<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic KV Store Fails about once a week in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/KV-Store-Fails-about-once-a-week/m-p/532064#M4693</link>
    <description>&lt;P&gt;Roughly once a week, I'm getting the following errors on my single instance Splunk deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV Store changed status to failed. KVStore process terminated..&lt;BR /&gt;12/3/2020, 11:53:25 AM&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.&lt;BR /&gt;12/3/2020, 11:53:25 AM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I can fix the issue, by stopping Splunk, renaming the mongod folder and restarting Splunk but I want to know why I'm getting the errors and how to prevent them in the first place.&amp;nbsp; Any help or assistance would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2020 18:38:29 GMT</pubDate>
    <dc:creator>AJSCSA</dc:creator>
    <dc:date>2020-12-04T18:38:29Z</dc:date>
    <item>
      <title>KV Store Fails about once a week</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/KV-Store-Fails-about-once-a-week/m-p/532064#M4693</link>
      <description>&lt;P&gt;Roughly once a week, I'm getting the following errors on my single instance Splunk deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KV Store changed status to failed. KVStore process terminated..&lt;BR /&gt;12/3/2020, 11:53:25 AM&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.&lt;BR /&gt;12/3/2020, 11:53:25 AM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I can fix the issue, by stopping Splunk, renaming the mongod folder and restarting Splunk but I want to know why I'm getting the errors and how to prevent them in the first place.&amp;nbsp; Any help or assistance would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 18:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/KV-Store-Fails-about-once-a-week/m-p/532064#M4693</guid>
      <dc:creator>AJSCSA</dc:creator>
      <dc:date>2020-12-04T18:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: KV Store Fails about once a week</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/KV-Store-Fails-about-once-a-week/m-p/532117#M4696</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228901"&gt;@AJSCSA&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;These alerts you have referenced in your post, is this the "alert" that pops up when you log into the Webpage?&lt;/P&gt;&lt;P&gt;Can you provide some output as to what the following log shows with lines that pertain to KVStore?&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;On Linux:&lt;/U&gt;&lt;BR /&gt;# tail -f /opt/splunk/var/log/splunk/mongod.log&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;On Windows:&lt;/U&gt;&lt;BR /&gt;# type /opt/splunk/var/log/splunk/mongod.log&lt;BR /&gt;OR&lt;BR /&gt;# Get-Content /opt/splunk/var/log/splunk/mongod.log -wait&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Do let us know what the results yield!&lt;/P&gt;&lt;P&gt;V/R,&lt;BR /&gt;nwuest&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 07:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/KV-Store-Fails-about-once-a-week/m-p/532117#M4696</guid>
      <dc:creator>nwuest</dc:creator>
      <dc:date>2020-12-06T07:22:24Z</dc:date>
    </item>
  </channel>
</rss>

