<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Windows Infrastructure: it has error &amp;quot;Key value store must be enabled. Please enable it&amp;quot; in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111334#M14369</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I know you said that you found the similar issue on a *nix system to be a dead end in your case, but this message appears only when the app detects that the App Key Value Store process (mongod) has not started for some reason.&lt;/P&gt;

&lt;P&gt;Can you check to see if the mongod process is running on your system? Also, if you could check mongod.log and post the contents of the log during startup, that would be very helpful in determining next steps.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2015 22:00:25 GMT</pubDate>
    <dc:creator>malmoore</dc:creator>
    <dc:date>2015-08-11T22:00:25Z</dc:date>
    <item>
      <title>Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111329#M14364</link>
      <description>&lt;P&gt;Why am I getting error "Key value store must be enabled. Please enable it" &lt;BR /&gt;
i use waindows server 2012 64 bit and Splunk version 6.2.3&lt;BR /&gt;
I can't find a way to enable it. Please help, Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 08:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111329#M14364</guid>
      <dc:creator>suwakhon</dc:creator>
      <dc:date>2015-07-09T08:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111330#M14365</link>
      <description>&lt;P&gt;What is your license type? Enterprise, Trial, or Free?&lt;/P&gt;

&lt;P&gt;Splunk Free does not allow KV Store, and may be the source of your problem. Otherwise, it is enabled by default.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 12:19:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111330#M14365</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-07-09T12:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111331#M14366</link>
      <description>&lt;P&gt;My license type is Enterprise.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 01:44:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111331#M14366</guid>
      <dc:creator>suwakhon</dc:creator>
      <dc:date>2015-07-10T01:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111332#M14367</link>
      <description>&lt;P&gt;take a look at this answer &lt;A href="http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html"&gt;http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 02:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111332#M14367</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-07-10T02:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111333#M14368</link>
      <description>&lt;P&gt;Experiencing the same problem. Splunk_x64-6.2.4 running on server 2012 with enterprise license. I have read the following articles but all are dead ends so far. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/AboutKVStore"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/AboutKVStore&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html"&gt;http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html&lt;/A&gt; &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/205689/splunk-app-for-windows-infrastructure-how-to-make.html"&gt;http://answers.splunk.com/answers/205689/splunk-app-for-windows-infrastructure-how-to-make.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/203979/splunk-app-for-microsoft-exchange-how-to-get-the-t.html"&gt;http://answers.splunk.com/answers/203979/splunk-app-for-microsoft-exchange-how-to-get-the-t.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 20:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111333#M14368</guid>
      <dc:creator>RichING</dc:creator>
      <dc:date>2015-08-11T20:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111334#M14369</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I know you said that you found the similar issue on a *nix system to be a dead end in your case, but this message appears only when the app detects that the App Key Value Store process (mongod) has not started for some reason.&lt;/P&gt;

&lt;P&gt;Can you check to see if the mongod process is running on your system? Also, if you could check mongod.log and post the contents of the log during startup, that would be very helpful in determining next steps.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 22:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111334#M14369</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-08-11T22:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111335#M14370</link>
      <description>&lt;P&gt;Mongod.exe is not running on the machine nor is any service of a similar name. The log on last restart is below:&lt;/P&gt;

