Getting Data In

Why do I get "Unable to remove disabled indexes.." when trying to delete an index, but then get "deleted, cannot enable.." when I try to enable it?

jflaherty
Path Finder

Hello,

I was having a problem with an index created by an app, so I manually created one as a test. I went to delete the index with the splunk remove index command. It says "Unable to remove disabled indexes.." I go to enable the index so I can delete it and it says "deleted, cannot enable..". I am caught in a loop. I cannot find the index in indexes.conf anywhere. Looks like the indexes.conf files have not been modified in some time. I am not sure how to remove this index and I really need the index name for the app to work.

Please help.

Thanks
-Josh

0 Karma
1 Solution

jflaherty
Path Finder

I determined that there it was an indexes.conf file under the appname\default directory that still had the index. I did not find it earlier because when i did search for indexes.conf under the root, my account did not have permission to that folder. I removed the index there and it is no longer showing up.

Thanks.

View solution in original post

0 Karma

jflaherty
Path Finder

I determined that there it was an indexes.conf file under the appname\default directory that still had the index. I did not find it earlier because when i did search for indexes.conf under the root, my account did not have permission to that folder. I removed the index there and it is no longer showing up.

Thanks.

0 Karma

gyslainlatsa
Motivator

hi,

1. there are `default index` in splunk that you can not remove or disabled.

2. there are also some `index-related `applications you installed in splunk. these indexes can not be disabled or deleted

I think you must have a problem in connection with the second case mentioned above.

please forgive my english.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...