Monitoring Splunk

KV store: Why is KV Store initialization failing?


I have an issue with KV store "KV Store initialization failed" and to overcome with this issue. I have followed below steps and after that no new error shown for "KV Store initialization failed". But after that all the entries under KV store lookup got vanished. Please help me how I should restore the entries. If restore is not possible then what is the other possible solution to restore the entries.

  • Stop Splunk
  • rename the current mongo folder to old
  • Start Splunk
  • And you will see a new mongo folder created with all the components.


Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...