR /&gt;enableDataIntegrityControl = 0&lt;BR /&gt;enableOnlineBucketRepair = 1&lt;BR /&gt;enableTsidxReduction = 0&lt;BR /&gt;metric.enableFloatingPointCompression = 1&lt;BR /&gt;minHotIdleSecsBeforeForceRoll = 0&lt;BR /&gt;rtRouterQueueSize =&lt;BR /&gt;rtRouterThreads =&lt;BR /&gt;selfStorageThreads =&lt;BR /&gt;suspendHotRollByDeleteQuery = 0&lt;BR /&gt;syncMeta = 1&lt;BR /&gt;tsidxWritingLevel =&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/default/indexes.conf contents:&lt;BR /&gt;( this file last modified havent been modified since 2 years ago)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 # Version 8.0.0&lt;BR /&gt;2 # DO NOT EDIT THIS FILE!&lt;BR /&gt;3 # Changes to default files will be lost on update and are difficult to&lt;BR /&gt;4 # manage and support.&lt;BR /&gt;5 #&lt;BR /&gt;6 # Please make any changes to system defaults by overriding them in&lt;BR /&gt;7 # apps or $SPLUNK_HOME/etc/system/local&lt;BR /&gt;8 # (See "Configuration file precedence" in the web documentation).&lt;BR /&gt;9 #&lt;BR /&gt;10 # To override a specific setting, copy the name of the stanza and&lt;BR /&gt;11 # setting to the file where you wish to override it.&lt;BR /&gt;12 #&lt;BR /&gt;13 # This file configures Splunk's indexes and their properties.&lt;BR /&gt;14 #&lt;BR /&gt;15&lt;BR /&gt;16 ################################################################################&lt;BR /&gt;17 # "global" params (not specific to individual indexes)&lt;BR /&gt;18 ################################################################################&lt;BR /&gt;19 sync = 0&lt;BR /&gt;20 indexThreads = auto&lt;BR /&gt;21 memPoolMB = auto&lt;BR /&gt;22 defaultDatabase = main&lt;BR /&gt;23 enableRealtimeSearch = true&lt;BR /&gt;24 suppressBannerList =&lt;BR /&gt;25 maxRunningProcessGroups = 8&lt;BR /&gt;26 maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;27 bucketRebuildMemoryHint = auto&lt;BR /&gt;28 serviceOnlyAsNeeded = true&lt;BR /&gt;29 serviceSubtaskTimingPeriod = 30&lt;BR /&gt;30 serviceInactiveIndexesPeriod = 60&lt;BR /&gt;31 maxBucketSizeCacheEntries = 0&lt;BR /&gt;32 processTrackerServiceInterval = 1&lt;BR /&gt;33 hotBucketTimeRefreshInterval = 10&lt;BR /&gt;34 rtRouterThreads = 0&lt;BR /&gt;35 rtRouterQueueSize = 10000&lt;BR /&gt;36 selfStorageThreads = 2&lt;BR /&gt;37 fileSystemExecutorWorkers = 5&lt;BR /&gt;38&lt;BR /&gt;39 ################################################################################&lt;BR /&gt;40 # index specific defaults&lt;BR /&gt;41 ################################################################################&lt;BR /&gt;42 maxDataSize = auto&lt;BR /&gt;43 maxWarmDBCount = 300&lt;BR /&gt;44 frozenTimePeriodInSecs = 188697600&lt;BR /&gt;45 rotatePeriodInSecs = 60&lt;BR /&gt;46 coldToFrozenScript =&lt;BR /&gt;47 coldToFrozenDir =&lt;BR /&gt;48 compressRawdata = true&lt;BR /&gt;49 maxTotalDataSizeMB = 500000&lt;BR /&gt;50 maxGlobalRawDataSizeMB = 0&lt;BR /&gt;51 maxGlobalDataSizeMB = 0&lt;BR /&gt;52 maxMemMB = 5&lt;BR /&gt;53 maxConcurrentOptimizes = 6&lt;BR /&gt;54 maxHotSpanSecs = 7776000&lt;BR /&gt;55 maxHotIdleSecs = 0&lt;BR /&gt;56 maxHotBuckets = 3&lt;BR /&gt;57 minHotIdleSecsBeforeForceRoll = auto&lt;BR /&gt;58 quarantinePastSecs = 77760000&lt;BR /&gt;59 