Splunk Enterprise Security

After upgrading from Splunk Enterprise Security 5.1, why am I getting the following error message?


We have two search heads. One of them is a deployment server containing mostly apps and the other is dedicated to Enterprise Security/other security stuff.

On the dedicated ES server, we just upgraded from v5.1 to 5.2 and are being presented with the following message :

"Installer was unable to start. Error in 'essinstall' command: (InstallException) Install cannot continue because some apps are managed via a deployment server:...."

and then lists a handful of apps from the deployment server.

On the deployment server/other apps server, we received this message:

"Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1)."

Any ideas on how to resolve this?

Thank you in advance!

0 Karma
1 Solution

Splunk Employee
Splunk Employee

Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...