Skip to main content

[FIX] Splunk KV Store Upgrade Precheck Failure

While upgrading a Splunk Enterprise server from 9.3.x to 9.4.12, the RPM installation failed during the pre-upgrade checks.

The error pointed to KV Store:

Currently used KVStore version=4.0.24-linux-splunk-v1
Expected version=4.2 or version=7

Active KVStore version upgrade precheck FAILED!
Some upgrade prechecks failed!
pre install check failed

My first assumption was that I simply needed to upgrade the KV Store version.

That turned out to be only part of the story.

The actual problem was that KV Store was not healthy in the first place. Once I started troubleshooting that, I found two separate issues: an expired Splunk server certificate and incorrect permissions on the KV Store key file.

Here is how I worked through it.

Checking the KV Store status

I started by checking the KV Store status:

$SPLUNK_HOME/bin/splunk show kvstore-status --verbose

The important part of the output was:

status : failed
storageEngine : wiredTiger

There was also an error while trying to retrieve the feature compatibility version.

At this point, I decided not to attempt any KV Store migration. If KV Store itself was not starting, upgrading it was unlikely to solve the actual problem.

The next place to look was mongod.log.

tail -100 $SPLUNK_HOME/var/log/splunk/mongod.log

That immediately revealed something useful:

The provided SSL certificate is expired or not yet valid.

Fatal Assertion 28652
aborting after fassert() failure

So MongoDB, which Splunk uses for KV Store, was refusing to start because of a certificate problem.

Finding the certificate Splunk was using

I checked the effective Splunk configuration with btool:

$SPLUNK_HOME/bin/splunk cmd btool server list sslConfig --debug

The server was using the standard Splunk certificate paths:

caCertFile = $SPLUNK_HOME/etc/auth/cacert.pem
serverCert = $SPLUNK_HOME/etc/auth/server.pem

I then checked the validity of server.pem:

$SPLUNK_HOME/bin/splunk cmd openssl x509 \
-in $SPLUNK_HOME/etc/auth/server.pem \
-noout -subject -issuer -dates

The result explained the problem:

notBefore=Nov 27 13:16:00 2019 GMT
notAfter=Nov 26 13:16:00 2022 GMT

The certificate had expired years earlier.

Interestingly, Splunk itself had continued running, so the issue only became obvious when the KV Store process needed to start properly during the upgrade activity.

I also checked the CA certificate separately. The CA was still valid, so there was no reason to touch it.

Replacing the expired server certificate

Before making any changes, I backed up the existing certificate.

After stopping Splunk, I copied the old certificate and moved it out of the active path:

sudo cp -p \
$SPLUNK_HOME/etc/auth/server.pem \
$SPLUNK_HOME/etc/auth/server.pem.expired_backup

sudo mv \
$SPLUNK_HOME/etc/auth/server.pem \
$SPLUNK_HOME/etc/auth/server.pem.old

I then started Splunk again.

Since this environment was using Splunk's default certificate setup, Splunk generated a new server.pem.

I checked the new certificate:

$SPLUNK_HOME/bin/splunk cmd openssl x509 \
-in $SPLUNK_HOME/etc/auth/server.pem \
-noout -subject -issuer -dates

The replacement certificate was valid until 2029.

So the certificate issue was fixed.

But KV Store still wasn't coming up.

The second problem

After another restart, show kvstore-status still showed:

status : failed

This time the error was more specific:

No suitable servers found
failed to connect to target host: 127.0.0.1:8191

That meant nothing was listening on the KV Store port.

I went back to mongod.log and checked the latest entries.

This time the error was:

permissions on
$SPLUNK_HOME/var/lib/splunk/kvstore/mongo/splunk.key
are too open

So after fixing the certificate, MongoDB was getting further into the startup process but was now refusing to use the KV Store key file because its filesystem permissions were too permissive.

I fixed the ownership and permissions:

sudo chown splunk:splunk \
$SPLUNK_HOME/var/lib/splunk/kvstore/mongo/splunk.key

sudo chmod 600 \
$SPLUNK_HOME/var/lib/splunk/kvstore/mongo/splunk.key

The resulting permissions looked like:

-rw------- 1 splunk splunk ... splunk.key

I restarted Splunk once again.

