Monitoring Splunk

KVStore Process Terminated

splunkuser145
New Member

Splunk installed on windows server, getting the following errors in web UI: 

 

KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details.

KV Store changed status to failed. KVStore process terminated.

Failed to start KV Store process. See mongod.log and splunkd.log for details.

 

Checking mongod.log has the following entry: 

[initandlisten] Detected unclean shutdown - C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\mongod.lock is not empty.
I JOURNAL [initandlisten] journal dir=C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal
I JOURNAL [initandlisten] recover begin
I JOURNAL [initandlisten] info no lsn file in journal/ directory
I JOURNAL [initandlisten] recover lsn: 0
I JOURNAL [initandlisten] recover C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0
F CONTROL [initandlisten] CreateFileW for C:\Program Files\Splunk\var\lib\splunk\kvstore\mongo\journal\j._0 failed with Access is denied. (file size is 8192) in MemoryMappedFile::map
F - [initandlisten] Fatal Assertion 16334 at src\mongo\db\storage\mmap_v1\mmap.cpp 129
F - [initandlisten]
***aborting after fassert() failure

 

Any ideas?

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...