Monitoring Splunk

KVSTORE FAILED TO START ISSUE

dy1
Loves-to-Learn
KV Store changed status to failed. KVStore process terminated.. 10/2/2025, 12:23:23 am
Failed to start KV Store process. See mongod.log and splunkd.log for details. 10/2/2025, 12:23:23 am
KV Store process terminated abnormally (exit code 4, status PID 6147 killed by signal 4: Illegal instruction). See mongod.log and splunkd.log for details.
 
 
this above mention issues are showing .
 
#kvstore @kvstore @splunk
Labels (4)
0 Karma

myitlab42000
Explorer

hi,

could you check this requirements. For example, is your cpu supported avx / avx2 instructions, if yes, is it enabled ?

https://docs.splunk.com/Documentation/Splunk/9.4.0/Admin/MigrateKVstore

https://www.mongodb.com/docs/manual/administration/production-notes/

i hope this help

Tags (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@dy1 

See the status of the KV store by using the following command.

/opt/splunk/bin/splunk show kvstore-status -auth <user_name>:<password>

Review the mongod.log and splunkd.log files for more detailed error messages.

If there's a lock file causing the issue, you can remove it:

sudo rm -rf /xxx/kvstore/mongo/mongod.lock

Renaming the current MongoDB folder can help reset the KV Store.

mv $SPLUNK_HOME/var/lib/splunk/kvstore/mongo $SPLUNK_HOME/var/lib/splunk/kvstore/mongo.old


Steps:-

Stop Splunk
Rename the current mongo folder to old
Start Splunk
And you will see a new Mongo folder created with all the components.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

richgalloway
SplunkTrust
SplunkTrust

What does mongod.log say?

What version of Splunk?  What version of KVStore?  Are you using mmapv1 or wiredTiger?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Dikshi
Loves-to-Learn Lots

using wiredtiger

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks.  Please answer the other three questions.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...