KV Store finally came back

After the restart, I checked:

$SPLUNK_HOME/bin/splunk show kvstore-status --verbose

This time the result was what I wanted:

featureCompatibilityVersion : 4.2
status : ready
storageEngine : wiredTiger
serverVersion : 4.2.17

KV Store was healthy again.

More importantly, the server was already running KV Store version 4.2.17, which satisfied the prerequisite for the Splunk 9.4 upgrade.

So there was no need to manually migrate KV Store at that point.

What actually happened

The upgrade error initially looked like a simple KV Store version mismatch.

In reality, the chain of events was:

Splunk upgrade precheck failed
        ↓
KV Store status was failed
        ↓
mongod.log showed expired certificate
        ↓
server.pem was replaced
        ↓
KV Store still failed
        ↓
mongod.log showed splunk.key permissions too open
        ↓
Permissions corrected
        ↓
KV Store started successfully
        ↓
KV Store 4.2.17 confirmed

There were therefore two separate problems:

1. The default Splunk server certificate had expired.

MongoDB refused to start because server.pem was no longer valid.

2. The KV Store key file had overly permissive permissions.

After the certificate was fixed, MongoDB refused to start until splunk.key was restricted to the Splunk account.

A few useful commands

Check KV Store status:

$SPLUNK_HOME/bin/splunk show kvstore-status --verbose

Check the MongoDB log:

tail -100 $SPLUNK_HOME/var/log/splunk/mongod.log

Check the effective SSL configuration:

$SPLUNK_HOME/bin/splunk cmd btool server list sslConfig --debug

Check a certificate's validity:

$SPLUNK_HOME/bin/splunk cmd openssl x509 \
-in $SPLUNK_HOME/etc/auth/server.pem \
-noout -subject -issuer -dates

Check whether MongoDB is running:

ps -ef | grep [m]ongod

Check whether KV Store is listening on port 8191:

ss -lntp | grep 8191

What I would avoid

One thing I would not do immediately in this situation is:

splunk clean kvstore

A failed KV Store does not automatically mean that the database is corrupted.

In this case, the KV Store data itself was fine. MongoDB simply could not start because of an expired certificate and incorrect file permissions.

I would also avoid modifying files under:

$SPLUNK_HOME/etc/system/default/

unless there is a very specific reason to do so.

Final takeaway

The most useful lesson from this issue was not to take the upgrade precheck message too literally.

The installer complained about the KV Store version, but the underlying issue was that KV Store was unhealthy.

Checking these two things first saved a lot of unnecessary troubleshooting:

splunk show kvstore-status --verbose

and:

$SPLUNK_HOME/var/log/splunk/mongod.log

Once the certificate and key-file permissions were corrected, KV Store returned to ready, version 4.2.17 was detected correctly, and the server was ready to continue with the Splunk 9.4 upgrade.

Popular Posts

Download Microsoft Office 2019 offline installer.

When you do malware analysis of documents or office files, it is important to have Microsoft Office installed in your Lab machine. I am using flare VM and it doesn't comes with MS Office. Since Microsoft is promoting Microsoft 365 over the offline version, finding the offline installer is not that easy. Here is the list of genuine Microsoft links to download the office .img files.  Download Microsoft Office 2019 Professional Plus : https://officecdn.microsoft.com/db/492350F6-3A01-4F97-B9C0-C7C6DDF67D60/media/en-US/ProPlus2019Retail.img Download Microsoft Office 2019 Professional : https://officecdn.microsoft.com/db/492350F6-3A01-4F97-B9C0-C7C6DDF67D60/media/en-US/Professional2019Retail.img Download Microsoft Office 2019 Home and Business : https://officecdn.microsoft.com/db/492350F6-3A01-4F97-B9C0-C7C6DDF67D60/media/en-US/HomeBusiness2019Retail.img Download Microsoft Office 2019 Home and Student : https://officecdn.microsoft.com/db/492350F6-3A01-4F97-B9C0-C7C6DDF67D60/media/en-U...

RUST error: linker `link.exe` not found

While compiling Rust program in a windows environment, you may encounter the error : linker `link.exe` not found. This is because of the absence of the C++ build tools in your machine. For compiling Rust programs successfully, one of the prerequisites is the installation of the Build Tools for Visual Studio 2019.   Download the Visual Studio 2019 Build tools from the Microsoft website. After the download, while installing the Build tools, make sure that you install the required components (highlighted in Yellow) This will download around 1.2GB of required files. Once everything is successfully installed, reboot and re-run your rust program and it will compile successfully.   Read More on RUST Hello World Rust Program : Code explained RUST Cargo Package Manager Explained Data Representation in Rust.

