Splunk Enterprise Security

After Enterprise Security Update I get connection reset by peer


I upgraded to the latest ES app and now I get "The connection was reset" error when I am trying to connect to the web interface.

0 Karma


SplunkWeb likely was not able to start.

This is likely due to old advanced XML modules being left around. Delete the directory $SPLUNK_HOME/etc/apps/SA-Utils/appserver/modules/SOLNLookupEditor and restart SplunkWeb.

See https://answers.splunk.com/answers/620634/why-wont-splunkweb-start-after-es-was-upgraded.html for more details.