I realize this response comes in a bit late in the game for most on this thread, but hopefully it will be useful to someone. KV Store is not used on indexers. In fact, it can be disabled on any Splunk Enterprise instance that is not running as a search head (see caveats below). This means includes Indexers, Deployment Servers, Cluster Managers, License Managers and Search Head Cluster Deployers, Heavy Forwarders (see exceptions below). Instances that SHOULD run KV Store include: Search Heads Monitoring Console (if you want access to its KV Store dashboards-- see caveats below) Heavy Forwarders, if used as search heads or are running DB Connect app (or, not likely but possible, any custom app that specifically relies on the KV Store) Lastly, any Splunk Enterprise instance in your deployment which requires token-based authentication CAVEATS: If your Monitoring Console machine also operates another Splunk role such as Deployment Server or License Manager, keep the KV Store running on that instance. As of this writing, the Monitoring Console appears to use the KV Store only for KV Store-specific dashboards. If you don't care about those dashboards and the KV Store is giving you real headaches on that instance, disabling it will cause the dashboards which rely on KV Store to stop working, but all other Monitoring Console dashboards will function as expected. Universal Forwarders are not shipped with the KV Store so nothing to worry about there
... View more