<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KVStore is not ready. Token auth system will not work. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679123#M18777</link>
    <description>Hi&lt;BR /&gt;Have you looked from mongod.log (or something similar) why mongod didn’t start?&lt;BR /&gt;r. Ismo</description>
    <pubDate>Thu, 29 Feb 2024 14:20:15 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-02-29T14:20:15Z</dc:date>
    <item>
      <title>KVStore is not ready. Token auth system will not work.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679110#M18775</link>
      <description>&lt;P&gt;When I navigate to Settings &amp;gt; Tokens, I get this error message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;KVStore is not ready. Token auth system will not work.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk logs shows this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ERROR JsonWebToken [233289 TcpChannelThread] - KVStore is not ready. Token auth system will not work.
ERROR KVStoreConfigurationProvider [233052 KVStoreConfigurationThread] - Failed to start mongod on first attempt reason=KVStore service will not start because kvstore process terminated
ERROR KVStoreBulletinBoardManager [233053 MongodLogThread] - KV Store changed status to failed. KVStore process terminated..&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can this be fixed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 12:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679110#M18775</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2024-02-29T12:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore is not ready. Token auth system will not work.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679123#M18777</link>
      <description>Hi&lt;BR /&gt;Have you looked from mongod.log (or something similar) why mongod didn’t start?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 29 Feb 2024 14:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679123#M18777</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-29T14:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore is not ready. Token auth system will not work.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679585#M18816</link>
      <description>&lt;P&gt;I found the solution which I came across here: &lt;A href="https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701" target="_blank"&gt;https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Turns out, the Splunk certificate was expired. This is how I checked:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Feb 27 13:56:21 2024 GMT&lt;/LI-CODE&gt;&lt;P&gt;To get a new certificate, I removed the old certificate and restarted Splunk (a new certificate will be created when Splunk starts):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$ mv /opt/splunk/etc/auth/server.pem /opt/splunk/etc/auth/server.pem.backup&lt;/LI-CODE&gt;&lt;P&gt;Now Settings &amp;gt; Tokens is working again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 12:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KVStore-is-not-ready-Token-auth-system-will-not-work/m-p/679585#M18816</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2024-03-05T12:48:25Z</dc:date>
    </item>
  </channel>
</rss>