quarantineFutureSecs = 2592000&lt;BR /&gt;60 rawChunkSizeBytes = 131072&lt;BR /&gt;61 minRawFileSyncSecs = disable&lt;BR /&gt;62 assureUTF8 = false&lt;BR /&gt;63 serviceMetaPeriod = 25&lt;BR /&gt;64 partialServiceMetaPeriod = 0&lt;BR /&gt;65 throttleCheckPeriod = 15&lt;BR /&gt;66 syncMeta = true&lt;BR /&gt;67 maxMetaEntries = 1000000&lt;BR /&gt;68 maxBloomBackfillBucketAge = 30d&lt;BR /&gt;69 enableOnlineBucketRepair = true&lt;BR /&gt;70 enableDataIntegrityControl = false&lt;BR /&gt;71 maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;72 maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;73 minStreamGroupQueueSize = 2000&lt;BR /&gt;74 warmToColdScript=&lt;BR /&gt;75 tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;76 homePath.maxDataSizeMB = 0&lt;BR /&gt;77 coldPath.maxDataSizeMB = 0&lt;BR /&gt;78 streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;79 journalCompression = gzip&lt;BR /&gt;80 enableTsidxReduction = false&lt;BR /&gt;81 suspendHotRollByDeleteQuery = false&lt;BR /&gt;82 tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;83 timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;84 datatype = event&lt;BR /&gt;85 splitByIndexKeys =&lt;BR /&gt;86 tsidxWritingLevel = 1&lt;BR /&gt;87 archiver.enableDataArchive = false&lt;BR /&gt;88 archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;89 tsidxTargetSizeMB = 1500&lt;BR /&gt;90 metric.tsidxTargetSizeMB = 1500&lt;BR /&gt;91 metric.enableFloatingPointCompression = true&lt;BR /&gt;92 metric.compressionBlockSize = 1024&lt;BR /&gt;93&lt;BR /&gt;94 #&lt;BR /&gt;95 # By default none of the indexes are replicated.&lt;BR /&gt;96 #&lt;BR /&gt;97 repFactor = 0&lt;BR /&gt;98&lt;BR /&gt;99 [volume:_splunk_summaries]&lt;BR /&gt;100 path = $SPLUNK_DB&lt;BR /&gt;101&lt;BR /&gt;102 [provider-family:hadoop]&lt;BR /&gt;103 vix.mode = report&lt;BR /&gt;104 vix.command = $SPLUNK_HOME/bin/jars/sudobash&lt;BR /&gt;105 vix.command.arg.1 = $HADOOP_HOME/bin/hadoop&lt;BR /&gt;106 vix.command.arg.2 = jar&lt;BR /&gt;107 vix.command.arg.3 = $SPLUNK_HOME/bin/jars/SplunkMR-h1.jar&lt;BR /&gt;108 vix.command.arg.4 = com.splunk.mr.SplunkMR&lt;BR /&gt;109 vix.env.MAPREDUCE_USER =&lt;BR /&gt;110 vix.env.HADOOP_HEAPSIZE = 512&lt;BR /&gt;111 vix.env.HADOOP_CLIENT_OPTS = -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;112 vix.env.HUNK_THIRDPARTY_JARS = $SPLUNK_HOME/bin/jars/thirdparty/common/avro-1.7.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/a&lt;BR /&gt;113 vix.mapred.job.reuse.jvm.num.tasks = 100&lt;BR /&gt;114 vix.mapred.child.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;115 vix.mapred.reduce.tasks = 0&lt;BR /&gt;116 vix.mapred.job.map.memory.mb = 2048&lt;BR /&gt;117 vix.mapred.job.reduce.memory.mb = 512&lt;BR /&gt;118 vix.mapred.job.queue.name = default&lt;BR /&gt;119 vix.mapreduce.job.jvm.numtasks = 100&lt;BR /&gt;120 vix.mapreduce.map.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;121 vix.mapreduce.reduce.