Installation

SSL Installation + KV Store error

chaitali_1994
Engager

I have a distributed environment where the Splunk instances are clustered and the version  I am using is 6.6.3. The server certificates are expired and there is no SSL communication enabled between Splunk servers. I have few queries:

1. How to enable the SSL communication?

2. How expired server certs are  going to impact  my Splunk environment?

3. How to know from the existing configurations, if there is any SSL communication between Splunk instances?

4. How can I resolve this error:

a. KV store changed its status to failed. KV store process terminated.

b. Failed to start KV store process. See mongod.log and splunkd.log for details.

c. KV store process terminated abnormally(exit code 14, status exited with code 14)

Labels (1)
0 Karma

aasabatini
Motivator

Hi @chaitali_1994 

as for certificates, you should upgrade splunk versions to be able to use unexpired certificates

how to use certificates you can follow this link:

https://docs.splunk.com/Documentation/Splunk/8.1.3/Security/ConfigureSplunkforwardingtousethedefault...

 

and for your kvstore error I suggest to  backup and resync your collection.

https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/BackupKVstore

https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/BackupKVstore

karma point or solution confirmation is appreciated

 

 

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...