<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP 503 -- KV Store initialization failed. Please contact your system administrator in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691386#M10109</link>
    <description>&lt;P&gt;&lt;SPAN&gt;i think its not about&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;permissions on /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;i tried&amp;nbsp; permission 400 and 600 and user group is both splunk. What should i do? Please help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 02:34:10 GMT</pubDate>
    <dc:creator>Anubaatar</dc:creator>
    <dc:date>2024-06-24T02:34:10Z</dc:date>
    <item>
      <title>HTTP 503 -- KV Store initialization failed. Please contact your system administrator</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691344#M10106</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Iam having this error since first of the june. Here is my splunkd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;06-22-2024 14:54:00.405 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" action=dbxquery_server_start_failed error=com.splunk.HttpException: HTTP 503 -- KV Store initialization failed. Please contact your system administrator. stack=com.splunk.HttpException.create(HttpException.java:84)\\com.splunk.DBXService.sendImpl(DBXService.java:132)\\com.splunk.DBXService.send(DBXService.java:44)\\com.splunk.HttpService.get(HttpService.java:172)\\com.splunk.dbx.model.repository.SecretKVStoreRepository.getSecrets(SecretKVStoreRepository.java:41)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.getSecretsFromKvStore(SecurityFileGenerationUtil.java:261)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.initEncryption(SecurityFileGenerationUtil.java:51)\\com.splunk.dbx.command.DbxQueryServerStart.startDbxQueryServer(DbxQueryServerStart.java:82)\\com.splunk.dbx.command.DbxQueryServerStart.streamEvents(DbxQueryServerStart.java:50)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.command.DbxQueryServerStart.main(DbxQueryServerStart.java:95)\\&lt;BR /&gt;06-22-2024 14:54:00.406 +0800 WARN ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" com.splunk.modularinput.MalformedDataException: Events must have at least the data field set to be written to XML.&lt;BR /&gt;06-22-2024 14:54:00.406 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" com.splunk.modularinput.Event.writeTo(Event.java:65)\\com.splunk.modularinput.EventWriter.writeEvent(EventWriter.java:137)\\com.splunk.dbx.command.DbxQueryServerStart.streamEvents(DbxQueryServerStart.java:51)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.command.DbxQueryServerStart.main(DbxQueryServerStart.java:95)\\&lt;BR /&gt;06-22-2024 14:54:04.800 +0800 INFO ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" action=start_task_server, configFile=/opt/splunk/etc/apps/splunk_app_db_connect/config/dbx_task_server.yml&lt;BR /&gt;06-22-2024 14:54:04.842 +0800 INFO ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" action=start_dbxquery_server, configFile=/opt/splunk/etc/apps/splunk_app_db_connect/config/dbxquery_server.yml&lt;BR /&gt;06-22-2024 14:54:04.981 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" 14:54:04.980 [main] INFO com.splunk.dbx.utils.SecurityFileGenerationUtil - initializing secret kv store collection&lt;BR /&gt;06-22-2024 14:54:05.015 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" 14:54:05.013 [main] INFO com.splunk.dbx.utils.SecurityFileGenerationUtil - initializing secret kv store collection&lt;BR /&gt;06-22-2024 14:54:05.102 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" 14:54:05.101 [main] INFO com.splunk.dbx.utils.SecurityFileGenerationUtil - secret KV Store found, store=com.splunk.Entity@d7b1517&lt;BR /&gt;06-22-2024 14:54:05.129 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" 14:54:05.129 [main] INFO com.splunk.dbx.utils.SecurityFileGenerationUtil - secret KV Store found, store=com.splunk.Entity@d7b1517&lt;BR /&gt;06-22-2024 14:54:05.214 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" action=task_server_start_failed error=com.splunk.HttpException: HTTP 503 -- KV Store initialization failed. Please contact your system administrator. stack=com.splunk.HttpException.create(HttpException.java:84)\\com.splunk.DBXService.sendImpl(DBXService.java:132)\\com.splunk.DBXService.send(DBXService.java:44)\\com.splunk.HttpService.get(HttpService.java:172)\\com.splunk.dbx.model.repository.SecretKVStoreRepository.getSecrets(SecretKVStoreRepository.java:41)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.getSecretsFromKvStore(SecurityFileGenerationUtil.java:261)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.initEncryption(SecurityFileGenerationUtil.java:51)\\com.splunk.dbx.server.bootstrap.TaskServerStart.startTaskServer(TaskServerStart.java:108)\\com.splunk.dbx.server.bootstrap.TaskServerStart.streamEvents(TaskServerStart.java:69)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.server.bootstrap.TaskServerStart.main(TaskServerStart.java:145)\\&lt;BR /&gt;06-22-2024 14:54:05.215 +0800 WARN ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" com.splunk.modularinput.MalformedDataException: Events must have at least the data field set to be written to XML.