Getting Data In
Highlighted

problem with parsing indexes.conf when creating a new indexer?

Engager

hey, im new to splunk , im doing practice for arch lab, i was creating a index in indexes.conf , once i saved and restarted splunk, i got the following :

Problem parsing indexes.conf: idx=audit Configured path 'volume:primary/audit/db' refers to non-existent volume 'primary'; 1 volumes in config
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit
issue

this indexes.conf on the indexer, (splunk_home$ etc/apps/BaseConf/local/indexes.conf)

0 Karma
Highlighted

Re: problem with parsing indexes.conf when creating a new indexer?

SplunkTrust
SplunkTrust

Hello @eey16,
it looks like you did not specified the volume "primary"
check indexes.conf.spec in /etc/system/README or the docs here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/Indexesconf
i am not providing the exact code here since you mentioned you are preparing for the exam

good luck!

View solution in original post

Highlighted

Re: problem with parsing indexes.conf when creating a new indexer?

Engager

right, i just switched the data base to SPLUNK_DB$

0 Karma