<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kv Store Backup Failing in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/748918#M22508</link>
    <description>&lt;P class="lia-align-left"&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308329"&gt;@Fenilleh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Is the issue resolved or still you are facing an issue? If issue still persists,please paste the error whatsoever you are getting in splunkd and mongod.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, I am attaching one KB article, have a look if that is relevant.&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/KV-Store-Backup-Fails" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/KV-Store-Backup-Fails&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jun 2025 16:16:58 GMT</pubDate>
    <dc:creator>Bhumi</dc:creator>
    <dc:date>2025-06-29T16:16:58Z</dc:date>
    <item>
      <title>Kv Store Backup Failing</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/745715#M22208</link>
      <description>&lt;P&gt;Hello everybody!&lt;BR /&gt;The problem that I have is that when I try to make a Backup of the KVStore on my Search Head, it fails after it is done dumping or while dumping the data.&amp;nbsp;&lt;BR /&gt;Splunk tells me to look into the logs but besides some basic info that the backup has failed I cant find any info in splunkd and mongo logs.&lt;BR /&gt;From my understanding, it is important that, since I'm using the point_in_time option, I have to make sure no searches are writing into the KV Store when I start the backup. Since Splunk makes a Snapshot of the moment I'm starting the backup, searches that modify the KVStores afterwards shoudln't impact the backup, right?&lt;BR /&gt;I made sure no searches have the running status when starting the Backup.&lt;BR /&gt;Does anybody have tips or threads that are about this topic?&lt;BR /&gt;I thought about stopping the scheduler during the backup, but since there are important searches running I want to look into all the options I have before taking drastic measures.&lt;BR /&gt;Thanks for any Tips and Hints in Advance!&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2025 17:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/745715#M22208</guid>
      <dc:creator>Fenilleh</dc:creator>
      <dc:date>2025-05-07T17:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Kv Store Backup Failing</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/748918#M22508</link>
      <description>&lt;P class="lia-align-left"&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308329"&gt;@Fenilleh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Is the issue resolved or still you are facing an issue? If issue still persists,please paste the error whatsoever you are getting in splunkd and mongod.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, I am attaching one KB article, have a look if that is relevant.&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/KV-Store-Backup-Fails" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/KV-Store-Backup-Fails&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jun 2025 16:16:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/748918#M22508</guid>
      <dc:creator>Bhumi</dc:creator>
      <dc:date>2025-06-29T16:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: Kv Store Backup Failing</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/749021#M22530</link>
      <description>&lt;P&gt;Thanks for Replying!&amp;nbsp;&lt;BR /&gt;The issue was forwarded to Splunk Support by me.&lt;BR /&gt;I was told that since the Search Head is standalone, the option&amp;nbsp;&lt;SPAN&gt;point_in_time is not needed.&lt;BR /&gt;The update was done successfully and the backup was luckily not required to be used.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 11:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Kv-Store-Backup-Failing/m-p/749021#M22530</guid>
      <dc:creator>Fenilleh</dc:creator>
      <dc:date>2025-07-01T11:52:27Z</dc:date>
    </item>
  </channel>
</rss>

