All Apps and Add-ons

IT Essentials Work - Error 500

daisy_st
Loves-to-Learn Everything

hi all,

so I installed IT Essentials Work and am getting error 500. It is also displayed as ITSI under Apps and not as IT Essentials Work. Also, there are 2 licenses available for some reason. I didn't add any. I don't have a license for ITSI, nor want to use ITSI. The app is installed via CLI, following Splunk's guidelines. Any suggestions what the reason could be?

there is a dev license used as well so not sure if this has anything to do with the issue.

Thanks!

 

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @daisy_st 

The ITEW/ITSI comes with an internal license which is used for the itsi_* sourcetypes, this means it wont count towards any other license you have.

To unlock ITEW into ITSI you do need a separate license key, however it sounds like this isnt an issue for you.

Relating to the 500 error(s) - Is there anything else you can see around this? 

* In the browser developer tools window, under Network, can you see the status=500 pages? Is there any response content for those api calls?

* In the _internal index have a search for log_level=error "itsi"  and/or look around in the $SPLUNK_HOME/var/log/splunk/*itsi* files to see if that gives any clues - feel free to post any specific error logs here to help us diagnose.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...