Splunk Enterprise Security

After upgrading from Splunk Enterprise Security 5.1, why am I getting the following error message?

coreylehman
Engager

We have two search heads. One of them is a deployment server containing mostly apps and the other is dedicated to Enterprise Security/other security stuff.

On the dedicated ES server, we just upgraded from v5.1 to 5.2 and are being presented with the following message :

"Installer was unable to start. Error in 'essinstall' command: (InstallException) Install cannot continue because some apps are managed via a deployment server:...."

and then lists a handful of apps from the deployment server.

On the deployment server/other apps server, we received this message:

"Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1)."

Any ideas on how to resolve this?

Thank you in advance!

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

smoir_splunk
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...