Monitoring Splunk

KVStore error

Germaine1989
Engager

We get these messages. For exmaple dbconnect doesn't work anymore... how could i solve this?



03-11-2025 12:09:07.792 +0100 WARN  MongoClient [1244 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost

03-11-2025 12:09:07.843 +0100 INFO  KVStoreConfigurationProvider [1244 KVStoreUpgradeStartupThread] - KVSTore peer=127.0.0.1:8191 replication state=KV store captain. Health state=1

03-11-2025 12:09:07.843 +0100 INFO  MongoUpgradePreChecks [1244 KVStoreUpgradeStartupThread] - Supported Upgrade 3

 

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:   File "C:\Program Files\Splunk\Python-3.9\lib\logging\handlers.py", line 115, in rotate

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:     os.rename(source, dest)

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Check KV Store Status

  1. Open Command Prompt as Administrator.
  2. Navigate to your Splunk bin directory:
     
    cd C:\Program Files\Splunk\bin
  3. Run the following command to check KV Store status:
     
    splunk show kvstore-status
  4. If the KV Store is running, you will see a status message indicating it is ready.

Let us know what this shows.

Also - I assume you've already tried restarting Splunk?

I see you've posted errors from splunkd.log - are there any other logs relating to mongo/KV Store, or anything in mongod.log?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

it shows this.. but everything is running

 

Germaine1989_0-1741943922950.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

So you say that Splunk is running on this server but the kvstore-status check says Splunk isnt running??

Is Splunk definitely not installed into 2 locations on that server (e.g. onto another drive/partition/location) ?

If you run restart Splunk and then run that command, what do you get?

cd C:\Program Files\Splunk\bin
splunk restart

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

i restart it and tried again.. now i get this message

 

Germaine1989_0-1741948246535.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

Have you recently upgraded or changed anything in your deployment? Please can you confirm the version and OS you’re running?

Thanks 

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...