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;122 vix.mapreduce.job.reduces = 0&lt;BR /&gt;123 vix.mapreduce.map.memory.mb = 2048&lt;BR /&gt;124 vix.mapreduce.reduce.memory.mb = 512&lt;BR /&gt;125 vix.mapreduce.job.queuename = default&lt;BR /&gt;126 vix.splunk.search.column.filter = 1&lt;BR /&gt;127 vix.splunk.search.mixedmode = 1&lt;BR /&gt;128 vix.splunk.search.debug = 0&lt;BR /&gt;129 vix.splunk.search.mr.maxsplits = 10000&lt;BR /&gt;130 vix.splunk.search.mr.minsplits = 100&lt;BR /&gt;131 vix.splunk.search.mr.splits.multiplier = 10&lt;BR /&gt;132 vix.splunk.search.mr.poll = 2000&lt;BR /&gt;133 vix.splunk.search.recordreader = SplunkJournalRecordReader,ValueAvroRecordReader,SimpleCSVRecordReader,SequenceFileRecordReader&lt;BR /&gt;134 vix.splunk.search.recordreader.avro.regex = \.avro$&lt;BR /&gt;135 vix.splunk.search.recordreader.csv.regex = \.([tc]sv)(?:\.(?:gz|bz2|snappy))?$&lt;BR /&gt;136 vix.splunk.search.recordreader.sequence.regex = \.seq$&lt;BR /&gt;137 vix.splunk.home.datanode = /tmp/splunk/$SPLUNK_SERVER_NAME/&lt;BR /&gt;138 vix.splunk.heartbeat = 1&lt;BR /&gt;139 vix.splunk.heartbeat.threshold = 60&lt;BR /&gt;140 vix.splunk.heartbeat.interval = 1000&lt;BR /&gt;141 vix.splunk.setup.onsearch = 1&lt;BR /&gt;142 vix.splunk.setup.package = current&lt;BR /&gt;143&lt;BR /&gt;144 ################################################################################&lt;BR /&gt;145 # index definitions&lt;BR /&gt;146 ################################################################################&lt;BR /&gt;147&lt;BR /&gt;148 [main]&lt;BR /&gt;149 homePath = $SPLUNK_DB/defaultdb/db&lt;BR /&gt;150 coldPath = $SPLUNK_DB/defaultdb/colddb&lt;BR /&gt;151 thawedPath = $SPLUNK_DB/defaultdb/thaweddb&lt;BR /&gt;152 tstatsHomePath = volume:_splunk_summaries/defaultdb/datamodel_summary&lt;BR /&gt;153 maxMemMB = 20&lt;BR /&gt;154 maxConcurrentOptimizes = 6&lt;BR /&gt;155 maxHotIdleSecs = 86400&lt;BR /&gt;156 maxHotBuckets = 10&lt;BR /&gt;157 maxDataSize = auto_high_volume&lt;BR /&gt;158&lt;BR /&gt;159 [history]&lt;BR /&gt;160 homePath = $SPLUNK_DB/historydb/db&lt;BR /&gt;161 coldPath = $SPLUNK_DB/historydb/colddb&lt;BR /&gt;162 thawedPath = $SPLUNK_DB/historydb/thaweddb&lt;BR /&gt;163 tstatsHomePath = volume:_splunk_summaries/historydb/datamodel_summary&lt;BR /&gt;164 maxDataSize = 10&lt;BR /&gt;165 frozenTimePeriodInSecs = 604800&lt;BR /&gt;166&lt;BR /&gt;167 [summary]&lt;BR /&gt;168 homePath = $SPLUNK_DB/summarydb/db&lt;BR /&gt;169 coldPath = $SPLUNK_DB/summarydb/colddb&lt;BR /&gt;170 thawedPath = $SPLUNK_DB/summarydb/thaweddb&lt;BR /&gt;171 tstatsHomePath = volume:_splunk_summaries/summarydb/datamodel_summary&lt;BR /&gt;172&lt;BR /&gt;173 [_internal]&lt;BR /&gt;174 homePath = $SPLUNK_DB/_internaldb/db&lt;BR /&gt;175 coldPath = $SPLUNK_DB/_internaldb/colddb&lt;BR /&gt;176 thawedPath = $SPLUNK_DB/_internaldb/thaweddb&lt;BR /&gt;177 tstatsHomePath = volume:_splunk_summaries/_internaldb/datamodel_summary&lt;BR /&gt;178 maxDataSize = 1000&lt;BR /&gt;179 maxHotSpanSecs = 432000&lt;BR /&gt;180 frozenTimePeriodInSecs = 2592000&lt;BR /&gt;181&lt;BR /&gt;182 [_audit]&lt;BR /&gt;183 homePath = $SPLUNK_DB/audit/db&lt;BR /&gt;184 coldPath = $SPLUNK_DB/audit/colddb&lt;BR /&gt;185 thawedPath = $SPLUNK_DB/audit/thaweddb&lt;BR /&gt;186 tstatsHomePath = volume:_splunk_summaries/audit/datamodel_summary&lt;BR /&gt;187&lt;BR /&gt;188 [_thefishbucket]&lt;BR /&gt;189 homePath = $SPLUNK_DB/fishbucket/db&lt;BR /&gt;190 coldPath = $SPLUNK_DB/fishbucket/colddb&lt;BR /&gt;191 thawedPath = $SPLUNK_DB/fishbucket/thaweddb&lt;BR /&gt;192 tstatsHomePath = volume:_splunk_summaries/fishbucket/datamodel_summary&lt;BR /&gt;193 maxDataSize = 500&lt;BR /&gt;194 frozenTimePeriodInSecs = 2419200&lt;BR /&gt;195&lt;BR /&gt;196 # this index has been removed in the 4.1 series, but this stanza must be&lt;BR /&gt;197 # preserved to avoid displaying errors for users that have tweaked the index's&lt;BR /&gt;198 # size/etc parameters in local/indexes.conf.