<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to resolve kvstore failed on  indexer? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626354#M9212</link>
    <description>&lt;P&gt;in default server.conf it is enabled, but you are saying by default it should be disabled, then why default conf file it is enabled ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiranhar_0-1673236786593.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23260i079B8B4E1BBEC5B3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiranhar_0-1673236786593.png" alt="kiranhar_0-1673236786593.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 04:01:09 GMT</pubDate>
    <dc:creator>kiranhar</dc:creator>
    <dc:date>2023-01-09T04:01:09Z</dc:date>
    <item>
      <title>How to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626089#M9201</link>
      <description>&lt;P&gt;Hello folks, Need your help.&lt;/P&gt;
&lt;P&gt;Here is the splunkd.log file with grep kvstore. Please review and advise what went wrong and what needs to be done to fix this issue.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiranhar_0-1672979455099.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23222i71C753DBE7B96ED4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiranhar_0-1672979455099.png" alt="kiranhar_0-1672979455099.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 14:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626089#M9201</guid>
      <dc:creator>kiranhar</dc:creator>
      <dc:date>2023-01-06T14:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626184#M9204</link>
      <description>&lt;P&gt;Indexers do not use the KVStore so it should be disabled.&amp;nbsp; Add these lines (if not already present) to the server.conf file on each indexer and restart them.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[kvstore]
disabled = true&lt;/LI-CODE&gt;&lt;P&gt;Then you can ignore those log messages.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 13:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626184#M9204</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-06T13:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626354#M9212</link>
      <description>&lt;P&gt;in default server.conf it is enabled, but you are saying by default it should be disabled, then why default conf file it is enabled ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiranhar_0-1673236786593.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23260i079B8B4E1BBEC5B3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiranhar_0-1673236786593.png" alt="kiranhar_0-1673236786593.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 04:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626354#M9212</guid>
      <dc:creator>kiranhar</dc:creator>
      <dc:date>2023-01-09T04:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626403#M9215</link>
      <description>&lt;P&gt;I did not say it should be disabled by default.&amp;nbsp; I merely said it should be disabled if it is not already,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 13:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626403#M9215</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-09T13:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626500#M9219</link>
      <description>&lt;P&gt;Thanks for your response. So, shall I disable from the default dir or local dir ? please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 03:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626500#M9219</guid>
      <dc:creator>kiranhar</dc:creator>
      <dc:date>2023-01-10T03:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626588#M9220</link>
      <description>&lt;P&gt;Never edit a file in a default dir.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 13:16:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626588#M9220</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-10T13:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626594#M9221</link>
      <description>&lt;P&gt;Jumping in to throw some speculations in the mix.. I don't know if this will fix the problems or its related.&lt;/P&gt;&lt;P&gt;Is this a new instance or an older Splunk Installations?&amp;nbsp;&lt;BR /&gt;In the past, especially after upgrading, I had problems with the KVStore which could be fixed by forcing Splunk to generate a new server.pem&lt;/P&gt;&lt;P&gt;You can force Splunk to create a new certificate by renaming the old one in /SPLUNK_HOME/etc/auth/server.pem to&amp;nbsp;/SPLUNK_HOME/etc/auth/server.pem_old&lt;BR /&gt;&lt;BR /&gt;then restart Splunk and it generates a new server.pem at startup&lt;BR /&gt;&lt;BR /&gt;If everything works you can delete the&amp;nbsp;server.pem_old&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 13:30:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/626594#M9221</guid>
      <dc:creator>FelixLeh</dc:creator>
      <dc:date>2023-01-10T13:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/673129#M9838</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;&lt;P&gt;Based on your answer, am I correct to assume that the KV Store role can be removed from the Indexer`s roles ?&lt;BR /&gt;&lt;BR /&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/673129#M9838</guid>
      <dc:creator>tomapatan</dc:creator>
      <dc:date>2024-01-03T14:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to resolve kvstore failed on  indexer?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/673133#M9839</link>
      <description>&lt;P&gt;If you're referring to the roles listed in the Monitoring Console then, yes.&amp;nbsp; Doing so does not change anything on the indexer itself, however.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-resolve-kvstore-failed-on-indexer/m-p/673133#M9839</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-03T14:55:27Z</dc:date>
    </item>
  </channel>
</rss>