&lt;P&gt;2015-08-11T23:36:36.602Z warning: No SSL certificate validation can be performed since no CA file has been provided; please specify an sslCAFile parameter&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] MongoDB starting : pid=5756 port=8191 dbpath=D:\Splunk\var\lib\splunk/kvstore\mongo 64-bit host=SAC-CORP-SPLKH1&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] targetMinOS: Windows 7/Windows Server 2008 R2&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] db version v2.6.7-splunk&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] git version: 7e66fa196686092ee1c184bd3f8fa1fe640c6550&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] OpenSSL version: OpenSSL 1.0.1m-fips 19 Mar 2015&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] build info: windows sys.getwindowsversion(major=6, minor=1, build=7601, platform=2, service_pack='Service Pack 1') BOOST_LIB_VERSION=1_49&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] allocator: system&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] options: { net: { port: 8191, ssl: { PEMKeyFile: "C:\Program Files\Splunk\etc\auth\server.pem", PEMKeyPassword: "", mode: "preferSSL" } }, replication: { oplogSizeMB: 1000 }, security: { keyFile: "D:\Splunk\var\lib\splunk/kvstore\mongo\splunk.key" }, setParameter: { enableLocalhostAuthBypass: "0" }, storage: { dbPath: "D:\Splunk\var\lib\splunk/kvstore\mongo", smallFiles: true }, systemLog: { timeStampFormat: "iso8601-utc" } }&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;old lock file: D:\Splunk\var\lib\splunk/kvstore\mongo\mongod.lock.  probably means unclean shutdown,&lt;BR /&gt;
 but there are no journal files to recover.&lt;BR /&gt;
 this is likely human error or filesystem corruption.&lt;BR /&gt;
 please make sure that your journal directory is mounted.&lt;BR /&gt;
 found 23 dbs.&lt;BR /&gt;
 see: &lt;A href="http://dochub.mongodb.org/core/repair" target="_blank"&gt;http://dochub.mongodb.org/core/repair&lt;/A&gt; for more information&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;2015-08-11T23:36:36.805Z [initandlisten] exception in initAndListen: 12596 old lock file, terminating&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] dbexit: &lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: going to close listening sockets...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: going to flush diaglog...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: going to close sockets...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: waiting for fs preallocator...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: lock for final commit...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: final commit...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] shutdown: closing all files...&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] closeAllFiles() finished&lt;BR /&gt;
 2015-08-11T23:36:36.805Z [initandlisten] dbexit: really exiting now&lt;/P&gt;

&lt;P&gt;It seems that there is a lock file which is similar to what was mentioned in this article. &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html" target="_blank"&gt;http://answers.splunk.com/answers/206030/splunk-app-for-windows-infrastructure-why-am-i-get-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However, This is a production instance of splunk and OP did say that he did not recommend his fix to be used in production. Also I was unable to locate the specified lock file anywhere in the C:\Program Files\Splunk folder.  Please let me know the best way to proceed. &lt;/P&gt;

&lt;P&gt;Thank You,&lt;BR /&gt;
Rich&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111335#M14370</guid>
      <dc:creator>RichING</dc:creator>
      <dc:date>2020-09-29T06:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111336#M14371</link>
      <description>&lt;P&gt;It's not going to be in C:\Program Files\Splunk unless that is where %SPLUNK_HOME% is. Like that other answer says, mongod (the Key Value Store service) won't run unless the lock file is zero bytes or not there because it thinks that the service is not in a good state. I would shut down Splunk on this instance, back up %SPLUNK_HOME%\var\lib\splunk, then delete the lock file and restart Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111336#M14371</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2020-09-29T06:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111337#M14372</link>
      <description>&lt;P&gt;I was able to locate the mongod.lock file on a different drive. I performed the steps mentioned and removed the lock file (1KB in size). On splunk restart a new one was created that is 0kb. However I am still receiving the  "Key value store must be enabled. Please enable it" in splunk. I re-traced my steps and will paste the mongod.log file below. It appears to me that there is a potential permissions issue with the file. Our splunkd service runs as a local system account. I found some linux articles when searching for the specific errors but nothing that seemed relevant. New log pasted below broken up by steps I had taken.&lt;/P&gt;

