Monitoring Splunk

KVStore error

Germaine1989
Engager

We get these messages. For exmaple dbconnect doesn't work anymore... how could i solve this?



03-11-2025 12:09:07.792 +0100 WARN  MongoClient [1244 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost

03-11-2025 12:09:07.843 +0100 INFO  KVStoreConfigurationProvider [1244 KVStoreUpgradeStartupThread] - KVSTore peer=127.0.0.1:8191 replication state=KV store captain. Health state=1

03-11-2025 12:09:07.843 +0100 INFO  MongoUpgradePreChecks [1244 KVStoreUpgradeStartupThread] - Supported Upgrade 3

 

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:   File "C:\Program Files\Splunk\Python-3.9\lib\logging\handlers.py", line 115, in rotate

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:     os.rename(source, dest)

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Check KV Store Status

  1. Open Command Prompt as Administrator.
  2. Navigate to your Splunk bin directory:
     
    cd C:\Program Files\Splunk\bin
  3. Run the following command to check KV Store status:
     
    splunk show kvstore-status
  4. If the KV Store is running, you will see a status message indicating it is ready.

Let us know what this shows.

Also - I assume you've already tried restarting Splunk?

I see you've posted errors from splunkd.log - are there any other logs relating to mongo/KV Store, or anything in mongod.log?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

it shows this.. but everything is running

 

Germaine1989_0-1741943922950.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

So you say that Splunk is running on this server but the kvstore-status check says Splunk isnt running??

Is Splunk definitely not installed into 2 locations on that server (e.g. onto another drive/partition/location) ?

If you run restart Splunk and then run that command, what do you get?

cd C:\Program Files\Splunk\bin
splunk restart

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

i restart it and tried again.. now i get this message

 

Germaine1989_0-1741948246535.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

Have you recently upgraded or changed anything in your deployment? Please can you confirm the version and OS you’re running?

Thanks 

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...