Splunk Search

KV Store status is currently unknown- How to resolve this error?

jpvalenc
Path Finder

We're intermittently getting this error (so far twice in 2 weeks) when trying to use the lookup command on a kvstore.

The full error message is " External command based lookup <kv_store> is not available because KV Store status is currently unknown".

We only found the error through the logs a few hours after the failure because the scheduled search with the lookup command didn't run successfully. When ran manually or on its next schedule, the search was running fine. KV store is also working as intended upon checking.

I couldn't find information online on what the "unknown" status means regarding kv stores.

Has anyone else seen this error?

Labels (1)
Tags (2)
0 Karma

woodcock
Esteemed Legend

This probably means your KVStore is down.  It is probably related to the WiredTiger upgrade.  Use the CLI to debug and fix:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/MigrateKVstore

0 Karma

etoombs
Path Finder

Did you ever figure this out? I'm seeing the same problem. 

0 Karma

jpvalenc
Path Finder

No, I never did but it did stop happening so I have no idea what caused it.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...