&lt;P&gt;2015-08-13T17:40:17.665Z warning: No SSL certificate validation can be performed since no CA file has been provided; please specify an sslCAFile parameter&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] MongoDB starting : pid=1732 port=8191 dbpath=D:\Splunk\var\lib\splunk/kvstore\mongo 64-bit host=SAC-CORP-SPLKH1&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] targetMinOS: Windows 7/Windows Server 2008 R2&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] db version v2.6.7-splunk&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] git version: 7e66fa196686092ee1c184bd3f8fa1fe640c6550&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] OpenSSL version: OpenSSL 1.0.1m-fips 19 Mar 2015&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] build info: windows sys.getwindowsversion(major=6, minor=1, build=7601, platform=2, service_pack='Service Pack 1') BOOST_LIB_VERSION=1_49&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] allocator: system&lt;BR /&gt;
 2015-08-13T17:40:17.949Z [initandlisten] options: { net: { port: 8191, ssl: { PEMKeyFile: "C:\Program Files\Splunk\etc\auth\server.pem", PEMKeyPassword: "", mode: "preferSSL" } }, replication: { oplogSizeMB: 1000 }, security: { keyFile: "D:\Splunk\var\lib\splunk/kvstore\mongo\splunk.key" }, setParameter: { enableLocalhostAuthBypass: "0" }, storage: { dbPath: "D:\Splunk\var\lib\splunk/kvstore\mongo", smallFiles: true }, systemLog: { timeStampFormat: "iso8601-utc" } }&lt;BR /&gt;
 2015-08-13T17:40:17.996Z [initandlisten] journal dir=D:\Splunk\var\lib\splunk/kvstore\mongo\journal&lt;BR /&gt;
 2015-08-13T17:40:17.996Z [initandlisten] recover : no journal files present, no recovery needed&lt;BR /&gt;
 2015-08-13T17:40:18.437Z [initandlisten] info preallocateIsFaster couldn't run due to: couldn't open file D:\Splunk\var\lib\splunk/kvstore\mongo\journal\tempLatencyTest for writing errno:5 Access is denied.; returning false&lt;BR /&gt;
 2015-08-13T17:40:19.004Z [FileAllocator] allocating new datafile D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0, filling with zeroes...&lt;BR /&gt;
 2015-08-13T17:40:19.004Z [FileAllocator] creating directory D:\Splunk\var\lib\splunk/kvstore\mongo_tmp&lt;BR /&gt;
 2015-08-13T17:40:19.004Z [FileAllocator] FileAllocator: couldn't create D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0 (D:\Splunk\var\lib\splunk/kvstore\mongo_tmp\1439487618012241) errno:5 Access is denied.&lt;BR /&gt;
 2015-08-13T17:40:19.004Z [FileAllocator] error: failed to allocate new file: D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0 size: 16777216 .  will try again in 10 seconds&lt;BR /&gt;
 2015-08-13T17:40:29.090Z [initandlisten] Assertion: 12520:new file allocation failure&lt;BR /&gt;
 2015-08-13T17:40:29.201Z [FileAllocator] allocating new datafile D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0, filling with zeroes...&lt;BR /&gt;
 2015-08-13T17:40:29.201Z [FileAllocator] FileAllocator: couldn't create D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0 (D:\Splunk\var\lib\splunk/kvstore\mongo_tmp\1439487618012242) errno:5 Access is denied.&lt;BR /&gt;
 2015-08-13T17:40:29.201Z [FileAllocator] error: failed to allocate new file: D:\Splunk\var\lib\splunk/kvstore\mongo\s_splunkiTR2RCAYp7Go4kZlq1TnMAm9_tSessiV6ysHGNENqOVEZL92qEHLjZQ.0 size: 16777216 .  will try again in 10 seconds&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] exception in initAndListen: 12520 new file allocation failure, terminating&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] dbexit: &lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: going to close listening sockets...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: going to flush diaglog...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: going to close sockets...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: waiting for fs preallocator...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: lock for final commit...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: final commit...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] shutdown: closing all files...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] closeAllFiles() finished&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] journalCleanup...&lt;BR /&gt;
 2015-08-13T17:40:29.295Z [initandlisten] removeJournalFiles&lt;BR /&gt;
 2015-08-13T17:40:29.311Z [initandlisten] shutdown: removing fs lock...&lt;BR /&gt;
 2015-08-13T17:40:29.311Z [initandlisten] dbexit: really exiting now&lt;/P&gt;

&lt;P&gt;---- After another restart of splunkd -----&lt;/P&gt;

