Installation

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for de

rayar
Contributor

Hi

I am getting 

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.

 

I have stopped splunk and moved mongod folder and started it again 

I am getting now 

2021-12-01T13:55:55.528Z W CONTROL [main] net.ssl.sslCipherConfig is deprecated. It will be removed in a future release.
2021-12-01T13:55:55.545Z F NETWORK [main] The provided SSL certificate is expired or not yet valid.
2021-12-01T13:55:55.545Z F - [main] Fatal Assertion 28652 at src/mongo/util/net/ssl_manager.cpp 1120
2021-12-01T13:55:55.545Z F - [main]
***aborting after fassert() failure

and I want to regenerate server.pem

 

just to confirm this is the right command 

$SPLUNK_HOME/bin/splunk createssl

what are the risks   ?

 

Labels (1)
0 Karma

rayar
Contributor

I tried but it fails and I am getting 

 

12-01-2021 19:06:26.395 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.395 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.400 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.400 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 INFO ServerConfig - No '' certificate found. Splunkd communication will not work without this. If this is a fresh installation, this should be OK.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
After that restart splunk should create a new certificate. Can you validate it now with splunk cmd openssl command?
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

rayar
Contributor

I have removed the server.pem and restarted the Splunk server and it didn't work

was not able to login Splunk 

this is the reason I wanted to renew the server.pem manually 

[splunk@ilissplsh01 bin]$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Nov 17 08:28:40 2021 GMT
[splunk@ilissplsh01 bin]$

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you restore the mongod folder back to it’s original place and then try restart again without cert?
0 Karma

rayar
Contributor

I have resolved it working with Splunk support , some server.conf configuration was missing 

we are still investigating 

0 Karma

Muwafi
Path Finder

Hello @rayar  , have you solved this issue ? if so, would you please update us and post the solution here?

 

Thanks 

0 Karma

rayar
Contributor

sorry its a very old issue I don't remember what was the solution 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...