I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .
Please find in the attachment a screenshot of the error.
Thank you very much for your helps.
Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.