Splunk Search

KV Store status is currently unknown- How to resolve this error?

jpvalenc
Path Finder

We're intermittently getting this error (so far twice in 2 weeks) when trying to use the lookup command on a kvstore.

The full error message is " External command based lookup <kv_store> is not available because KV Store status is currently unknown".

We only found the error through the logs a few hours after the failure because the scheduled search with the lookup command didn't run successfully. When ran manually or on its next schedule, the search was running fine. KV store is also working as intended upon checking.

I couldn't find information online on what the "unknown" status means regarding kv stores.

Has anyone else seen this error?

Labels (1)
Tags (2)
0 Karma

woodcock
Esteemed Legend

This probably means your KVStore is down.  It is probably related to the WiredTiger upgrade.  Use the CLI to debug and fix:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/MigrateKVstore

0 Karma

etoombs
Path Finder

Did you ever figure this out? I'm seeing the same problem. 

0 Karma

jpvalenc
Path Finder

No, I never did but it did stop happening so I have no idea what caused it.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...