<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic KVStore Failed 9.4.3 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750265#M119211</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;I upgraded Splunk Enterprise from 9.2.3 to 9.4.3, and the KVSotre status is failed.&lt;BR /&gt;&lt;BR /&gt;It was migrated successfully to 7.0.14 on one server automatically, but on the second server, migration did not start upon upgrade.&amp;nbsp;&lt;BR /&gt;Is there a solution to restore the KVstore status and migrate to&amp;nbsp; 7.0.14?&lt;BR /&gt;It is a standalone server and not part of clustered environment.&lt;BR /&gt;Some servers also have KVStore status Failed on the version 9.2.3, and I want to change the status before starting to upgrade them to 9.4.3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This member:&lt;BR /&gt;backupRestoreStatus : Ready&lt;BR /&gt;disabled : 0&lt;BR /&gt;featureCompatibilityVersion : An error occurred during the last operation ('getParameter', domain: '15', code: '13053'): No suitable servers found: `serverSelectionTimeoutMS` expired: [Failed to connect to target host: 127.0.0.1:8191]&lt;BR /&gt;guid : xzy&lt;BR /&gt;port : 8191&lt;BR /&gt;standalone : 1&lt;BR /&gt;status : failed&lt;BR /&gt;storageEngine : wiredTiger&lt;BR /&gt;versionUpgradeInProgress : 0&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jul 2025 16:14:47 GMT</pubDate>
    <dc:creator>tech_g706</dc:creator>
    <dc:date>2025-07-22T16:14:47Z</dc:date>
    <item>
      <title>KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750265#M119211</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I upgraded Splunk Enterprise from 9.2.3 to 9.4.3, and the KVSotre status is failed.&lt;BR /&gt;&lt;BR /&gt;It was migrated successfully to 7.0.14 on one server automatically, but on the second server, migration did not start upon upgrade.&amp;nbsp;&lt;BR /&gt;Is there a solution to restore the KVstore status and migrate to&amp;nbsp; 7.0.14?&lt;BR /&gt;It is a standalone server and not part of clustered environment.&lt;BR /&gt;Some servers also have KVStore status Failed on the version 9.2.3, and I want to change the status before starting to upgrade them to 9.4.3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This member:&lt;BR /&gt;backupRestoreStatus : Ready&lt;BR /&gt;disabled : 0&lt;BR /&gt;featureCompatibilityVersion : An error occurred during the last operation ('getParameter', domain: '15', code: '13053'): No suitable servers found: `serverSelectionTimeoutMS` expired: [Failed to connect to target host: 127.0.0.1:8191]&lt;BR /&gt;guid : xzy&lt;BR /&gt;port : 8191&lt;BR /&gt;standalone : 1&lt;BR /&gt;status : failed&lt;BR /&gt;storageEngine : wiredTiger&lt;BR /&gt;versionUpgradeInProgress : 0&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 16:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750265#M119211</guid>
      <dc:creator>tech_g706</dc:creator>
      <dc:date>2025-07-22T16:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750268#M119212</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Here are some internal logs:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;2025-07-22T17:37:22.629Z I&amp;nbsp; NETWORK&amp;nbsp; [conn1078] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: self signed certificate in certificate chain. Ending connection from 127.0.0.1:43286 (connection id: 1078)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;2025-07-22T17:37:22.629Z E&amp;nbsp; NETWORK&amp;nbsp; [conn1078] SSL peer certificate validation failed: self signed certificate in certificate chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;T 2025-07-22T17:37:22.125Z I&amp;nbsp; NETWORK&amp;nbsp; [conn1077] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: self signed certificate in certificate chain. Ending connection from 127.0.0.1:43272 (connection id: 1077)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;h 2025-07-22T17:37:22.125Z E&amp;nbsp; NETWORK&amp;nbsp; [conn1077] SSL peer certificate validation failed: self signed certificate in certificate chain&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 17:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750268#M119212</guid>
      <dc:creator>tech_g706</dc:creator>
