My kvstore is failed and I am trying to renew my certificate, my Splunk server is on a windows server. I have tried the steps by removing the server.pem and server_pkcs1.pem from ..\Splunk\etc\auth\ as well as delete the expired Cert SplunkServerDefaultCert from Cerlm. this method worked for me in four other deployments however this one deployment, when I go start my Splunk services, I get failure to start Splunkd with an error message " Unable to generate certificate for SSL. Splunkd port communication may not work (Child failed to start: FormatMessage was unable to decode error (193), (0xc1)) SSL certificate generation failed.
check permission issue in log files
splunkd ... mongod logs
Check file ownership and permission for server.pem, server.key