<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I experiencing KVStore Failure using Red Hat Linux 7.5 and Splunk 7.3.4? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/546003#M4975</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;W CONTROL [main] net.ssl.sslCipherConfig is deprecated. It will be removed in a future release.
F NETWORK [main] The provided SSL certificate is expired or not yet valid.
F - [main] Fatal Assertion 28652 at src/mongo/util/net/ssl_manager.cpp 1145F F F - [main] 
***aborting after fassert() failure&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I am on a closed network so I copied these errors from other posts and removed their older time stamps.&amp;nbsp; &amp;nbsp;Yes, I have tried removing server.pem and restarting splunk it does nto auto generate a new Server .pem.&amp;nbsp; Yes I followed the attached instructions:&amp;nbsp;&lt;A href="https://splunkonbigdata.com/2019/07/03/failed-to-start-kv-store-process-see-mongod-log-and-splunkd-log-for-details/" target="_blank" rel="noopener"&gt;https://splunkonbigdata.com/2019/07/03/failed-to-start-kv-store-process-see-mongod-log-and-splunkd-log-for-details/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do have in server.conf&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[sslConfig]

caCertFile= $SPLUNK_HOME/etc/auth/cacert.pem

caPath=$SPLUNK_HOME/etc/auth

enableSplunkdSSL = true

serverCert = /opt/splunk/etc/auth/mycerts/myCert.pem

SSLRootCAPath = /opt/splunk/etc/auth/mycerts/CA-Chain-Cert.pem&lt;/LI-CODE&gt;
&lt;P&gt;I do not have any Certs listed under [KVStore] section&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it defaults to use server.pem if not listed or if it defaults to the SSLConfig.&amp;nbsp; The certs in my SSLConfig ARE expired and I cannot get server team to generate new ones.&amp;nbsp; I have a distributed environment.&amp;nbsp; I can create local certs using ./splunk createssl if that helps and move off of the Current CA the enterprise uses since it is needing upgraded anyway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using Red Hat Linux 7.5 and Splunk 7.3.4 and I have Enterprise Security and UBA as well.&amp;nbsp; I first noticed this error after a reboot on the ES Server search server.&amp;nbsp; I then later did a rolling restart on my index cluster and they all give kvstore errors now as well.&amp;nbsp; I do not have experience with Splunk ES or UBA and just arrived at this job a few months ago.&amp;nbsp; They have gone through a tone of quasi splunk admins who had little or no experience with SPLUNK due to difficulty finding splunk admins.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I feel like the servercert in sslconfig of server.conf may be my issue.&amp;nbsp; any help is HIGHLY appreciated!&lt;/P&gt;
&lt;P&gt;Yes, I will upvote troubleshooting assistance and answers &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 19:17:13 GMT</pubDate>
    <dc:creator>Funderburg78</dc:creator>
    <dc:date>2022-03-14T19:17:13Z</dc:date>
    <item>
      <title>Why am I experiencing KVStore Failure using Red Hat Linux 7.5 and Splunk 7.3.4?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/546003#M4975</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;W CONTROL [main] net.ssl.sslCipherConfig is deprecated. It will be removed in a future release.
F NETWORK [main] The provided SSL certificate is expired or not yet valid.
F - [main] Fatal Assertion 28652 at src/mongo/util/net/ssl_manager.cpp 1145F F F - [main] 
***aborting after fassert() failure&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I am on a closed network so I copied these errors from other posts and removed their older time stamps.&amp;nbsp; &amp;nbsp;Yes, I have tried removing server.pem and restarting splunk it does nto auto generate a new Server .pem.&amp;nbsp; Yes I followed the attached instructions:&amp;nbsp;&lt;A href="https://splunkonbigdata.com/2019/07/03/failed-to-start-kv-store-process-see-mongod-log-and-splunkd-log-for-details/" target="_blank" rel="noopener"&gt;https://splunkonbigdata.com/2019/07/03/failed-to-start-kv-store-process-see-mongod-log-and-splunkd-log-for-details/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do have in server.conf&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[sslConfig]

