I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .
Please find in the attachment a screenshot of the error.
Thank you very much for your helps.
Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.
Hi there, did you by any chance disable your main (AKA default) index on your indexer ?
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .
Splunk version ?
when you try to start splunk,
what message do you receive on the terminal?
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"