Splunk Enterprise

Kv Store Backup Failing

Fenilleh
Observer

Hello everybody!
The problem that I have is that when I try to make a Backup of the KVStore on my Search Head, it fails after it is done dumping or while dumping the data. 
Splunk tells me to look into the logs but besides some basic info that the backup has failed I cant find any info in splunkd and mongo logs.
From my understanding, it is important that, since I'm using the point_in_time option, I have to make sure no searches are writing into the KV Store when I start the backup. Since Splunk makes a Snapshot of the moment I'm starting the backup, searches that modify the KVStores afterwards shoudln't impact the backup, right?
I made sure no searches have the running status when starting the Backup.
Does anybody have tips or threads that are about this topic?
I thought about stopping the scheduler during the backup, but since there are important searches running I want to look into all the options I have before taking drastic measures.
Thanks for any Tips and Hints in Advance!

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...