<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk does not start and has indexing disabled in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53029#M10231</link>
    <description>&lt;P&gt;Prior to the IndexProcessor error, there should be another ERROR that indicates what is wrong with the default index. Can you check your splunkd.log and see if any error's pop up before the disabled message?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2012 17:43:02 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2012-12-04T17:43:02Z</dc:date>
    <item>
      <title>splunk does not start and has indexing disabled</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53028#M10230</link>
      <description>&lt;P&gt;After starting splunk stops immediately with&lt;/P&gt;

&lt;P&gt;in splunkd.log&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;12-03-2012 16:16:26.414 -0800 ERROR IndexProcessor - default index disabled - quit!&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;and on the command line&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Validating databases (splunkd validatedb) failed with code '-1'. Please file a case online at &lt;A href="http://www.splunk.com/page/submit_issue"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 04 Dec 2012 01:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53028#M10230</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-12-04T01:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: splunk does not start and has indexing disabled</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53029#M10231</link>
      <description>&lt;P&gt;Prior to the IndexProcessor error, there should be another ERROR that indicates what is wrong with the default index. Can you check your splunkd.log and see if any error's pop up before the disabled message?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 17:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53029#M10231</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-12-04T17:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: splunk does not start and has indexing disabled</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53030#M10232</link>
      <description>&lt;P&gt;I suspect the issue is the one in the answer I posted here, so take a look at this link: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/23536/moving-indexes-to-a-new-splunk-server"&gt;http://splunk-base.splunk.com/answers/23536/moving-indexes-to-a-new-splunk-server&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To find the colliding buckets, see this post:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing-conflicts-in-my-index"&gt;http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing-conflicts-in-my-index&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 18:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53030#M10232</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-12-04T18:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: splunk does not start and has indexing disabled</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53031#M10233</link>
      <description>&lt;P&gt;in $SPLUNK_HOME/etc/apps/search/local/indexes.conf I see &lt;BR /&gt;
&lt;CODE&gt;[main] &lt;BR /&gt;
disabled =1&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;but it comes back if I remove it.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 18:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53031#M10233</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-12-04T18:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: splunk does not start and has indexing disabled</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53032#M10234</link>
      <description>&lt;P&gt;Great, I had duplicates bucket ids in my main index : defaultdb\db&lt;BR /&gt;
I remember now, my backup agent did restore indexes the other day, it seems that multiples indexes were merged into one.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2012 18:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-does-not-start-and-has-indexing-disabled/m-p/53032#M10234</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-12-04T18:37:40Z</dc:date>
    </item>
  </channel>
</rss>

