Installation

kvstore failing to start

tinscore
New Member

Trying to run splunk in a docker container - which I can successfully get running.

however...

Once I try to add a persistent volume for /splunkhome/var and /splunkhome/etc, the kvstore fails to start.

The persistent volume is being hosted on a NAS (synology diskstation) which is being mounted to my linux host via SMB (cifs) with the local admin of the NAS - so I should have full permissions to the share.

I've been able to observe the following error

"homePath='/opt/splunk/var/lib/splunk/audit/db' of index=_audit on unusable filesystem."

are SMB file shares not supposed by splunk?

I can get past this error by adding "OPSIMISTIC_ABOUT_FILE_LOCKING = 1"
to splunk-launch.conf

but then I get stuck with where kvstore failing to start.  kvstore logs indicate it's because the permissions are too open - even though I've changed them to 400.

 

Any insight from your beautiful minds?

Labels (1)
0 Karma

BartZm
New Member

You need to unmount "/opt/splunk/var/lib/splunk/kvstore/mongo" folder.

Eg. in docker-compose

volumes:
- "/home/docker_volumes/etc:/opt/splunk/etc"
- "/home/docker_volumes/var:/opt/splunk/var"
- "/opt/splunk/var/lib/splunk/kvstore/mongo"

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...