<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KV Store process terminated abnormally (exit code 100, status exited with code 100). See mongod.log and splunkd.log for details. in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/KV-Store-process-terminated-abnormally-exit-code-100-status/m-p/369482#M3148</link>
    <description>&lt;P&gt;Hey there, have you tried chmod'ing the permissions to 600 and deleting the lock file ( &lt;CODE&gt;/opt/splunk/var/lib/splunk/kvstore/mongo/mongod.lock&lt;/CODE&gt; )?&lt;/P&gt;

&lt;P&gt;In my experience whenever this happens, the solution for me has been to chmod the mongo splunk key to 600, delete the lock file, and then reboot the whole server (not just the splunk service).&lt;/P&gt;

&lt;P&gt;Additionally, if you're still having issues check the permissions to make sure that the proper account owns/has access to mongo.  &lt;/P&gt;</description>
    <pubDate>Thu, 20 Sep 2018 17:25:13 GMT</pubDate>
    <dc:creator>pkiripolsky</dc:creator>
    <dc:date>2018-09-20T17:25:13Z</dc:date>
    <item>
      <title>KV Store process terminated abnormally (exit code 100, status exited with code 100). See mongod.log and splunkd.log for details.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/KV-Store-process-terminated-abnormally-exit-code-100-status/m-p/369481#M3147</link>
      <description>&lt;P&gt;I have the following message regarding an indexer in my environment (Splunk 6.6.5). :&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Search peer &lt;STRONG&gt;indexer&lt;/STRONG&gt; has the following message: KV Store process terminated abnormally (exit code 100, status exited with code 100). See mongod.log and splunkd.log for details. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;splunkd.log    &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-27-2018 13:29:07.622 -0400 WARN  DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Fri Apr 27 13:29:06 2018). Context: source::/opt/splunk/var/log/splunk/mongod.log|host::olpidx01|mongod|50
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;mongodb.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; 2018-04-25T18:07:11.837Z W -        [initandlisten] Detected unclean shutdown - /opt/splunk/var/lib/splunk/kvstore/mongo/mongod.lock is not empty.
 2018-04-25T18:07:11.845Z I STORAGE  [initandlisten]
 2018-04-25T18:07:11.845Z I STORAGE  [initandlisten] ** WARNING: Readahead for /opt/splunk/var/lib/splunk/kvstore/mongo is set to 4096KB
 2018-04-25T18:07:11.845Z I STORAGE  [initandlisten] **          We suggest setting it to 256KB (512 sectors) or less
 2018-04-25T18:07:11.845Z I STORAGE  [initandlisten] **          &lt;A href="http://dochub.mongodb.org/core/readahead" target="test_blank"&gt;http://dochub.mongodb.org/core/readahead&lt;/A&gt;
 2018-04-25T18:07:11.845Z I STORAGE  [initandlisten] **************
 old lock file: /opt/splunk/var/lib/splunk/kvstore/mongo/mongod.lock.  probably means unclean shutdown,
 but there are no journal files to recover.
 this is likely human error or filesystem corruption.
 please make sure that your journal directory is mounted.
 found 5 dbs.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The permissions on files are also same&lt;/P&gt;

&lt;P&gt;I tried this to make sure&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; chmod -R 400 $SPLUNK_HOME/var/lib/splunk/kvstore/mongo/splunk.key
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I even restarted my server and splunk service. Nothing seems to work please help.&lt;/P&gt;

&lt;P&gt;The mongod.log says empty jounal. My journal folder is empty on that indexer. Can i copy the files on another indexer and place them there.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 18:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/KV-Store-process-terminated-abnormally-exit-code-100-status/m-p/369481#M3147</guid>
      <dc:creator>omprakash9998</dc:creator>
      <dc:date>2018-04-27T18:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store process terminated abnormally (exit code 100, status exited with code 100). See mongod.log and splunkd.log for details.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/KV-Store-process-terminated-abnormally-exit-code-100-status/m-p/369482#M3148</link>
      <description>&lt;P&gt;Hey there, have you tried chmod'ing the permissions to 600 and deleting the lock file ( &lt;CODE&gt;/opt/splunk/var/lib/splunk/kvstore/mongo/mongod.lock&lt;/CODE&gt; )?&lt;/P&gt;

&lt;P&gt;In my experience whenever this happens, the solution for me has been to chmod the mongo splunk key to 600, delete the lock file, and then reboot the whole server (not just the splunk service).&lt;/P&gt;

&lt;P&gt;Additionally, if you're still having issues check the permissions to make sure that the proper account owns/has access to mongo.  &lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 17:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/KV-Store-process-terminated-abnormally-exit-code-100-status/m-p/369482#M3148</guid>
      <dc:creator>pkiripolsky</dc:creator>
      <dc:date>2018-09-20T17:25:13Z</dc:date>
    </item>
  </channel>
</rss>

