<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kvstore failed in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756121#M12779</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313343"&gt;@egko&lt;/a&gt;&amp;nbsp; Take the backup of KV store&lt;BR /&gt;ref:&amp;nbsp;&lt;A href="https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.4/administer-the-app-key-value-store/back-up-and-restore-kv-store" target="_blank"&gt;https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.4/administer-the-app-key-value-store/back-up-and-restore-kv-store&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and try to clean the kvstore and restart the splunk.&lt;/P&gt;&lt;P&gt;check the status&amp;nbsp;&lt;/P&gt;&lt;P&gt;splunk show kvstore-status --verbose&lt;/P&gt;&lt;P&gt;splunk stop&lt;BR /&gt;splunk clean kvstore --local&lt;BR /&gt;splunk start&lt;/P&gt;&lt;P&gt;please refer the below document as well for more details about kv store troubleshooting&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.0/welcome-to-splunk-enterprise-administration/administer-the-app-key-value-store/kv-store-troubleshooting-tools" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.0/welcome-to-splunk-enterprise-administration/administer-the-app-key-value-store/kv-store-troubleshooting-tools&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2025 07:26:20 GMT</pubDate>
    <dc:creator>thahir</dc:creator>
    <dc:date>2025-12-03T07:26:20Z</dc:date>
    <item>
      <title>Kvstore failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756120#M12778</link>
      <description>&lt;P&gt;On my current machine, Kvstore is failing.&lt;BR /&gt;When I restart Splunk, the Kvstore status is "Ready." However, when I click the Audit Log tab in ES, the status changes to "Failed." This makes it impossible to access other Kvstore-related functions, such as incident review in ES.&lt;/P&gt;&lt;P&gt;I tried changing the server.pem file to a different extension and restarting, as well as changing the mongod.lock and splunk.key files to different extensions and restarting. I also tried changing all configuration files, but nothing worked.&lt;/P&gt;&lt;P&gt;I'm wondering if there are any other solutions.&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk version : 8.1.10.1&lt;BR /&gt;Splunk Enterprise Security: 7.0.1&lt;/P&gt;&lt;P&gt;ERROR-Log&lt;BR /&gt;Failed to execute KVstore lookups External command based lookup 'goverence_lookup' is not available because KVstore initialization has failed, Contact your system admin...&lt;BR /&gt;Failed to create kvstore lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 06:49:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756120#M12778</guid>
      <dc:creator>egko</dc:creator>
      <dc:date>2025-12-03T06:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Kvstore failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756121#M12779</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313343"&gt;@egko&lt;/a&gt;&amp;nbsp; Take the backup of KV store&lt;BR /&gt;ref:&amp;nbsp;&lt;A href="https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.4/administer-the-app-key-value-store/back-up-and-restore-kv-store" target="_blank"&gt;https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.4/administer-the-app-key-value-store/back-up-and-restore-kv-store&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and try to clean the kvstore and restart the splunk.&lt;/P&gt;&lt;P&gt;check the status&amp;nbsp;&lt;/P&gt;&lt;P&gt;splunk show kvstore-status --verbose&lt;/P&gt;&lt;P&gt;splunk stop&lt;BR /&gt;splunk clean kvstore --local&lt;BR /&gt;splunk start&lt;/P&gt;&lt;P&gt;please refer the below document as well for more details about kv store troubleshooting&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.0/welcome-to-splunk-enterprise-administration/administer-the-app-key-value-store/kv-store-troubleshooting-tools" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.0/welcome-to-splunk-enterprise-administration/administer-the-app-key-value-store/kv-store-troubleshooting-tools&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 07:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756121#M12779</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-12-03T07:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Kvstore failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756123#M12780</link>
      <description>&lt;P&gt;The mongod.lock file is 0 bytes no matter how many times I restart it.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 08:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756123#M12780</guid>
      <dc:creator>egko</dc:creator>
      <dc:date>2025-12-03T08:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Kvstore failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756124#M12781</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313343"&gt;@egko&lt;/a&gt;&amp;nbsp; remove the lock file and clean up the kvstore and do the restart&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 08:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756124#M12781</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-12-03T08:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Kvstore failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756126#M12782</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313343"&gt;@egko&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your Splunk Enterprise 8.1x is outdated, and Splunk Enterprise Security 7.0.1 is likely incompatible, causing the KV Store to fail (from "Ready" to "Failed") when ES loads.&lt;BR /&gt;&lt;BR /&gt;Upgrade Splunk Enterprise, then upgrade ES to a compatible version.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;#&lt;A href="https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.0/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/get-started/install-and-upgrade/9.0/upgrade-or-migrate-splunk-enterprise/how-to-upgrade-splunk-enterprise&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 09:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Kvstore-failed/m-p/756126#M12782</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-12-03T09:43:33Z</dc:date>
    </item>
  </channel>
</rss>

