Monitoring Splunk

KVStore Process Terminated

splunkuser145
New Member

Splunk installed on windows server, getting the following errors in web UI: 

 

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.

KV Store changed status to failed. KVStore process terminated.

Failed to start KV Store process. See mongod.log and splunkd.log for details.

 

Checking mongod.log has the following entry: 

[initandlisten] Detected unclean shutdown - C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\mongod.lock is not empty.
I JOURNAL [initandlisten] journal dir=C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal
I JOURNAL [initandlisten] recover begin
I JOURNAL [initandlisten] info no lsn file in journal/ directory
I JOURNAL [initandlisten] recover lsn: 0
I JOURNAL [initandlisten] recover C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0
F CONTROL [initandlisten] CreateFileW for C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0 failed with Access is denied. (file size is 8192) in MemoryMappedFile::map
F - [initandlisten] Fatal Assertion 16334 at src\mongo\db\storage\mmap_v1\mmap.cpp 129
F - [initandlisten]
***aborting after fassert() failure

 

Any ideas?

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...