<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KV store initiation failure, in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645158#M16469</link>
    <description>&lt;P&gt;2021-05-29T18:15:03.594Z I CONTROL [initandlisten] ** WARNING: No SSL certificate validation can be performed since no CA file has been provided 2021-05-29T18:15:03.594Z I CONTROL [initandlisten] ** Please specify an sslCAFile parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for the reply what do you think is this the problem it seems to be that the Mongo database that is the key Value Store does not have a valid certificate and cannot access the application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 21:32:30 GMT</pubDate>
    <dc:creator>Quantum</dc:creator>
    <dc:date>2023-05-30T21:32:30Z</dc:date>
    <item>
      <title>KV store initiation failure-what log is the most relevant for this kind of error?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645151#M16466</link>
      <description>&lt;P&gt;&lt;SPAN&gt;KV&amp;nbsp; store initiation failure, I have got this area that says&amp;nbsp; &amp;nbsp; &amp;nbsp;......"error in input lookup command external command-based lookup es notable events is not available because KV store initialization has failed contact your system administrator,"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;what log is the most relevant for this kind of error would it be the mongodb log and look for a lock? is that a good route to go?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am a pretty good engineer but new to Splunk and definitely could use some guidance on just about everything Splunk related.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 14:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645151#M16466</guid>
      <dc:creator>Quantum</dc:creator>
      <dc:date>2023-05-31T14:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: KV store initiation failure,</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645154#M16467</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you should look both mongodb.log and splunkd.log. You could search those from _internal index with sourcetype mongod or splunkd with host=&amp;lt;your host&amp;gt; source=*/&amp;lt;log file name&amp;gt;. Or look those from file /opt/splunk/var/log/splunk/….&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 20:51:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645154#M16467</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-05-30T20:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: KV store initiation failure,</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645157#M16468</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yeah it looks like it might be expired certificate I am getting that definitely in the Mongo log&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 21:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645157#M16468</guid>
      <dc:creator>Quantum</dc:creator>
      <dc:date>2023-05-30T21:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: KV store initiation failure,</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645158#M16469</link>
      <description>&lt;P&gt;2021-05-29T18:15:03.594Z I CONTROL [initandlisten] ** WARNING: No SSL certificate validation can be performed since no CA file has been provided 2021-05-29T18:15:03.594Z I CONTROL [initandlisten] ** Please specify an sslCAFile parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for the reply what do you think is this the problem it seems to be that the Mongo database that is the key Value Store does not have a valid certificate and cannot access the application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 21:32:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645158#M16469</guid>
      <dc:creator>Quantum</dc:creator>
      <dc:date>2023-05-30T21:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: KV store initiation failure,</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645160#M16470</link>
      <description>&lt;P&gt;05-30-2023 16:58:19.978 -0400 ERROR ExecProcessor [4245 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" Exception in thread "main" java.lang.ExceptionInInitializerError 05-30-2023 16:58:19.978 -0400 ERROR ExecProcessor [4245 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" at com.splunk.dbx.splunkclient.SplunkServiceBuilder.&amp;lt;clinit&amp;gt;(SplunkServiceBuilder.java:19)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/splunk_app_&lt;STRONG&gt;&lt;EM&gt;db_connect/&lt;/EM&gt;&lt;/STRONG&gt;linux_x86_64/bin/dbxquery.sh"&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 21:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645160#M16470</guid>
      <dc:creator>Quantum</dc:creator>
      <dc:date>2023-05-30T21:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: KV store initiation failure,</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645202#M16473</link>
      <description>&lt;P&gt;Quite probably this was the reason. I suppose that you have already found how to fix it? If you are using Splunk's own certs then this describes how to fix it&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701" target="_blank"&gt;https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701&lt;/A&gt;. If you have own / public certs then do renew process as normally.&lt;/P&gt;&lt;P&gt;If you have changed to another CA than Splunk, then check from conf files that CA etc. files are pointed to correct places. There are couple of settings and some use different attributes for same thing.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 06:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-store-initiation-failure-what-log-is-the-most-relevant-for/m-p/645202#M16473</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-05-31T06:12:48Z</dc:date>
    </item>
  </channel>
</rss>

