On my current machine, Kvstore is failing. When I restart Splunk, the Kvstore status is "Ready." However, when I click the Audit Log tab in ES, the status changes to "Failed." This makes it impossible to access other Kvstore-related functions, such as incident review in ES. I tried changing the server.pem file to a different extension and restarting, as well as changing the mongod.lock and splunk.key files to different extensions and restarting. I also tried changing all configuration files, but nothing worked. I'm wondering if there are any other solutions. Please help. Splunk version : 8.1.10.1 Splunk Enterprise Security: 7.0.1 ERROR-Log Failed to execute KVstore lookups External command based lookup 'goverence_lookup' is not available because KVstore initialization has failed, Contact your system admin... Failed to create kvstore lookup
... View more