Installation

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for de

rayar
Contributor

Hi

I am getting 

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.

 

I have stopped splunk and moved mongod folder and started it again 

I am getting now 

2021-12-01T13:55:55.528Z W CONTROL [main] net.ssl.sslCipherConfig is deprecated. It will be removed in a future release.
2021-12-01T13:55:55.545Z F NETWORK [main] The provided SSL certificate is expired or not yet valid.
2021-12-01T13:55:55.545Z F - [main] Fatal Assertion 28652 at src/mongo/util/net/ssl_manager.cpp 1120
2021-12-01T13:55:55.545Z F - [main]
***aborting after fassert() failure

and I want to regenerate server.pem

 

just to confirm this is the right command 

$SPLUNK_HOME/bin/splunk createssl

what are the risks   ?

 

Labels (1)
0 Karma

rayar
Contributor

I tried but it fails and I am getting 

 

12-01-2021 19:06:26.395 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.395 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.400 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 WARN ConfigEncryptor - Invalid setting for server.conf/[general]/legacyCiphers
12-01-2021 19:06:26.400 +0200 ERROR ConfigEncryptor - server.conf/[general]/legacyCiphers is misconfigured.
12-01-2021 19:06:26.400 +0200 INFO ServerConfig - No '' certificate found. Splunkd communication will not work without this. If this is a fresh installation, this should be OK.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
After that restart splunk should create a new certificate. Can you validate it now with splunk cmd openssl command?
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

rayar
Contributor

I have removed the server.pem and restarted the Splunk server and it didn't work

was not able to login Splunk 

this is the reason I wanted to renew the server.pem manually 

[splunk@ilissplsh01 bin]$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Nov 17 08:28:40 2021 GMT
[splunk@ilissplsh01 bin]$

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you restore the mongod folder back to it’s original place and then try restart again without cert?
0 Karma

rayar
Contributor

I have resolved it working with Splunk support , some server.conf configuration was missing 

we are still investigating 

0 Karma

Muwafi
Path Finder

Hello @rayar  , have you solved this issue ? if so, would you please update us and post the solution here?

 

Thanks 

0 Karma

rayar
Contributor

sorry its a very old issue I don't remember what was the solution 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...