Getting Data In

splunk does not start and has indexing disabled

yannK
Splunk Employee
Splunk Employee

After starting splunk stops immediately with

in splunkd.log

12-03-2012 16:16:26.414 -0800 ERROR IndexProcessor - default index disabled - quit!

and on the command line

Validating databases (splunkd validatedb) failed with code '-1'. Please file a case online at http://www.splunk.com/page/submit_issue

Tags (3)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

yannK
Splunk Employee
Splunk Employee

in $SPLUNK_HOME/etc/apps/search/local/indexes.conf I see
[main]
disabled =1

but it comes back if I remove it.

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

I suspect the issue is the one in the answer I posted here, so take a look at this link:

http://splunk-base.splunk.com/answers/23536/moving-indexes-to-a-new-splunk-server

To find the colliding buckets, see this post:

http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing...

yannK
Splunk Employee
Splunk Employee

Great, I had duplicates bucket ids in my main index : defaultdb\db
I remember now, my backup agent did restore indexes the other day, it seems that multiples indexes were merged into one.

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

Prior to the IndexProcessor error, there should be another ERROR that indicates what is wrong with the default index. Can you check your splunkd.log and see if any error's pop up before the disabled message?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...