caCertFile= $SPLUNK_HOME/etc/auth/cacert.pem

caPath=$SPLUNK_HOME/etc/auth

enableSplunkdSSL = true

serverCert = /opt/splunk/etc/auth/mycerts/myCert.pem

SSLRootCAPath = /opt/splunk/etc/auth/mycerts/CA-Chain-Cert.pem&lt;/LI-CODE&gt;
&lt;P&gt;I do not have any Certs listed under [KVStore] section&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure if it defaults to use server.pem if not listed or if it defaults to the SSLConfig.&amp;nbsp; The certs in my SSLConfig ARE expired and I cannot get server team to generate new ones.&amp;nbsp; I have a distributed environment.&amp;nbsp; I can create local certs using ./splunk createssl if that helps and move off of the Current CA the enterprise uses since it is needing upgraded anyway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using Red Hat Linux 7.5 and Splunk 7.3.4 and I have Enterprise Security and UBA as well.&amp;nbsp; I first noticed this error after a reboot on the ES Server search server.&amp;nbsp; I then later did a rolling restart on my index cluster and they all give kvstore errors now as well.&amp;nbsp; I do not have experience with Splunk ES or UBA and just arrived at this job a few months ago.&amp;nbsp; They have gone through a tone of quasi splunk admins who had little or no experience with SPLUNK due to difficulty finding splunk admins.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I feel like the servercert in sslconfig of server.conf may be my issue.&amp;nbsp; any help is HIGHLY appreciated!&lt;/P&gt;
&lt;P&gt;Yes, I will upvote troubleshooting assistance and answers &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 19:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/546003#M4975</guid>
      <dc:creator>Funderburg78</dc:creator>
      <dc:date>2022-03-14T19:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failure</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/546850#M4987</link>
      <description>&lt;P class="lia-align-left"&gt;FYI This has been resolved.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Turns out if you utilize the&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;[sslConfig]&lt;/P&gt;&lt;P class="lia-align-left"&gt;serverca =&lt;/P&gt;&lt;P class="lia-align-left"&gt;servercerts =&lt;/P&gt;&lt;P class="lia-align-left"&gt;Then the KVStore no longer uses server.pem and instead uses the certs assigned in the sslConfig.&amp;nbsp; This was not mentioned anywhere in Documentation.&amp;nbsp; If this post helps you later please extend some Karma &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 11:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/546850#M4987</guid>
      <dc:creator>Funderburg78</dc:creator>
      <dc:date>2021-04-06T11:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failure</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/588936#M8746</link>
      <description>&lt;P&gt;LOL, taking over after you have gone... the other systems certs expired.&amp;nbsp; This post got me to that point... thanks el Hefe!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 14:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/588936#M8746</guid>
      <dc:creator>lowcrawl</dc:creator>
      <dc:date>2022-03-14T14:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: KVStore Failure</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/589109#M8748</link>
      <description>&lt;P&gt;Glad to hear it bro!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 14:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/589109#M8748</guid>
      <dc:creator>Funderburg78</dc:creator>
      <dc:date>2022-03-15T14:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I experiencing KVStore Failure using Red Hat Linux 7.5 and Splunk 7.3.4?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/649645#M9617</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Knowledge-Management/Why-is-KV-Store-certificate-renewal-not-working/td-p/471252" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Knowledge-Management/Why-is-KV-Store-certificate-renewal-not-working/td-p/471252&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Windows, you may get the following error message in mongod.log:&lt;/P&gt;&lt;P&gt;Fatal Assertion 50755 at src\mongo\util\net\ssl_manager_windows.cpp 1609&lt;/P&gt;&lt;P&gt;To fix the error that causes mongod to terminate, you need the following in addition to deleting server.pem:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Open Windows certificate management MMC for the local computer ( certlm.msc )&lt;/LI&gt;&lt;LI&gt;Navigate to Personal &amp;gt; Certificates&lt;/LI&gt;&lt;LI&gt;Delete any entries named SplunkServerDefaultCert&lt;/LI&gt;&lt;LI&gt;Restart splunk.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 07 Jul 2023 16:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Why-am-I-experiencing-KVStore-Failure-using-Red-Hat-Linux-7-5/m-p/649645#M9617</guid>
      <dc:creator>pavankumarh</dc:creator>
      <dc:date>2023-07-07T16:08:20Z</dc:date>
    </item>
  </channel>
</rss>

