Monitoring Splunk

KVStore Process Terminated

splunkuser145
New Member

Splunk installed on windows server, getting the following errors in web UI: 

 

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.

KV Store changed status to failed. KVStore process terminated.

Failed to start KV Store process. See mongod.log and splunkd.log for details.

 

Checking mongod.log has the following entry: 

[initandlisten] Detected unclean shutdown - C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\mongod.lock is not empty.
I JOURNAL [initandlisten] journal dir=C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal
I JOURNAL [initandlisten] recover begin
I JOURNAL [initandlisten] info no lsn file in journal/ directory
I JOURNAL [initandlisten] recover lsn: 0
I JOURNAL [initandlisten] recover C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0
F CONTROL [initandlisten] CreateFileW for C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0 failed with Access is denied. (file size is 8192) in MemoryMappedFile::map
F - [initandlisten] Fatal Assertion 16334 at src\mongo\db\storage\mmap_v1\mmap.cpp 129
F - [initandlisten]
***aborting after fassert() failure

 

Any ideas?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...