Deployment Architecture

Splunk SH Cluster - KV store cannot initiate set

perfecto25
Path Finder

Hello, Im running a 3-node SH cluster + deployer (running splunk 7.1 on Centos 7)

Cluster is up and Captain is SH1, my kv-status comes back with,

This member:
                           backupRestoreStatus : Ready
                                      disabled : 0
                                          guid : 6DE38BA1-8716-4909-9053-C60751902220
                                          port : 8191
                                    standalone : 0
                                        status : failed

 Enabled KV store members:
        njosplunksh02.company.local:8191
                                          guid : 6C547544-700B-4A12-9446-C2246E73A717
                                   hostAndPort : njosplunksh02.company.local:8191
        njosplunksh01.company.local:8191
                                          guid : 6DE38BA1-8716-4909-9053-C60751902220
                                   hostAndPort : njosplunksh01.company.local:8191
        njosplunksh03.company.local:8191
                                          guid : 85A78216-32F6-4875-8FC7-9DB7BB0AD1E5
                                   hostAndPort : njosplunksh03.company.local:8191

On the 1st SH (captain), Im getting this warning in the console,

KV Store changed status to failed. 'njosplunksh01.company.local:8191' has data already, cannot initiate set.

I tried cleaning Raft and KV Store, but getting the same results after splunk is restarted,

"rm -rf /opt/splunk/var/run/splunk/_raft/*"
"/opt/splunk/bin/splunk clean kvstore --cluster --answer-yes"
"/opt/splunk/bin/splunk clean raft --answer-yes"

Couldnt find anything in KB for this error. Does anyone know how to troubleshoot this? Thanks.

0 Karma

leonardoguerra1
New Member

Hi, could you solve this problem? If you solved it, can you tell me how?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...