Splunk Enterprise

when backup kvStore using "-auth" option

tkdguq0110
Path Finder

Hello.

Currently, SH's Enterprise core version is 9.2.7.

I'm performing daily kvStore backups on SH using the following command:

./splunk backup kvstore -archiveName "archiveName" -auth user:'password'

I confirmed that the above command successfully backs up kvStore, even though the user password is different.

I can't find the -auth option in the kvStore documentation for Enterprise 9.2.7.

the -auth option doesn't apply to kvStore backups in version 9.2.7?

If anyone has had a similar experience or has resolved this issue, please help

Thank you 🙂

Labels (1)
Tags (3)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @tkdguq0110 

The backup kvstore command does not require authentication as far as I know - you can pass a number of -keyName value' params and it will just ignore any that its not expecting.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

tkdguq0110
Path Finder

Thank you for your reply.

I remembered it asking for an account when backing up kvStore,
but it seems it was a different command.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @tkdguq0110 

The backup kvstore command does not require authentication as far as I know - you can pass a number of -keyName value' params and it will just ignore any that its not expecting.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...