Splunk Enterprise Security

Why do I receive error "Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer?

RihabCH2
Engager

Hello ,

I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .

Please find in the attachment a screenshot of the error.

Thank you very much for your helps.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.

0 Karma

alemarzu
Motivator

Hi there, did you by any chance disable your main (AKA default) index on your indexer ?

0 Karma

RihabCH2
Engager

Hello,
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .

0 Karma

alemarzu
Motivator

Splunk version ?

0 Karma

adonio
Ultra Champion

when you try to start splunk,
what message do you receive on the terminal?

0 Karma

RihabCH2
Engager

Hello,
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...