<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security 6.2.0 Upgrade Failure - SOLUTION in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/533603#M9565</link>
    <description>&lt;P&gt;The only thing I found worked was to perform the following steps:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;1. Change directories to: /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/install&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;2.&amp;nbsp; Execute the following command: for i in *.spl; do /opt/splunk/bin/splunk install app $i; done&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3. Change is_configured = 0 to is_configured = 1 in /opt/etc/apps/SplunkEnterpriseSecuritySuite/local/app.conf&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3. Restart Splunk services&lt;/P&gt;&lt;P&gt;NOTE: Also works on 6.4.0&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 18:32:59 GMT</pubDate>
    <dc:creator>jbburkes</dc:creator>
    <dc:date>2020-12-18T18:32:59Z</dc:date>
    <item>
      <title>Splunk Enterprise Security 6.2.0 Upgrade Failure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/509518#M9015</link>
      <description>&lt;P&gt;Recently upgraded Splunk Enterprise Security from 6.1.1 to 6.2.0, install went fine, however clicking on Setup gives me the following error, this happens for both my personal account and the embedded administrator account:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Error: You do not have the permissions to view this page.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Executed the following Search: "| essinstall --dry-run gives the following error:"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Error in 'essinstall' command: (Exception) Missing the capabilities to use essinstall command&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I investigate the Job Inspector/Search.log I find the following error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;File "/opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/bin/essinstall.py" line 385 in run while self._handle_chunk()&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Logged into the Splunk server SSH/CLI itself and ran the command manually ("/opt/splunk/bin/splunk cmd python3 /opt/splunk/etc/apps/SplunkEnterpriseSecurity/bin/essinstall.py" as the splunk user and get the following error:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-60px"&gt;&lt;SPAN&gt;File "/opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/bin/essinstall.py" line 14, in &amp;lt;module&amp;gt; import splunk.rest as rest&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;There is more to the error than the above, but figure I need to solve that issue first before worrying about the rest. Seems it cannot import splunk.rest?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Verified both the Splunk server is configured for python3 (not enforce) in local/server.conf as well as Splunk Enterprise Security which by default is python3 in inputs.conf, I don't have a custom inputs.conf in local for Splunk Enterprise Security&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 13:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/509518#M9015</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2020-07-16T13:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 6.2.0 Upgrade Failure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/518410#M9238</link>
      <description>&lt;P&gt;Grant the current user to inherit the&amp;nbsp;&lt;STRONG&gt;ess_admin&lt;/STRONG&gt; role.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 10:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/518410#M9238</guid>
      <dc:creator>rivaanbechan</dc:creator>
      <dc:date>2020-09-08T10:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 6.2.0 Upgrade Failure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/525900#M9398</link>
      <description>Yes, it did help.</description>
      <pubDate>Wed, 21 Oct 2020 20:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/525900#M9398</guid>
      <dc:creator>tomasmoser</dc:creator>
      <dc:date>2020-10-21T20:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 6.2.0 Upgrade Failure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/527985#M9438</link>
      <description>&lt;P&gt;Sorry just getting back to this, user already has essadmin. Still the same error. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 18:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/527985#M9438</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2020-11-04T18:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 6.2.0 Upgrade Failure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/528007#M9439</link>
      <description>&lt;P&gt;Should also add that if I "upgrade" back to 6.1.1, no issues.&amp;nbsp; Only when I install 6.2.0 do I have issues.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 19:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/528007#M9439</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2020-11-04T19:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security 6.2.0 Upgrade Failure - SOLUTION</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/533603#M9565</link>
      <description>&lt;P&gt;The only thing I found worked was to perform the following steps:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;1. Change directories to: /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/install&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;2.&amp;nbsp; Execute the following command: for i in *.spl; do /opt/splunk/bin/splunk install app $i; done&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3. Change is_configured = 0 to is_configured = 1 in /opt/etc/apps/SplunkEnterpriseSecuritySuite/local/app.conf&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3. Restart Splunk services&lt;/P&gt;&lt;P&gt;NOTE: Also works on 6.4.0&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 18:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-6-2-0-Upgrade-Failure/m-p/533603#M9565</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2020-12-18T18:32:59Z</dc:date>
    </item>
  </channel>
</rss>

