Monitoring Splunk

KVStore error

Germaine1989
Engager

We get these messages. For exmaple dbconnect doesn't work anymore... how could i solve this?



03-11-2025 12:09:07.792 +0100 WARN  MongoClient [1244 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost

03-11-2025 12:09:07.843 +0100 INFO  KVStoreConfigurationProvider [1244 KVStoreUpgradeStartupThread] - KVSTore peer=127.0.0.1:8191 replication state=KV store captain. Health state=1

03-11-2025 12:09:07.843 +0100 INFO  MongoUpgradePreChecks [1244 KVStoreUpgradeStartupThread] - Supported Upgrade 3

 

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:   File "C:\Program Files\Splunk\Python-3.9\lib\logging\handlers.py", line 115, in rotate

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:     os.rename(source, dest)

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Check KV Store Status

  1. Open Command Prompt as Administrator.
  2. Navigate to your Splunk bin directory:
     
    cd C:\Program Files\Splunk\bin
  3. Run the following command to check KV Store status:
     
    splunk show kvstore-status
  4. If the KV Store is running, you will see a status message indicating it is ready.

Let us know what this shows.

Also - I assume you've already tried restarting Splunk?

I see you've posted errors from splunkd.log - are there any other logs relating to mongo/KV Store, or anything in mongod.log?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

it shows this.. but everything is running

 

Germaine1989_0-1741943922950.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

So you say that Splunk is running on this server but the kvstore-status check says Splunk isnt running??

Is Splunk definitely not installed into 2 locations on that server (e.g. onto another drive/partition/location) ?

If you run restart Splunk and then run that command, what do you get?

cd C:\Program Files\Splunk\bin
splunk restart

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

i restart it and tried again.. now i get this message

 

Germaine1989_0-1741948246535.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

Have you recently upgraded or changed anything in your deployment? Please can you confirm the version and OS you’re running?

Thanks 

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...