&lt;P&gt;2015-08-13T17:50:00.728Z warning: No SSL certificate validation can be performed since no CA file has been provided; please specify an sslCAFile parameter&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] MongoDB starting : pid=6604 port=8191 dbpath=D:\Splunk\var\lib\splunk/kvstore\mongo 64-bit host=SAC-CORP-SPLKH1&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] targetMinOS: Windows 7/Windows Server 2008 R2&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] db version v2.6.7-splunk&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] git version: 7e66fa196686092ee1c184bd3f8fa1fe640c6550&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] OpenSSL version: OpenSSL 1.0.1m-fips 19 Mar 2015&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] build info: windows sys.getwindowsversion(major=6, minor=1, build=7601, platform=2, service_pack='Service Pack 1') BOOST_LIB_VERSION=1_49&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] allocator: system&lt;BR /&gt;
 2015-08-13T17:50:00.932Z [initandlisten] options: { net: { port: 8191, ssl: { PEMKeyFile: "C:\Program Files\Splunk\etc\auth\server.pem", PEMKeyPassword: "", mode: "preferSSL" } }, replication: { oplogSizeMB: 1000 }, security: { keyFile: "D:\Splunk\var\lib\splunk/kvstore\mongo\splunk.key" }, setParameter: { enableLocalhostAuthBypass: "0" }, storage: { dbPath: "D:\Splunk\var\lib\splunk/kvstore\mongo", smallFiles: true }, systemLog: { timeStampFormat: "iso8601-utc" } }&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] exception in initAndListen: 13627 Unable to create/open lock file: D:\Splunk\var\lib\splunk/kvstore\mongo\mongod.lock Access is denied.. Is a mongod instance already running?, terminating&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] dbexit: &lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: going to close listening sockets...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: going to flush diaglog...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: going to close sockets...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: waiting for fs preallocator...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: lock for final commit...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: final commit...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] shutdown: closing all files...&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] closeAllFiles() finished&lt;BR /&gt;
 2015-08-13T17:50:00.963Z [initandlisten] dbexit: really exiting now&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111337#M14372</guid>
      <dc:creator>RichING</dc:creator>
      <dc:date>2020-09-29T06:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111338#M14373</link>
      <description>&lt;P&gt;After working with Splunk Support I was able to resolve this issue. They were not able to reproduce it in the lab. It ended up being an odd permissions issue. I had to stop the splunkd service, go to our Splunk Data directory, right-click -&amp;gt; Properties -&amp;gt;Security -&amp;gt; Advanced, Click on the SYSTEM account -&amp;gt; Change permissions -&amp;gt; Check "Replace all child object permission entries" box. Basically this forced the SYSTEM account to reapply its permissions to all files. I then deleted the Mongod.lock file and _tmp directory in %Splunk_DATA%\var\lib\splunk\kvstore\mongo. Start splunk service&lt;/P&gt;

&lt;P&gt;I am not sure why it happened this way but it is something to try if you are having a similar problem. We have a Splunk 6.0.3 instance that was upgraded to 6.2.4 running on Windows server 2012. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111338#M14373</guid>
      <dc:creator>RichING</dc:creator>
      <dc:date>2020-09-29T07:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111339#M14374</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;

&lt;P&gt;Apologies for the late response. It's been really busy here and I didn't see the updates you had made until now.&lt;/P&gt;

&lt;P&gt;So, I would see what is going on with the D:\ drive. Is it local? Is it a Windows drive formatted as NTFS, or a shared drive off a Linux server? If a Windows drive, then does the "Everyone" group have read permissions? Does the NT AUTHORITY\SYSTEM account have Full Control permissions? Once you fix the permissions issue, the service should start and this message should go away.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 19:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111339#M14374</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-08-20T19:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Windows Infrastructure: it has error "Key value store must be enabled. Please enable it"</title>
      <link>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111340#M14375</link>
      <description>&lt;P&gt;I was experiencing this problem as well and it ended up being a permissions issue on the mongo folder itself.  after reading through these posts as well as the referenced posts I did the following:&lt;/P&gt;

&lt;P&gt;1) stopped splunk process&lt;BR /&gt;
2) right clicked on mongo folder located in C:\Program Files\Splunk\var\lib\splunk\kvstore&lt;BR /&gt;
3) selected security and altered the security permissions for local admin as well system, before exiting I selected the replace child object permissions entries with inheritable permissions entries from this object.&lt;BR /&gt;
4) restarted splunk and my errors went away.&lt;/P&gt;

&lt;P&gt;these steps cleared the error message Key value store must be enabled. Please enable it" and it enabled me to perform a KVStore migrate which i was not able to do before fixing this error.  (KV Store initialization has failed.)&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 18:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-App-for-Windows-Infrastructure-it-has-error-quot-Key/m-p/111340#M14375</guid>
      <dc:creator>mtime24</dc:creator>
      <dc:date>2016-08-16T18:17:28Z</dc:date>
    </item>
  </channel>
</rss>

