Knowledge Management

Failed to start KV store

corti77
Contributor

Hi,

I run splunk 9.0.8 and after an issue with our storage (LUN full). I had to full scan the disk and successfully repaired the filesystem.

splunk starts now but there is a persistent error with the KV store. the status is the following:

show kvstore-status

This member:
backupRestoreStatus : Ready
disabled : 0
guid : E59FAAA8-D66A-498E-8DDF-0F5C29866F95
port : 8191
standalone : 1
status : failed
storageEngine : wiredTiger

Any suggestion on how could get an operational status?

many thanks.

Jose

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @corti77 ,

you have to reset the mongod.lock:

  • stop splunkd
  • delete $SPLUNK_HOME\var\lib\splunk\kvstore\mongo\mongod.lock"
  • start splunkd

I asked to Splunk ideas to create a script od a dedicated solution to this frequent issue, if you think as me that's important, please vote for this idea at https://ideas.splunk.com/ideas/EID-I-2058

Ciao.

Giuseppe

View solution in original post

corti77
Contributor

just voted, thanks a lot

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @corti77 ,

you have to reset the mongod.lock:

  • stop splunkd
  • delete $SPLUNK_HOME\var\lib\splunk\kvstore\mongo\mongod.lock"
  • start splunkd

I asked to Splunk ideas to create a script od a dedicated solution to this frequent issue, if you think as me that's important, please vote for this idea at https://ideas.splunk.com/ideas/EID-I-2058

Ciao.

Giuseppe

Ogorek
Engager

Hello, what to do when my kvstore folder just vanished? It do not create again after restart. Tried to create new folder with splunk privileges but it wont help. Do u have any idea how to reapir this? 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...