Knowledge Management

Failed to start KV store

corti77
Contributor

Hi,

I run splunk 9.0.8 and after an issue with our storage (LUN full). I had to full scan the disk and successfully repaired the filesystem.

splunk starts now but there is a persistent error with the KV store. the status is the following:

show kvstore-status

This member:
backupRestoreStatus : Ready
disabled : 0
guid : E59FAAA8-D66A-498E-8DDF-0F5C29866F95
port : 8191
standalone : 1
status : failed
storageEngine : wiredTiger

Any suggestion on how could get an operational status?

many thanks.

Jose

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @corti77 ,

you have to reset the mongod.lock:

  • stop splunkd
  • delete $SPLUNK_HOME\var\lib\splunk\kvstore\mongo\mongod.lock"
  • start splunkd

I asked to Splunk ideas to create a script od a dedicated solution to this frequent issue, if you think as me that's important, please vote for this idea at https://ideas.splunk.com/ideas/EID-I-2058

Ciao.

Giuseppe

View solution in original post

corti77
Contributor

just voted, thanks a lot

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @corti77 ,

you have to reset the mongod.lock:

  • stop splunkd
  • delete $SPLUNK_HOME\var\lib\splunk\kvstore\mongo\mongod.lock"
  • start splunkd

I asked to Splunk ideas to create a script od a dedicated solution to this frequent issue, if you think as me that's important, please vote for this idea at https://ideas.splunk.com/ideas/EID-I-2058

Ciao.

Giuseppe

Ogorek
Engager

Hello, what to do when my kvstore folder just vanished? It do not create again after restart. Tried to create new folder with splunk privileges but it wont help. Do u have any idea how to reapir this? 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

It’s go time — Boston, here we come!

Are you ready to take your Splunk skills to the next level? Get set, because Splunk University is back, and ...