<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709513#M21389</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp; - Errors definitely seems to be related to SSL certificate file or SSL certificate configuration in Splunk.&lt;/P&gt;&lt;P&gt;* Its more broader topic to tell exactly what's wrong.&lt;/P&gt;&lt;P&gt;* But need to check SSL certs configured on Splunk and then for those SSL files check expiration date and validation of cert file.&lt;/P&gt;&lt;P&gt;* Make sure Splunk config not having any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2025 19:30:53 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2025-01-22T19:30:53Z</dc:date>
    <item>
      <title>KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709353#M21378</link>
      <description>&lt;P&gt;Hello Splunker,&lt;/P&gt;&lt;P&gt;After I upgraded to version 9.4 , KV store does not start , I generated a new certificate by renaming server.pem and restarting the splunk , And now I see the following error on mongod.log&lt;/P&gt;&lt;P&gt;[conn937] SSL peer certificate validation failed: self signed certificate in certificate chain&lt;BR /&gt;NETWORK [conn937] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: self signed certificate in certificate chain. Ending connection from 127.0.0.1:38268 (connection id: 937)&lt;/P&gt;&lt;P&gt;Does anyone have any idea what could be missing ?&lt;/P&gt;&lt;P&gt;Appreciate your inputs in this regard,&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Moh&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 17:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709353#M21378</guid>
      <dc:creator>mohsplunking</dc:creator>
      <dc:date>2025-01-21T17:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709355#M21379</link>
      <description>&lt;P&gt;And Splunkd logs has the following error MONGO GB&lt;/P&gt;&lt;P&gt;WARN MongoClient [999733 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost&lt;BR /&gt;ERROR KVStorageProvider [999733 KVStoreUpgradeStartupThread] - An error occurred during the last operation ('replSetGetStatus', domain: '15', code: '13053'): No suitable servers found (`serverSelectionTryOnce` set): [connection closed calling hello on '127.0.0.1:8191']&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 17:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709355#M21379</guid>
      <dc:creator>mohsplunking</dc:creator>
      <dc:date>2025-01-21T17:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709513#M21389</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234071"&gt;@mohsplunking&lt;/a&gt;&amp;nbsp; - Errors definitely seems to be related to SSL certificate file or SSL certificate configuration in Splunk.&lt;/P&gt;&lt;P&gt;* Its more broader topic to tell exactly what's wrong.&lt;/P&gt;&lt;P&gt;* But need to check SSL certs configured on Splunk and then for those SSL files check expiration date and validation of cert file.&lt;/P&gt;&lt;P&gt;* Make sure Splunk config not having any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 19:30:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/709513#M21389</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-01-22T19:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/710125#M21499</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Please can you confirm if you followed the Splunk 9.4 upgrade pre-steps that are documented here?&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Installation/AboutupgradingREADTHISFIRST" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&lt;BR /&gt;There is a section on upgrading the kv-store before running the Splunk 9.4 upgrade.&lt;BR /&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 11:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/710125#M21499</guid>
      <dc:creator>mserieys_splunk</dc:creator>
      <dc:date>2025-01-29T11:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/712637#M21721</link>
      <description>&lt;P&gt;If you're still experiencing issues, please take a look here&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/KV-store-status-failed-after-upgrade-to-9-4" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/KV-store-status-failed-after-upgrade-to-9-4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The suggestion of concatenating CA certs resolved the errors and Splunk was able to upgrade/initialize kvstore after a restart of splunkd.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 20:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/712637#M21721</guid>
      <dc:creator>n8o</dc:creator>
      <dc:date>2025-02-26T20:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store changed status to failed. Failed to start KV Store process. See mongod.log</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/712660#M21725</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i don't know if it is the same issue but could you check this requirements. For example, is your cpu supported avx / avx2 instructions, if yes, is it enabled ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Admin/MigrateKVstore" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Admin/MigrateKVstore&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.mongodb.com/docs/manual/administration/production-notes/" target="_blank"&gt;https://www.mongodb.com/docs/manual/administration/production-notes/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;i hope this help&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 23:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/KV-Store-changed-status-to-failed-Failed-to-start-KV-Store/m-p/712660#M21725</guid>
      <dc:creator>myitlab42000</dc:creator>
      <dc:date>2025-02-26T23:47:32Z</dc:date>
    </item>
  </channel>
</rss>

