Splunk Enterprise Security

Why do I receive error "Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer?

Engager

Hello ,

I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .

Please find in the attachment a screenshot of the error.

Thank you very much for your helps.

0 Karma

Splunk Employee
Splunk Employee

Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.

0 Karma

Motivator

Hi there, did you by any chance disable your main (AKA default) index on your indexer ?

0 Karma

Engager

Hello,
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .

0 Karma

Motivator

Splunk version ?

0 Karma

SplunkTrust
SplunkTrust

when you try to start splunk,
what message do you receive on the terminal?

0 Karma

Engager

Hello,
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!