Splunk Enterprise

Splunk 9 Universal Forwarder getting "[App Key Value Store migration] " error after upgrade from Splunk 8.2.4

vksplunk1
Explorer

Hi ,

Splunk 9 Universal Forwarder getting "[app key value store migration collection data is not available] " error after upgrade from Splunk 8.2.4.    Splunk is not starting

 

app key value store migration collection data is not available

 

Why is UF is looking for KV Store ?

 

Any suggestion to resolve it

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this is a known issue on those 9.0.x UF even it's not documented on release notes!

You can try to add this to the server.conf

[kvstore]
disabled = true

 and test it this helps.

Anyhow there shouldn't be any kvstore running on UFs! It's only needed on search heads.

r. Ismo

likedasplunk
Path Finder

@isoutamo 

I added that stanza to server.conf and I still get prompted for interactive login. No matter what I do or try, I still get prompted for Nix UF 9.0.3. Is there any update on this?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...