Monitoring Splunk

KVStore error

Germaine1989
Engager

We get these messages. For exmaple dbconnect doesn't work anymore... how could i solve this?



03-11-2025 12:09:07.792 +0100 WARN  MongoClient [1244 KVStoreUpgradeStartupThread] - Disabling TLS hostname validation for localhost

03-11-2025 12:09:07.843 +0100 INFO  KVStoreConfigurationProvider [1244 KVStoreUpgradeStartupThread] - KVSTore peer=127.0.0.1:8191 replication state=KV store captain. Health state=1

03-11-2025 12:09:07.843 +0100 INFO  MongoUpgradePreChecks [1244 KVStoreUpgradeStartupThread] - Supported Upgrade 3

 

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:   File "C:\Program Files\Splunk\Python-3.9\lib\logging\handlers.py", line 115, in rotate

03-11-2025 12:09:11.773 +0100 ERROR PersistentScript [2200 PersistentScriptIo] - From {"C:\Program Files\Splunk\bin\Python3.9.exe" "C:\Program Files\Splunk\Python-3.9\Lib\site-packages\splunk\persistconn\appserver.py"}:     os.rename(source, dest)

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Check KV Store Status

  1. Open Command Prompt as Administrator.
  2. Navigate to your Splunk bin directory:
     
    cd C:\Program Files\Splunk\bin
  3. Run the following command to check KV Store status:
     
    splunk show kvstore-status
  4. If the KV Store is running, you will see a status message indicating it is ready.

Let us know what this shows.

Also - I assume you've already tried restarting Splunk?

I see you've posted errors from splunkd.log - are there any other logs relating to mongo/KV Store, or anything in mongod.log?

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

it shows this.. but everything is running

 

Germaine1989_0-1741943922950.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

So you say that Splunk is running on this server but the kvstore-status check says Splunk isnt running??

Is Splunk definitely not installed into 2 locations on that server (e.g. onto another drive/partition/location) ?

If you run restart Splunk and then run that command, what do you get?

cd C:\Program Files\Splunk\bin
splunk restart

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

Germaine1989
Engager

i restart it and tried again.. now i get this message

 

Germaine1989_0-1741948246535.png

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Germaine1989 

Have you recently upgraded or changed anything in your deployment? Please can you confirm the version and OS you’re running?

Thanks 

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma

Germaine1989
Engager

yes we upgraded to 9.3 on windows server 2019

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...