Getting Data In

Kv store status showing failed not able to start?

sekhar463
Path Finder

Getting errors as Failed to start KV Store process. See mongod.log and splunkd.log for details.

tried few steps by rm -rf /data1/kvstore/mongo/mongod.lock followed by restart but still showing status as failed 

please let us know on this to resolve

 

/opt/splunk/bin #systemctl status Splunkd
● Splunkd.service - Systemd service file for Splunk, generated by 'splunk enable boot-start'
Loaded: loaded (/etc/systemd/system/Splunkd.service; enabled; vendor preset: disabled)
Active: active (running) since Wed 2022-10-12 11:02:22 CDT; 9s ago
Main PID: 28477 (splunkd)
Tasks: 7
Memory: 111.6M (limit: 100.0G)
CGroup: /system.slice/Splunkd.service
├─28477 splunkd --under-systemd --systemd-delegate=yes -p 8089 _internal_launch_under_systemd
├─28530 [splunkd pid=28477] splunkd --under-systemd --systemd-delegate=yes -p 8089 _internal_launch_under_systemd [process-runner]
└─28558 /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_TA_aws/bin/aws_billing_cur.py --scheme

Oct 12 11:02:24 usappslnglp100 splunk[28477]: Checking critical directories... Done
Oct 12 11:02:24 usappslnglp100 splunk[28477]: Checking indexes...
Oct 12 11:02:24 usappslnglp100 splunk[28477]: Validated: _audit _internal _introspection _metrics _telemetry _thefishbucket add_on_builder_index ...rts ivz_o
Oct 12 11:02:24 usappslnglp100 splunk[28477]: Done
Oct 12 11:02:25 usappslnglp100 splunk[28477]: Checking filesystem compatibility... Done
Oct 12 11:02:25 usappslnglp100 splunk[28477]: Checking conf files for problems...
Oct 12 11:02:25 usappslnglp100 splunk[28477]: Done
Oct 12 11:02:25 usappslnglp100 splunk[28477]: Checking default conf files for edits...
Oct 12 11:02:25 usappslnglp100 splunk[28477]: Validating installed files against hashes from '/opt/splunk/splunk-8.0.1-6db836e2fb9e-linux-2.6-x86...manifest'
Oct 12 11:02:25 usappslnglp100 splunk[28477]: 2022-10-12 11:02:25.875 -0500 splunkd started (build 6db836e2fb9e) pid=28477
Hint: Some lines were ellipsized, use -l to show in full.
root@usappslnglp100:/opt/splunk/bin #./splunk show kvstore-status
Your session is invalid. Please login.
Splunk username: admin
Password:

This member:
backupRestoreStatus : Ready
disabled : 0
guid : 45F2DDC2-C57A-4A47-B6C9-3523E0D936E6
port : 8191
standalone : 1
status : failed

 

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...