All Apps and Add-ons

What does this Enterprise Security error message mean?

kriznikm
Loves-to-Learn

I have the below error showing on the search head, I've been looking for a cause of this error with no luck.

Unable to initialize modular input "es_identity" defined in the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=es_identity_export: script running failed (exited with code 1)

Post-Install Configuration gives Error: Fetch failed:admin/ess_configured/ssl

I'm new to SPLUNK, thank you.

 

 

Labels (1)
0 Karma

kriznikm
Loves-to-Learn

gcusello,

thank you for reply. How do I disable the  check?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kriznikm ,

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kriznikm,

too much time passed when I found this error, but it should be at:

[Enterprise Security > Configure > general > Configuration Checker]

disable "confcheck_es_conf_cleanup"

ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @kriznikm,

it's a frequent error when a script has an exit code non correctly managed.

You can disable the check or open a case To Splunk Support.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...