Splunk Enterprise Security

What steps must I do to resolve KVStore status Failed?

Spinner79
Explorer

Hi all,

need some help. my SH2 kvstore is always showing "Status: Failed" despite me reinstalling entire Splunk Enterprise 

Below mentioned steps done but still no luck:

- Rebuild Splunk Enterprise

- Recreated Self sign Cert

- removed and rebuild Mongo 

- revert back to Splunk default Self Sign cert Kvstore shows Ready but not on created self sign cert.

 

Labels (1)
Tags (2)
0 Karma

woodcock
Esteemed Legend

Stop Splunk, remove $SPLUNK_HOME/*, reinstall Splunk, start Splunk.

Tags (1)
0 Karma

tscroggins
Influencer

Hi,

Have you added your self-signed certificate to $SPLUNK_HOME/etc/auth/cacert.pem?

What errors (E) or warnings (W) are logged to $SPLUNK_HOME/var/log/splunk/mongod.log just before mongod shuts down?

0 Karma

Spinner79
Explorer

Hi

Today i tried reinstalling everything on to the similar server with fresh OS reinstalled still the same.

I have 2 SH my SH1 do not have this problem only my SH2 have this issue and both configured the same way.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...