Splunk Enterprise Security

Why do I receive error "Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer?

Engager

Hello ,

I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .

Please find in the attachment a screenshot of the error.

Thank you very much for your helps.

0 Karma

Splunk Employee
Splunk Employee

Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.

0 Karma

Motivator

Hi there, did you by any chance disable your main (AKA default) index on your indexer ?

0 Karma

Engager

Hello,
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .

0 Karma

Motivator

Splunk version ?

0 Karma

SplunkTrust
SplunkTrust

when you try to start splunk,
what message do you receive on the terminal?

0 Karma

Engager

Hello,
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"

0 Karma