Splunk Enterprise

KVstore SSL error

Haleb
Path Finder

Hello there. After updating from 9.3.1 to 9.4.1 my KVstore stoped working. During quick investigation I found the following errors:

2025-03-19T14:35:15.556Z I  NETWORK  [listener] connection accepted from 127.0.0.1:41888 #1188 (1 connection now open)
 2025-03-19T14:35:15.566Z E  NETWORK  [conn1188] SSL peer certificate validation failed: unable to get issuer certificate
 2025-03-19T14:35:15.566Z I  NETWORK  [conn1188] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unable to get issuer certificate. Ending connection from 127.0.0.1:41888 (connection id: 1188)

openssl s_client -connect 127.0.0.1:8191 -showcerts 
gives me valid certificate info. Any idea why I receive this errors? Thx

 

0 Karma
1 Solution

Haleb
Path Finder

I think the easiest way is to use default certificates for KV store.

View solution in original post

0 Karma

Haleb
Path Finder

I think the easiest way is to use default certificates for KV store.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@Haleb 

Hey, take a look at this documentation, I think it covers the same issue you’re running into

Solved: KV Store Failing to start 9.4 .1 - Splunk Community 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...