Thank you for the pointers, there are some entries in the job log indeed but I don't know which are the important bits: WARNING <?xml version="1.0" encoding="UTF-8"?>
<response>
<messages>
<msg type="ERROR">KV Store initialization failed. Please contact your system administrator.</msg>
</messages>
</response>
(JSONDecodeError) Expecting value: line 1 column 1 (char 0) Mongodb is not running and KV Store complains about expired certificates but I was not able to renew the internal certificate by renamein it and let 'splunk start ' issue a new one but it only complains The certificate generation script did not generate the expected certificate file:/opt/splunk/etc/auth/server.pem. Splunkd port communication will not work. SSL certificate generation failed. and splunkd-utility.log logs ServerConfig - No '/opt/splunk/etc/auth/server.pem' certificate found. Splunkd communication will not work without this. If this is a fresh installation, this should be OK. Does the logexperiment rely on a functioning kvstore? Is the fit still working and the logexperiment error could be ignored? And for the renewing of the certificate (splunk enterprise 9.4 btw) -- am I missing something obvious? Should I better open a support case?
... View more