Getting Data In

TA-pps_ondemand Error: KV Store is disabled

chandrag
Explorer

In Splunk Cloud for one of my client environment, I'm seeing below message.

TA-pps_ondemand Error: KV Store is disabled. Please enable it to start the data collection.

Please help me with suitable solution.

Labels (4)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @chandrag ,

on Splunk Cloud you have few chances for action, open a case to Splunk Cloud Support.

It seems that KV-Store is disabled in one component of your architecture and this is a best practice for Indexers and Heavy Forwarder, but the Add-On you're using requires KV-Store.

Ciao.

Giuseppe

View solution in original post

aquinol
Explorer

I have the same issue. I'm on the Victoria distro of Splunk cloud.  I opened a ticket with Splunk support and they say that the KV Store/Service is already enabled and running on our stack and to go to proofpoint to fix.  I can't install an older version of the app to see if it works because I'm on cloud.  Proofpoint initially tried to kick it back to splunk saying it's a splunk issue, so I don't know what else to do.  I tried uninstalling and reinstalling the app, restarting the cloud stack, etc, so I'm basically stuck. 

gcusello
SplunkTrust
SplunkTrust

Hi @chandrag ,

on Splunk Cloud you have few chances for action, open a case to Splunk Cloud Support.

It seems that KV-Store is disabled in one component of your architecture and this is a best practice for Indexers and Heavy Forwarder, but the Add-On you're using requires KV-Store.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...