Splunk Enterprise

Kv Store Backup Failing

Fenilleh
Engager

Hello everybody!
The problem that I have is that when I try to make a Backup of the KVStore on my Search Head, it fails after it is done dumping or while dumping the data. 
Splunk tells me to look into the logs but besides some basic info that the backup has failed I cant find any info in splunkd and mongo logs.
From my understanding, it is important that, since I'm using the point_in_time option, I have to make sure no searches are writing into the KV Store when I start the backup. Since Splunk makes a Snapshot of the moment I'm starting the backup, searches that modify the KVStores afterwards shoudln't impact the backup, right?
I made sure no searches have the running status when starting the Backup.
Does anybody have tips or threads that are about this topic?
I thought about stopping the scheduler during the backup, but since there are important searches running I want to look into all the options I have before taking drastic measures.
Thanks for any Tips and Hints in Advance!

Labels (2)
0 Karma
1 Solution

Fenilleh
Engager

Thanks for Replying! 
The issue was forwarded to Splunk Support by me.
I was told that since the Search Head is standalone, the option point_in_time is not needed.
The update was done successfully and the backup was luckily not required to be used.

View solution in original post

Fenilleh
Engager

Thanks for Replying! 
The issue was forwarded to Splunk Support by me.
I was told that since the Search Head is standalone, the option point_in_time is not needed.
The update was done successfully and the backup was luckily not required to be used.

Bhumi
Path Finder

Hi @Fenilleh 

 

Is the issue resolved or still you are facing an issue? If issue still persists,please paste the error whatsoever you are getting in splunkd and mongod. 

Also, I am attaching one KB article, have a look if that is relevant. 

https://splunk.my.site.com/customer/s/article/KV-Store-Backup-Fails

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...