Splunk Enterprise Security

Why do I receive error "Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer?

RihabCH2
Engager

Hello ,

I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .

Please find in the attachment a screenshot of the error.

Thank you very much for your helps.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.

0 Karma

alemarzu
Motivator

Hi there, did you by any chance disable your main (AKA default) index on your indexer ?

0 Karma

RihabCH2
Engager

Hello,
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .

0 Karma

alemarzu
Motivator

Splunk version ?

0 Karma

adonio
Ultra Champion

when you try to start splunk,
what message do you receive on the terminal?

0 Karma

RihabCH2
Engager

Hello,
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...