Splunk Enterprise Security

After Enterprise Security Update I get connection reset by peer

andresito123
Communicator

I upgraded to the latest ES app and now I get "The connection was reset" error when I am trying to connect to the web interface.

0 Karma

LukeMurphey
Champion

SplunkWeb likely was not able to start.

This is likely due to old advanced XML modules being left around. Delete the directory $SPLUNK_HOME/etc/apps/SA-Utils/appserver/modules/SOLNLookupEditor and restart SplunkWeb.

See https://answers.splunk.com/answers/620634/why-wont-splunkweb-start-after-es-was-upgraded.html for more details.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...