Monitoring Splunk

KVSTORE FAILED TO START ISSUE

dy1
Loves-to-Learn
KV Store changed status to failed. KVStore process terminated.. 10/2/2025, 12:23:23 am
Failed to start KV Store process. See mongod.log and splunkd.log for details. 10/2/2025, 12:23:23 am
KV Store process terminated abnormally (exit code 4, status PID 6147 killed by signal 4: Illegal instruction). See mongod.log and splunkd.log for details.
 
 
this above mention issues are showing .
 
#kvstore @kvstore @splunk
Labels (4)
0 Karma

myitlab42000
Explorer

hi,

could you check this requirements. For example, is your cpu supported avx / avx2 instructions, if yes, is it enabled ?

https://docs.splunk.com/Documentation/Splunk/9.4.0/Admin/MigrateKVstore

https://www.mongodb.com/docs/manual/administration/production-notes/

i hope this help

Tags (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@dy1 

See the status of the KV store by using the following command.

/opt/splunk/bin/splunk show kvstore-status -auth <user_name>:<password>

Review the mongod.log and splunkd.log files for more detailed error messages.

If there's a lock file causing the issue, you can remove it:

sudo rm -rf /xxx/kvstore/mongo/mongod.lock

Renaming the current MongoDB folder can help reset the KV Store.

mv $SPLUNK_HOME/var/lib/splunk/kvstore/mongo $SPLUNK_HOME/var/lib/splunk/kvstore/mongo.old


Steps:-

Stop Splunk
Rename the current mongo folder to old
Start Splunk
And you will see a new Mongo folder created with all the components.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

richgalloway
SplunkTrust
SplunkTrust

What does mongod.log say?

What version of Splunk?  What version of KVStore?  Are you using mmapv1 or wiredTiger?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Dikshi
Loves-to-Learn Lots

using wiredtiger

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks.  Please answer the other three questions.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...