Getting Data In

moving index to one server

gudavasr
Path Finder

I have indexes on two servers and moved index to one server:
I followed the followind guidelines:
http://splunk-base.splunk.com/answers/10184/consolidate-databases-from-multiple-splunk-instances
and
http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing...

but I still get this error:
IndexProcessor - received eve
IndexProcessor - received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::wspra99a0546' sourcetype='sourcetype::audittrail' (1 missing total)

nt for unconfigured/disabled index='_internal' with source='source::/opt/local/qosmont/splunk_search_head_02_sit/var/log/splunk/splunkd.log' host='host::wspra99a0546' sourcetype='sourcetype::splunkd' (2 missing total)

How can I fix these?

Thank You.

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi gudavasr

check if those indexes are disabled:

| rest /services/data/indexes | table title disabled

if so you can enable them in 'Manager >> Indexes'
probably it is also possible via REST but I haven't checked on that yet 😉

cheers,
MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi gudavasr

check if those indexes are disabled:

| rest /services/data/indexes | table title disabled

if so you can enable them in 'Manager >> Indexes'
probably it is also possible via REST but I haven't checked on that yet 😉

cheers,
MuS

gudavasr
Path Finder

This worked. Can you explain why indexes automatically got enabled when it is restarted?
Thank You

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...