Knowledge Management

Why does my KVStore replicationStatus show recovering?

satyaallaparthi
Communicator

Hello,

I have a problem with my replication status.. getting the below result when ever I am trying to see kvstore status.

host 2 replication status is showing recovering from past 1 week.

I tried to resync both shcluster config using "splunk resync shcluster-replicated-config" and kvstore using "splunk resync kvstore -source MyGUID"

But, both didn't work.

Any help would be appreciated.

This member:
backupRestoreStatus : Ready
date : Mon Feb 3 15:50:19 2020
dateSec : 1580763019.583
disabled : 0
guid : ****-46ED-450B-BE21-******
oplogEndTimestamp : Mon Feb 3 15:50:18 2020
oplogEndTimestampSec : 1580763018
oplogStartTimestamp : Mon Feb 3 06:06:00 2020
oplogStartTimestampSec : 1580727960
port : 8191
replicaSet : splunkrs
replicationStatus : KV store captain
standalone : 0
status : ready

Enabled KV store members:
host1:8191
guid : ****-46ED-450B-BE21-******
hostAndPort : host1:8191
host2:8191
guid : ***-9A10-4962-9A3F-******
hostAndPort : host2:8191
host3:8191
guid : ****-F4B3-4E58-B765-*******
hostAndPort : host3:8191

KV store members:
host1:8191
configVersion : 205602
hostAndPort : host1:8191
lastHeartbeat : Mon Feb 3 15:50:17 2020
lastHeartbeatRecv : Mon Feb 3 15:50:17 2020
lastHeartbeatRecvSec : 1580763017.874
lastHeartbeatSec : 1580763017.873
optimeDate : Mon Feb 3 15:50:14 2020
optimeDateSec : 1580763014
pingMs : 0
replicationStatus : Non-captain KV store member
uptime : 253492

   host2:8191
                             configVersion : 205602
                               hostAndPort : host:8191
                             lastHeartbeat : Mon Feb  3 15:50:17 2020
                         lastHeartbeatRecv : Mon Feb  3 15:50:19 2020
                      lastHeartbeatRecvSec : 1580763019.366
                          lastHeartbeatSec : 1580763017.873
                                optimeDate : Wed Oct  2 11:09:46 2019
                             optimeDateSec : 1570028986
                                    pingMs : 0
                         replicationStatus : Recovering
                                    uptime : 253417

    host3:8191
                             configVersion : 205602
                              electionDate : Fri Jan 24 21:18:18 2020
                           electionDateSec : 1579918698
                               hostAndPort : host3:8191
                                optimeDate : Mon Feb  3 15:50:18 2020
                             optimeDateSec : 1580763018
                         replicationStatus : KV store captain
                                    uptime : 844587

Thanks,

Labels (1)
Tags (2)
0 Karma

mustapha_arakji
Splunk Employee
Splunk Employee
0 Karma

jaihingorani
Path Finder

if resyn does not work, you can try below, it has been working for me so far :
1. stop the splunk.
2../splunk clean kvstore --local
3. start splunk.

This triggers the initial Synchronization from other KVstore members

humrish_b
Explorer

@satyaallaparthi  did you try the steps provided by @jaihingorani  was it successful. Could you let me know how this issue is resolved.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...