Splunk Enterprise Security

Any idea how I can troubleshoot this indexes.conf config?

daniel333
Builder

All,

I have this indexes.conf and added a frozen archive. The path is fully readable and writable by the Splunk user account. But when I add this config stanza the indexer fails to start. Just starting with this so I am curious what area some areas I should check.

alt text

0 Karma

fverdi
Explorer
  • Are you starting Splunk from the shell?
  • Are there any errors presented there?
  • If so, what are you seeing?

Take a look at:
$splunk_home/var/log/splunk/splunkd.log

There are several other log files in that directory that may be worth looking at including crash dumps.

0 Karma

ddrillic
Ultra Champion

What does splunkd.log say?

0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...