Splunk Enterprise

KVStore is not ready. Token auth system will not work.

whrg
Motivator

When I navigate to Settings > Tokens, I get this error message:

 

KVStore is not ready. Token auth system will not work.

 

Splunk logs shows this:

 

ERROR JsonWebToken [233289 TcpChannelThread] - KVStore is not ready. Token auth system will not work.
ERROR KVStoreConfigurationProvider [233052 KVStoreConfigurationThread] - Failed to start mongod on first attempt reason=KVStore service will not start because kvstore process terminated
ERROR KVStoreBulletinBoardManager [233053 MongodLogThread] - KV Store changed status to failed. KVStore process terminated..

 

How can this be fixed?

 

Labels (1)
0 Karma
1 Solution

whrg
Motivator

I found the solution which I came across here: https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701

Turns out, the Splunk certificate was expired. This is how I checked:

$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Feb 27 13:56:21 2024 GMT

To get a new certificate, I removed the old certificate and restarted Splunk (a new certificate will be created when Splunk starts):

$ mv /opt/splunk/etc/auth/server.pem /opt/splunk/etc/auth/server.pem.backup

Now Settings > Tokens is working again.

 

View solution in original post

0 Karma

whrg
Motivator

I found the solution which I came across here: https://community.splunk.com/t5/Security/How-do-I-renew-an-expired-Splunk-Certificate/m-p/389701

Turns out, the Splunk certificate was expired. This is how I checked:

$ openssl x509 -enddate -noout -in /opt/splunk/etc/auth/server.pem
notAfter=Feb 27 13:56:21 2024 GMT

To get a new certificate, I removed the old certificate and restarted Splunk (a new certificate will be created when Splunk starts):

$ mv /opt/splunk/etc/auth/server.pem /opt/splunk/etc/auth/server.pem.backup

Now Settings > Tokens is working again.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you looked from mongod.log (or something similar) why mongod didn’t start?
r. Ismo
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...