Monitoring Splunk

KVStore error

Germaine1989
Engager

We get these messages. For exmaple dbconnect doesn't work anymore... how could i solve this?



03-11-2025 12:09:07.792 +0100 WARN  MongoClient [1244 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost

03-11-2025 12:09:07.843 +0100 INFO  KVStoreConfigurationProvider [1244 KVStoreUpgradeStartupThread] - KVSTore peer=127.0.0.1:8191 replication state=KV store captain. Health state=1

03-11-2025 12:09:07.843 +0100 INFO  MongoUpgradePreChecks [1244 KVStoreUpgradeStartupThread] - Supported Upgrade 3

 

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:   File "C:\Program Files\Splunk\Python-3.9\lib\logging\handlers.py", line 115, in rotate

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:     os.rename(source, dest)

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Check KV Store Status

  1. Open Command Prompt as Administrator.
  2. Navigate to your Splunk bin directory:
     
    cd C:\Program Files\Splunk\bin
  3. Run the following command to check KV Store status:
     
    splunk show kvstore-status
  4. If the KV Store is running, you will see a status message indicating it is ready.

Let us know what this shows.

Also - I assume you've already tried restarting Splunk?

I see you've posted errors from splunkd.log - are there any other logs relating to mongo/KV Store, or anything in mongod.log?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

it shows this.. but everything is running

 

Germaine1989_0-1741943922950.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

So you say that Splunk is running on this server but the kvstore-status check says Splunk isnt running??

Is Splunk definitely not installed into 2 locations on that server (e.g. onto another drive/partition/location) ?

If you run restart Splunk and then run that command, what do you get?

cd C:\Program Files\Splunk\bin
splunk restart

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

i restart it and tried again.. now i get this message

 

Germaine1989_0-1741948246535.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

Have you recently upgraded or changed anything in your deployment? Please can you confirm the version and OS you’re running?

Thanks 

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...