All,
I have this indexes.conf and added a frozen archive. The path is fully readable and writable by the Splunk user account. But when I add this config stanza the indexer fails to start. Just starting with this so I am curious what area some areas I should check.
Take a look at:
$splunk_home/var/log/splunk/splunkd.log
There are several other log files in that directory that may be worth looking at including crash dumps.
What does splunkd.log
say?