Splunk Enterprise

KVStore is not ready. Token auth system will not work.

whrg
Motivator

When I navigate to Settings > Tokens, I get this error message:

 

KVStore is not ready. Token auth system will not work.

 

Splunk logs shows this:

 

ERROR JsonWebToken [233289 TcpChannelThread] - KVStore is not ready. Token auth system will not work.
ERROR KVStoreConfigurationProvider [233052 KVStoreConfigurationThread] - Failed to start mongod on first attempt reason=KVStore service will not start because kvstore process terminated
ERROR KVStoreBulletinBoardManager [233053 MongodLogThread] - KV Store changed status to failed. KVStore process terminated..

 

How can this be fixed?

 

Labels (1)
0 Karma
1 Solution

whrg
Motivator

I found the solution which I came across here: https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701

Turns out, the Splunk certificate was expired. This is how I checked:

$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Feb 27 13:56:21 2024 GMT

To get a new certificate, I removed the old certificate and restarted Splunk (a new certificate will be created when Splunk starts):

$ mv /opt/splunk/etc/auth/server.pem /opt/splunk/etc/auth/server.pem.backup

Now Settings > Tokens is working again.

 

View solution in original post

0 Karma

whrg
Motivator

I found the solution which I came across here: https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701

Turns out, the Splunk certificate was expired. This is how I checked:

$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Feb 27 13:56:21 2024 GMT

To get a new certificate, I removed the old certificate and restarted Splunk (a new certificate will be created when Splunk starts):

$ mv /opt/splunk/etc/auth/server.pem /opt/splunk/etc/auth/server.pem.backup

Now Settings > Tokens is working again.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you looked from mongod.log (or something similar) why mongod didn’t start?
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...