Knowledge Management

KV store issue for collection SavedSearchHistory

lqiao
Explorer

From time to time, I am getting below warning:

WARN SavedSearchHistory - Can't persist saved-search history due to the KV-Store either being disabled or failing

It doesn't appear all the time, just randomly. What does this message mean? How to fix this? We have KV-Store enabled. Thanks.

Tags (1)
0 Karma

nunoaragao
Path Finder

Old thread, but leaving it here in hope other people might chip in. 

Also seen the same WARNs, at a time we suffered from KV Store consuming a whole lot of CPU and wiredTigerCacheSizeGB, over 15 times the sum of any collection. Opening a Splunk Support case we were told:

Splunk does not use KV Store to manage or store the history of scheduled searches. Scheduled searches are managed and tracked via internal logs, dispatch directories, and internal indexes, not KV Store

However, we occasionally see those events on Search Heads, and frequently on Heavy Forwarders on role of parsing and routing, not connected to License Manager and disabled KV Store.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...