Splunk Enterprise

KVstore SSL error

Haleb
Path Finder

Hello there. After updating from 9.3.1 to 9.4.1 my KVstore stoped working. During quick investigation I found the following errors:

2025-03-19T14:35:15.556Z I  NETWORK  [listener] connection accepted from 127.0.0.1:41888 #1188 (1 connection now open)
 2025-03-19T14:35:15.566Z E  NETWORK  [conn1188] SSL peer certificate validation failed: unable to get issuer certificate
 2025-03-19T14:35:15.566Z I  NETWORK  [conn1188] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unable to get issuer certificate. Ending connection from 127.0.0.1:41888 (connection id: 1188)

openssl s_client -connect 127.0.0.1:8191 -showcerts 
gives me valid certificate info. Any idea why I receive this errors? Thx

 

0 Karma
1 Solution

Haleb
Path Finder

I think the easiest way is to use default certificates for KV store.

View solution in original post

0 Karma

Haleb
Path Finder

I think the easiest way is to use default certificates for KV store.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@Haleb 

Hey, take a look at this documentation, I think it covers the same issue you’re running into

Solved: KV Store Failing to start 9.4 .1 - Splunk Community 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...