Cisco ASA: Disable SSLv3 and configure TLSv1.2.

For configuring TLS v1.2, the ASA should run software version 9.3(2) or later. In earlier versions of ASA, TLS 1.2 is not supported.If you are running the old version, it's time to upgrade. But before that i will show you the config prior to the change. I am running ASA version 9.6.1 Now ,set the server-version to tlsv1.2, though ASA supports version tlsv1.1, its always better to configure the connection to more secure. Server here in the sense, the ASA will be act as the server and the client will connect to the ASA.     #ssl server-version tlsv1.2 set the client-version to tlsv1.2, if required.     #ssl client-version tlsv1.2 ssl cipher command in ASA offers 5 predefined security levels and an additional custom level.     #ssl cipher tlsv1.2 high we can see the setting of each cipher levels using #show ssl cipher command. Now set the DH group to 24, which is the strongest offered as of now in the AS...

How to Install Netmiko on Windows?

Netmiko, developed by kirk Byers is an open source python library  based on Paramiko which simplifies SSH management to network devices and is primarily used for network automation tasks. Installing Netmiko in linux is a matter o f one single command but if you need to use Netmiko in your Windows PC, follow this process. 1) Install the latest version of Python. 2) Install Anaconda, which is an opensource distribution platform that you can install in Windows and other OS's (https://www.anaconda.com/download/) 3) From the Anaconda Shell, run “ conda install paramiko ”. 4) From the Anaconda Shell, run “ pip install scp ”. 5) Now Install the Git for Windows. (https://www.git-scm.com/downloads) . Git is required for downloading and cloning all the Netmiko library files from Github. 6) From Git Bash window, Clone Netmiko using the following command git clone https://github.com/ktbyers/netmiko&#8221         7) Onc...

PrintNightmare (CVE-2021-1675) PoC exploit Walkthrough

I am not an exploit developer but was interested to see how this vulnerability can be exploited. So i tried to replicate the infamous PrintNightmare vulnerability using the following PoCs ( https://github.com/cube0x0/CVE-2021-1675 ) and ( https://github.com/rapid7/metasploit-framework/pull/15385 ) However i had trouble with the new metasploit module (auxiliary/admin/dcerpc/cve_2021_1675_printnightmare) and i couldn't able to exploit the machine successfully. So i tried the second PoC from cube0x0. This one has done the magic. I just followed the guidelines with couple of tweaks. First of all, i installed the impacket (cube0x0 version) which will install the required modules and files. After that i set up a samba share with an anonymous login. This is required for hosting the dll file. I edited the smb.conf with the following settings. [global]     map to guest = Bad User     server role = standalone server     usershare allow guests = yes ...

Google Cloud : Basic Cloud Shell commands

Google Cloud resources can be managed in multiple ways. It can be done using Cloud Console, SDK or by using Cloud Shell. A few basic Google Cloud shell commands are listed below. 1)    List the active account name gcloud auth list 2)    List the project ID gcloud config list project 3)    Create a new instance using Gcloud shell gcloud compute instances create [INSTANCE_NAME] --machine-type n1-standard-2 --zone [ZONE_NAME] Use gcloud compute machine-types list to view a list of machine types available in particular zone. If the additional parameters, such as a zone is not specified, Google Cloud will use the information from your default project. To view the default project information, use gcloud compute project-info describe 4)    SSH in to the machine gcloud compute ssh [INSTANCE_NAME] --zone [YOUR_ZONE] 5)    RDP a windows server gcloud compute instances get-serial-port-output [INSTANCE_NAME...

Unable to locate package linux-headers / E: Unable to locate package linux-headers-5.10.0-kali5-amd64

While compiling programs, you may encounter this particular error. E: Unable to locate package linux-headers-5.10.0-kali5-amd64 I encountered this while compiling a C code. To fix this, i first updated my Kali machine (v2020.2a).  sudo apt update -y && apt upgrade -y && apt dist-upgrade   Rebooted. Then installed the headers.   sudo apt install linux-headers-$(uname -r)