Splunk Enterprise Security

Why do I receive error "Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer?

RihabCH2
Engager

Hello ,

I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I get suddenly this error message on the indexer and it's stopped "Problem parsing indexes.conf: default index disabled - quit! Validating databases (splunkd validatedb) failed with code '1'. Please file a case online at http://www.splunk.com/page/submit_issue" .

Please find in the attachment a screenshot of the error.

Thank you very much for your helps.

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

Hello, from your screenshot, you probably copied one window index to a new one and forgot to change the thawed path.
-> doesn't make sense, correct the path and it will happily start again.

0 Karma

alemarzu
Motivator

Hi there, did you by any chance disable your main (AKA default) index on your indexer ?

0 Karma

RihabCH2
Engager

Hello,
No , I don't disable the default main index.
Please there is any recommandations to solve this problem?
Thank you very much .

0 Karma

alemarzu
Motivator

Splunk version ?

0 Karma

adonio
Ultra Champion

when you try to start splunk,
what message do you receive on the terminal?

0 Karma

RihabCH2
Engager

Hello,
I try to start splunk but always is failed with this error message:"Problem in indexer : Problem parsing indexes.conf: default index disabled - quit!" on the indexer"

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...