Knowledge Management

ERROR: The kvstore port [foo] is already bound. Splunk needs to use this port.

_gkollias
SplunkTrust
SplunkTrust

Hi,

Rather than seeing a mgmt port bound error, I am seeing kvstore port is already bound. I ran ps -aux | grep <port> and noticed a mongod process taking up the port. Does mongod correspond to Splunk's KV store? Just trying to see if there is any connection between the two before killing the process ID and restarting the indexer. Any insight is greatly appreciated.

Thanks in advance

0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

Yes, KVStore's engine is tight related to mongodb process built in Splunk package. The port number must be set in [kvstore] stanza in server.conf. If you are not running any Splunk instances and the port is taken by a mongo process, most likely you are safe to kill the process.

View solution in original post

Masa
Splunk Employee
Splunk Employee

Yes, KVStore's engine is tight related to mongodb process built in Splunk package. The port number must be set in [kvstore] stanza in server.conf. If you are not running any Splunk instances and the port is taken by a mongo process, most likely you are safe to kill the process.

Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...