Splunk Enterprise Security

After upgrading from Splunk Enterprise Security 5.1, why am I getting the following error message?

coreylehman
Engager

We have two search heads. One of them is a deployment server containing mostly apps and the other is dedicated to Enterprise Security/other security stuff.

On the dedicated ES server, we just upgraded from v5.1 to 5.2 and are being presented with the following message :

"Installer was unable to start. Error in 'essinstall' command: (InstallException) Install cannot continue because some apps are managed via a deployment server:...."

and then lists a handful of apps from the deployment server.

On the deployment server/other apps server, we received this message:

"Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1)."

Any ideas on how to resolve this?

Thank you in advance!

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

smoir_splunk
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...

Announcing Our Splunk MVPs

We are excited to announce the first cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...