All Apps and Add-ons

Why am I getting error "key value store is locked" trying to install the Splunk App for Windows Infrastructure?

URSI
New Member

I've got an install of Splunk 64-bit running on Windows Server 2012 & am trying to install the Splunk App for Windows Infrastructure. Unfortunately I'm getting the "key value store is locked" error while setting it up. After looking through C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo I noticed there was a "mongod.lock" which set me to looking through the logs in C:\Program Files\Splunk\var\log\splunk\mongod.log & found this:


 old lock file: C:\Program Files\Splunk\var\lib\splunk/kvstore\mongo\mongod.lock.  probably means unclean shutdown,
 but there are no journal files to recover.
 this is likely human error or filesystem corruption.
 please make sure that your journal directory is mounted.
 found 53 dbs.
 see: http://dochub.mongodb.org/core/repair for more information

Does anyone have a fix for this?

0 Karma

dflodstrom
Builder

I have come across this and similar issues with kvstore. Occasionally I'll have two SSH sessions opened to the same server and attempt to restart Splunk while I'm editing a conf file. KVstore doesn't shut down cleanly when this happens and mongodb continues to run. When this happens I get prompted to select another port because my KVstore port is in use. I'm forced to manually kill the process and then start Splunk to work around this.

The lock file is slightly different. I believe just deleting that file will allow mongodb to start back up (not the safest option)
This site has the info you need --> http://docs.mongodb.org/manual/tutorial/recover-data-following-unexpected-shutdown/

0 Karma

URSI
New Member

What do I use for the dbpath?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...