<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we getting an error &amp;quot;SCRAM-SHA-1 authentication failed&amp;quot; on kvstore? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/651620#M110671</link>
    <description>&lt;P&gt;Are you using a custom certificate, and is it secured with a password? This error suggests an incorrect password, or possibly the password uses special characters and mongod doesn't like them. I found a case where someone using mongod and logging in from the command line had to escape out the special characters in their password. I don't see how that would be an issue with Splunk's implementation o mongod, but might be a good thing to test.&lt;/P&gt;&lt;P&gt;In the meantime, I will continue researching as I am working with another Splunk user encountering the same message.&lt;/P&gt;</description>
    <pubDate>Sat, 22 Jul 2023 13:45:53 GMT</pubDate>
    <dc:creator>trashyroadz</dc:creator>
    <dc:date>2023-07-22T13:45:53Z</dc:date>
    <item>
      <title>Why are we getting an error "SCRAM-SHA-1 authentication failed" on kvstore?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/586609#M103110</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm experiencing some issues on kvstore:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[conn4556] SCRAM-SHA-1 authentication failed for __system on local from client xxx.xxx.x.xx:xxxxx ; AuthenticationFailed: SCRAM-SHA-1 authentication failed, storedKey mismatch&lt;/LI-CODE&gt;
&lt;P&gt;I followed this&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-KV-Store-status-is-showing-as-quot-starting-quot-in/m-p/284690" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Deployment-Architecture/Why-is-the-KV-Store-status-is-showing-as-quot-starting-quot-in/m-p/284690&lt;/A&gt;&amp;nbsp;as for 1SH (total of 3)&amp;nbsp; I'm reciving:&lt;/P&gt;
&lt;P&gt;This member:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;backupRestoreStatus : Ready
disabled : 0
guid : xxxxxxxxxxxxxxxxxxxxxx
port : 8191
standalone : 0
status : starting
storageEngine : mmapv1&lt;/LI-CODE&gt;
&lt;P&gt;I appreciate any help&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 18:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/586609#M103110</guid>
      <dc:creator>tokio13</dc:creator>
      <dc:date>2022-02-25T18:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting an error "SCRAM-SHA-1 authentication failed" on kvstore?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/651143#M110600</link>
      <description>&lt;P&gt;I'm seeing the same message logged in mongod.log with Splunk v8.2.10 running on Windows Server.&lt;/P&gt;&lt;P&gt;It is logged as Info ("I ACCESS") instead of Error ("E&amp;nbsp;ACCESS"), so maybe it can be ignored?&lt;/P&gt;&lt;P&gt;Not sure which location "storedKey" it is referring to:&lt;/P&gt;&lt;P&gt;The expired Splunk local certificate was renewed a few months ago (server.pem), but there was still an old copy residing in Windows' certlm.msc repository. Updating the latter doesn't appear to fix the issue.&lt;/P&gt;&lt;P&gt;Environment Variable&amp;nbsp; SSL_CERT_FILE pointing to server.pem doesn't help either.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 16:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/651143#M110600</guid>
      <dc:creator>NK</dc:creator>
      <dc:date>2023-07-19T16:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting an error "SCRAM-SHA-1 authentication failed" on kvstore?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/651620#M110671</link>
      <description>&lt;P&gt;Are you using a custom certificate, and is it secured with a password? This error suggests an incorrect password, or possibly the password uses special characters and mongod doesn't like them. I found a case where someone using mongod and logging in from the command line had to escape out the special characters in their password. I don't see how that would be an issue with Splunk's implementation o mongod, but might be a good thing to test.&lt;/P&gt;&lt;P&gt;In the meantime, I will continue researching as I am working with another Splunk user encountering the same message.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 13:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-getting-an-error-quot-SCRAM-SHA-1-authentication/m-p/651620#M110671</guid>
      <dc:creator>trashyroadz</dc:creator>
      <dc:date>2023-07-22T13:45:53Z</dc:date>
    </item>
  </channel>
</rss>