      <dc:date>2025-07-22T17:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750288#M119215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309054"&gt;@tech_g706&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have custom SSL Certs on your server?&lt;/P&gt;&lt;P&gt;Please can you confirm the output of the following which might help us dig down. Thanks&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/bin/splunk cmd btool server list --debug kvstore&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 22:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750288#M119215</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-22T22:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750314#M119216</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; Thanks for the response.&lt;BR /&gt;&lt;BR /&gt;Yes, some servers having custom certificates on those servers, we are having issue&lt;BR /&gt;&lt;BR /&gt;If I try changing to the default local certificate, then it works&lt;BR /&gt;&lt;BR /&gt;root@test02:/opt/splunk/bin# ./splunk cmd openssl verify -verbose -x509_strict -CAfile /opt/splunk/etc/auth/cacert.pem.default /opt/splunk/etc/auth/server.pem_old&lt;BR /&gt;/opt/splunk/etc/auth/server.pem_old: OK&lt;BR /&gt;root@test02:/opt/splunk/bin#&lt;BR /&gt;root@test02:/opt/splunk/bin#&lt;BR /&gt;root@test02:/opt/splunk/bin#&lt;BR /&gt;root@test02:/opt/splunk/bin# ./splunk cmd openssl verify -verbose -x509_strict -CAfile /opt/splunk/etc/auth/cacert.pem /opt/splunk/etc/auth/server.pem&lt;BR /&gt;&lt;BR /&gt;error 20 at 0 depth lookup: unable to get local issuer certificate&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;./splunk cmd btool server list --debug kvstore&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf [kvstore]&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf clientConnectionPoolSize = 500&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf clientConnectionTimeout = 10&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf clientSocketTimeout = 300&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf dbCursorOperationTimeout = 300&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf dbPath = $SPLUNK_DB/kvstore&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf defaultKVStoreType = local&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf delayShutdownOnBackupRestoreInProgress = false&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf disabled = false&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf initAttempts = 300&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf initialSyncMaxFetcherRestarts = 0&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf kvstoreUpgradeCheckInterval = 5&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf kvstoreUpgradeOnStartupDelay = 60&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf kvstoreUpgradeOnStartupEnabled = true&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf kvstoreUpgradeOnStartupRetries = 2&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf minSnapshotHistoryWindow = 5&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf oplogSize = 1000&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf percRAMForCache = 15&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf port = 8191&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf replicaset = splunkrs&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf replicationWriteTimeout = 1800&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf shutdownTimeout = 100&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf sslVerifyServerCert = false&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf sslVerifyServerName = false&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf storageEngine = wiredTiger&lt;BR /&gt;/opt/splunk/etc/system/default/server.conf storageEngineMigration = false&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 07:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750314#M119216</guid>
      <dc:creator>tech_g706</dc:creator>
      <dc:date>2025-07-23T07:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750346#M119217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309054"&gt;@tech_g706&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometime the issue with the MongoDB as well&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the following, it will helpful for further troubleshooting.&lt;/P&gt;&lt;P&gt;Mongodb status&lt;/P&gt;&lt;P&gt;ps -ef | grep -i mongod&lt;/P&gt;&lt;P&gt;if we are not getting any output means kvstore is not running.&lt;/P&gt;&lt;P&gt;check the below logs, try to find any clue on this logs&lt;/P&gt;&lt;P&gt;cat $SPLUNK_HOME/var/log/splunk/kvstore.log&lt;BR /&gt;cat $SPLUNK_HOME/var/log/splunk/mongod.log&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750346#M119217</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-07-23T15:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failed 9.4.3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750933#M119271</link>
      <description>&lt;P&gt;We're experiencing the same issue.&amp;nbsp; Were you able to resolve this?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 16:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KVStore-Failed-9-4-3/m-p/750933#M119271</guid>
      <dc:creator>ahainline</dc:creator>
      <dc:date>2025-08-01T16:46:22Z</dc:date>
    </item>
  </channel>
</rss>

