Splunk Enterprise Security

Any idea how I can troubleshoot this indexes.conf config?

daniel333
Builder

All,

I have this indexes.conf and added a frozen archive. The path is fully readable and writable by the Splunk user account. But when I add this config stanza the indexer fails to start. Just starting with this so I am curious what area some areas I should check.

alt text

0 Karma

fverdi
Explorer
  • Are you starting Splunk from the shell?
  • Are there any errors presented there?
  • If so, what are you seeing?

Take a look at:
$splunk_home/var/log/splunk/splunkd.log

There are several other log files in that directory that may be worth looking at including crash dumps.

0 Karma

ddrillic
Ultra Champion

What does splunkd.log say?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...