&lt;BR /&gt;199 #&lt;BR /&gt;200 [splunklogger]&lt;BR /&gt;201 homePath = $SPLUNK_DB/splunklogger/db&lt;BR /&gt;202 coldPath = $SPLUNK_DB/splunklogger/colddb&lt;BR /&gt;203 thawedPath = $SPLUNK_DB/splunklogger/thaweddb&lt;BR /&gt;204 disabled = true&lt;BR /&gt;205&lt;BR /&gt;206 [_introspection]&lt;BR /&gt;207 homePath = $SPLUNK_DB/_introspection/db&lt;BR /&gt;208 coldPath = $SPLUNK_DB/_introspection/colddb&lt;BR /&gt;209 thawedPath = $SPLUNK_DB/_introspection/thaweddb&lt;BR /&gt;210 maxDataSize = 1024&lt;BR /&gt;211 frozenTimePeriodInSecs = 1209600&lt;BR /&gt;212&lt;BR /&gt;213 [_telemetry]&lt;BR /&gt;214 homePath = $SPLUNK_DB/_telemetry/db&lt;BR /&gt;215 coldPath = $SPLUNK_DB/_telemetry/colddb&lt;BR /&gt;216 thawedPath = $SPLUNK_DB/_telemetry/thaweddb&lt;BR /&gt;217 maxDataSize = 256&lt;BR /&gt;218 frozenTimePeriodInSecs = 63072000&lt;BR /&gt;219&lt;BR /&gt;220 [_metrics]&lt;BR /&gt;221 homePath = $SPLUNK_DB/_metrics/db&lt;BR /&gt;222 coldPath = $SPLUNK_DB/_metrics/colddb&lt;BR /&gt;223 thawedPath = $SPLUNK_DB/_metrics/thaweddb&lt;BR /&gt;224 datatype = metric&lt;BR /&gt;225 #14 day retention&lt;BR /&gt;226 frozenTimePeriodInSecs = 1209600&lt;BR /&gt;227 splitByIndexKeys = metric_name&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 10:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549804#M5701</guid>
      <dc:creator>coweatgrass14</dc:creator>
      <dc:date>2021-04-29T10:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549810#M5702</link>
      <description>&lt;P&gt;I found the only one system index ( summary is working, others are disabled )&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="螢幕截圖 2021-04-29 下午6.45.41.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13973iB58E44A7258BCA9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="螢幕截圖 2021-04-29 下午6.45.41.png" alt="螢幕截圖 2021-04-29 下午6.45.41.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 10:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/549810#M5702</guid>
      <dc:creator>coweatgrass14</dc:creator>
      <dc:date>2021-04-29T10:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: All Splunk internal indexes were disabled with red lock icons</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/759250#M23984</link>
      <description>&lt;P&gt;Old topic but ... did you have ITSI deployed on that Search Head ?&lt;/P&gt;
&lt;P&gt;ITSI seems to lock all access to internal indexes for being searched &lt;span class="lia-unicode-emoji" title=":flushed_face:"&gt;😳&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 15:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/All-Splunk-internal-indexes-were-disabled-with-red-lock-icons/m-p/759250#M23984</guid>
      <dc:creator>ldongradi_SPL</dc:creator>
      <dc:date>2026-03-12T15:00:25Z</dc:date>
    </item>
  </channel>
</rss>

