I am running 6.4.2 on MAC OS X El Capitan.
The following is showing up in my logs:
2016-07-12T02:24:11.083Z W CONTROL No SSL certificate validation can be performed since no CA file has been provided; please specify an sslCAFile parameter
2016-07-12T02:24:11.236Z I ACCESS permissions on /Volumes/2TB Media/Applications/Splunk/var/lib/splunk/kvstore/mongo/splunk.key are too open
Looking at my KVStores:
Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/server/introspection/kvstore/serverstatus?count=0 from server=https://127.0.0.1:8089
I've found all of this while trying to get my Splunk App for Stream to work since the configurations pages are blank.
This usually happens when the SSL cert used by Mongo expires. See https://answers.splunk.com/answers/409506/why-are-configuration-dashboards-empty-after-upgra.html
Also, I forgot to add the following:
From streamfwd.log:
2016-07-11 21:25:29 INFO [0x7fff76da7000] (main.cpp:769) stream.main - streamfwd has started successfully (version 6.5.1 build 256)
2016-07-11 21:25:29 INFO [0x7fff76da7000] (main.cpp:771) stream.main - web interface listening on port 8889
2016-07-11 21:25:45 ERROR [0x70000020a000] (CaptureServer.cpp:1693) stream.CaptureServer - Unable to update streams config (sender=b301537a-f121-45a1-95b1-e049dc962665): /en-us/custom/splunk_app_stream/streams/?streamForwarderId=williams-mac-mini.local status=500