&lt;BR /&gt;06-22-2024 14:54:05.215 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh" com.splunk.modularinput.Event.writeTo(Event.java:65)\\com.splunk.modularinput.EventWriter.writeEvent(EventWriter.java:137)\\com.splunk.dbx.server.bootstrap.TaskServerStart.streamEvents(TaskServerStart.java:74)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.server.bootstrap.TaskServerStart.main(TaskServerStart.java:145)\\&lt;BR /&gt;06-22-2024 14:54:05.233 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" action=dbxquery_server_start_failed error=com.splunk.HttpException: HTTP 503 -- KV Store initialization failed. Please contact your system administrator. stack=com.splunk.HttpException.create(HttpException.java:84)\\com.splunk.DBXService.sendImpl(DBXService.java:132)\\com.splunk.DBXService.send(DBXService.java:44)\\com.splunk.HttpService.get(HttpService.java:172)\\com.splunk.dbx.model.repository.SecretKVStoreRepository.getSecrets(SecretKVStoreRepository.java:41)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.getSecretsFromKvStore(SecurityFileGenerationUtil.java:261)\\com.splunk.dbx.utils.SecurityFileGenerationUtil.initEncryption(SecurityFileGenerationUtil.java:51)\\com.splunk.dbx.command.DbxQueryServerStart.startDbxQueryServer(DbxQueryServerStart.java:82)\\com.splunk.dbx.command.DbxQueryServerStart.streamEvents(DbxQueryServerStart.java:50)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.command.DbxQueryServerStart.main(DbxQueryServerStart.java:95)\\&lt;BR /&gt;06-22-2024 14:54:05.233 +0800 WARN ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" com.splunk.modularinput.MalformedDataException: Events must have at least the data field set to be written to XML.&lt;BR /&gt;06-22-2024 14:54:05.233 +0800 ERROR ExecProcessor [201562 ExecProcessor] - message from "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/dbxquery.sh" com.splunk.modularinput.Event.writeTo(Event.java:65)\\com.splunk.modularinput.EventWriter.writeEvent(EventWriter.java:137)\\com.splunk.dbx.command.DbxQueryServerStart.streamEvents(DbxQueryServerStart.java:51)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.command.DbxQueryServerStart.main(DbxQueryServerStart.java:95)\\&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;And here is the mongod.log&lt;/P&gt;&lt;P&gt;2024-06-19T15:46:17.512+0800 W CONTROL [main] Option: sslMode is deprecated. Please use tlsMode instead.&lt;BR /&gt;2024-06-19T15:46:17.512+0800 W CONTROL [main] Option: sslPEMKeyFile is deprecated. Please use tlsCertificateKeyFile instead.&lt;BR /&gt;2024-06-19T15:46:17.512+0800 W CONTROL [main] Option: sslPEMKeyPassword is deprecated. Please use tlsCertificateKeyFilePassword instead.&lt;BR /&gt;2024-06-19T15:46:17.512+0800 W CONTROL [main] Option: sslCipherConfig is deprecated. Please use tlsCipherConfig instead.&lt;BR /&gt;2024-06-19T15:46:17.512+0800 W CONTROL [main] Option: sslAllowInvalidHostnames is deprecated. Please use tlsAllowInvalidHostnames instead.&lt;BR /&gt;2024-06-19T07:46:17.513Z W CONTROL [main] net.tls.tlsCipherConfig is deprecated. It will be removed in a future release.&lt;BR /&gt;2024-06-19T07:46:17.522Z W NETWORK [main] Server certificate has no compatible Subject Alternative Name. This may prevent TLS clients from connecting&lt;BR /&gt;2024-06-19T07:46:17.524Z W ASIO [main] No TransportLayer configured during NetworkInterface startup&lt;BR /&gt;2024-06-19T07:46:17.527Z I ACCESS [main] permissions on /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I tried create new ssl certificate but it doesnt work. And tried change the permission of the&lt;BR /&gt;/opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key&lt;BR /&gt;still encountering same error.&lt;BR /&gt;&lt;BR /&gt;What should i do? Please help.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2024 06:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691344#M10106</guid>
      <dc:creator>Anubaatar</dc:creator>
      <dc:date>2024-06-22T06:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP 503 -- KV Store initialization failed. Please contact your system administrator</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691371#M10107</link>
      <description>&lt;P&gt;If you still see "&lt;SPAN&gt;permissions on /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open," make sure the file is owned by your Splunk user and change the permissions to user (owner) read or read+write:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;$ chmod 0600 /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;If you're using a file system that supports extended ACLs, also make sure none are applied. You can check with getfacl:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;$ getfacl -p /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key
# file: /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key
# owner: splunk
# group: splunk
user::rw-
group::---
other::---&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2024 16:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691371#M10107</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-06-23T16:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP 503 -- KV Store initialization failed. Please contact your system administrator</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691385#M10108</link>
      <description>&lt;P&gt;i think its not about&lt;BR /&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;permissions on /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;i tried&amp;nbsp; permission 400 and 600 and user group is both splunk. What should i do? Please help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 01:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691385#M10108</guid>
      <dc:creator>Anubaatar</dc:creator>
      <dc:date>2024-06-24T01:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP 503 -- KV Store initialization failed. Please contact your system administrator</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691386#M10109</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i think its not about&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;permissions on /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;i tried&amp;nbsp; permission 400 and 600 and user group is both splunk. What should i do? Please help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 02:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HTTP-503-KV-Store-initialization-failed-Please-contact-your/m-p/691386#M10109</guid>
      <dc:creator>Anubaatar</dc:creator>
      <dc:date>2024-06-24T02:34:10Z</dc:date>
    </item>
  </channel>
</rss>

