Splunk Enterprise

Assistance needed with kvstore migration

JSwofford
New Member

I've got a new deployment of 9.1.1, upgraded from a prior version, I can't remember which off the top of my head.  I am running Windows 2019 btw, if there is any relevance.

 

When I log in I get the following message

 

 

Failed to upgrade KV Store to the latest version. KV Store is running an old version, service(36). Resolve upgrade errors and try to upgrade KV Store to the latest version again. Learn more.
11/20/2023, 12:04:48 PM

 

 

 

If I shutdown splunkd, then run 
splunk.exe migrate migrate-kvstore -v 

I'll get the following error.

 

 

[App Key Value Store migration] Starting migrate-kvstore.
Started standalone KVStore update, start_time="2023-11-20 12:00:29".
failed to add license to stack enterprise, err - stack already has this license, cannot add again

[App Key Value Store migration] Checking if migration is needed. Upgrade type 1. This can take up to 600seconds.

 2023-11-20T17:00:30.187Z W CONTROL  [main] net.ssl.sslCipherConfig is deprecated. It will be removed in a future release.

 2023-11-20T17:00:30.193Z F CONTROL  [main] Failed global initialization: InvalidSSLConfiguration: CertAddCertificateContextToStore Failed  The object or property already exists.
mongod exited abnormally (exit code 1, status: exited with code 1) - look at mongod.log to investigate.
KV Store process terminated abnormally (exit code 1, status exited with code 1). See mongod.log and splunkd.log for details.

WARN: [App Key Value Store migration] Service(40) terminated before the service availability check could complete. Exit code 1, waited for 0 seconds.
App Key Value Store migration failed, check the migration log for details. After you have addressed the cause of the service failure, run the migration again, otherwise App Key Value Store won't function.

 

 

No entries are ever posted to mongod.log.

Just to verify, I cleanred out the var/log/splunk directory.  Moving the folder, and upon running the command, the folders are generated, but the mongod.log file is never created.

 

Any Advice on how to get the kvstore to migrate?

 

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you check that your server.pem is still valid? Anyhow there should be log entry on mogodb.log if this is the issue.
You also have enough free disk space on your node?
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...