All Apps and Add-ons

Splunk on local machine fails to install apps from file

mgrant74
Engager

I'm trying to install Splunk Security Essentials for Fraud Detection on my local machine that I use for practicing with Splunk, and I can't find the app in the Browse More Apps section, so I downloaded the .tgz file, unzipped it to get the .tar file, and tried it both ways. In the past, app installs would throw an error, but the app would still be installed. This time I'm getting either ERR_CONNECTION_RESET or ERR_CONNECTION_ABORTED depending on if I use the .TGZ or .TAR respectively.

Is there an easier way to do this, or some other app I need to install prior to the SSE for Fraud Detection app? I already have SSE installed.

Thanks!

Tags (1)
0 Karma

lacastillo
Path Finder

@mgrant74 Did you install the dependencies?
https://splunkbase.splunk.com/app/3693/#/details
under the "Details" tab

"Dependencies:

Splunk Security Essentials for Fraud Detection depends on the following apps
Splunk Machine Learning Toolkit
Python for Scientific Computing
Clustered Single Value Map Visualization
3D Scatterplot

All above apps can be downloaded for free from Splunkbase. When installing these apps please select the appropriate platform.

Make sure these apps are properly installed in your Splunk environment before installing this app."

Also, did you follow the Quick Installation Suggestions?

"Quick Installation Suggestions
Due to very large size of the app - it may be a challenge to install it via normal, GUI way.
Here are suggested steps to install this app in a faster, more reliable manner:
- Download the app to your computer
- Unzip it manually (via WinRar or 7Zip or related linux utilities)
- If you do not need Healthcare demo - you may delete Healthcare dataset - all files under ./Splunk-SE-Fraud-Detection/DATA/af-cms* - this will greatly reduce the size of the app as well.
- Move ./Splunk-SE-Fraud-Detection tree under ./etc/apps of your Splunk installation
- Restart Splunk
- If you included (did not delete) healthcare datasets - give app some time (30-60 minutes) to index the complete datasets. Once indexing is finished (af-cms-* indexes stopped growing) - the app is ready for use"

Let me know if this helps.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...