Getting Data In

bad index path

jlaigo2
Path Finder

So I added a new index and without thinking I hit submit without changed db info. I restarted and now I can get splunk up as you can see below. Anyone know how to remove an index reference with splunk not running?

root@atpscld1>/opt/splunk/bin/splunk start

Splunk> 4TW

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking configuration... Done.
Checking index directory...
Problem parsing indexes.conf: The homePath "/opt/splunk/var/lib/splunk/defaultdb/db" of index "nms" is repeated multiple times (already specified as homePath of index "main").
Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue
root@atpscld1>

root@atpscld1>/opt/splunk/bin/splunk disable index nms
Splunk is not running, and it must be for this operation. To start splunk, run "splunk start".
root@atpscld1>

0 Karma

gekoner
Communicator

jlaigo2 -
Assuming you have version 4.x or higher and that you are running a single Splunk instance.

1) Go to /opt/splunk/etc/system/local

Windows = $SPLUNK_HOME\etc\system\local

2) EDIT your indexes.conf
You can just delete the lines with the new index name in the brackets
- OR just edit it so it has the correct path - You can look at indexes.conf.example too

   [indexname]
    thawedPath = $SPLUNK_DB/indexname/thaweddb
    homePath = $SPLUNK_DB/indexname/db
    coldPath = $SPLUNK_DB/indexname/colddb

3) Start Splunk

0 Karma

Drainy
Champion

See; http://docs.splunk.com/Documentation/Splunk/latest/admin/indexesconf

You should find your new one in $SPLUNK_HOME/etc/system/local/indexes.conf.
Just open the conf and delete the lines relevant to the faulty index and restart splunk and all should be well again, you can then add it via the conf file (as per the link) or have another go through the UI 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...