Splunk Enterprise Security

After upgrading from Splunk Enterprise Security 5.1, why am I getting the following error message?

coreylehman
Engager

We have two search heads. One of them is a deployment server containing mostly apps and the other is dedicated to Enterprise Security/other security stuff.

On the dedicated ES server, we just upgraded from v5.1 to 5.2 and are being presented with the following message :

"Installer was unable to start. Error in 'essinstall' command: (InstallException) Install cannot continue because some apps are managed via a deployment server:...."

and then lists a handful of apps from the deployment server.

On the deployment server/other apps server, we received this message:

"Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1)."

Any ideas on how to resolve this?

Thank you in advance!

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

smoir_splunk
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...