I ran the upgrade to 5.0 of the Palo app and now Splunk won't start. When I try to start the service I get the below error.
Checking http port : open
Checking mgmt port : open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port : open
Checking configuration... Done.
Checking critical directories... Done
Problem parsing indexes.conf: stanza=flowintegrator Required parameter=homePath not configured
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue
I looked at the indexes.conf and saw that it was missing the paths to the DB's, so I added them, but it didn't make a difference.
The 5.0 version of the app does not have any built in indexes. Indexes were removed in this 5.0 version. Which means you have something left over from a previous version which is messing things up. My recommendation is to remove the app and install fresh. Or at least remove everything from the local directory.