Getting Data In

Why do I get "Unable to remove disabled indexes.." when trying to delete an index, but then get "deleted, cannot enable.." when I try to enable it?

jflaherty
Path Finder

Hello,

I was having a problem with an index created by an app, so I manually created one as a test. I went to delete the index with the splunk remove index command. It says "Unable to remove disabled indexes.." I go to enable the index so I can delete it and it says "deleted, cannot enable..". I am caught in a loop. I cannot find the index in indexes.conf anywhere. Looks like the indexes.conf files have not been modified in some time. I am not sure how to remove this index and I really need the index name for the app to work.

Please help.

Thanks
-Josh

0 Karma
1 Solution

jflaherty
Path Finder

I determined that there it was an indexes.conf file under the appname\default directory that still had the index. I did not find it earlier because when i did search for indexes.conf under the root, my account did not have permission to that folder. I removed the index there and it is no longer showing up.

Thanks.

View solution in original post

0 Karma

jflaherty
Path Finder

I determined that there it was an indexes.conf file under the appname\default directory that still had the index. I did not find it earlier because when i did search for indexes.conf under the root, my account did not have permission to that folder. I removed the index there and it is no longer showing up.

Thanks.

0 Karma

gyslainlatsa
Motivator

hi,

1. there are `default index` in splunk that you can not remove or disabled.

2. there are also some `index-related `applications you installed in splunk. these indexes can not be disabled or deleted

I think you must have a problem in connection with the second case mentioned above.

please forgive my english.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...