Splunk Enterprise Security

Config problem with Enterprise Security 3.0.2 on: Encounterd the following error 'localapps'

dave3131
Engager

A bit of a snag in the upgrade and install of a fresh ES 3.0.2 on Splunk 6.0.3. After the install, you have to configure the app. After you hit save you'll get:

Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=\/servicesNS\/nobody\/SplunkEnterpriseSecuritySuite\/admin\/enterprise_security_suite/general_settings

0 Karma
1 Solution

dave3131
Engager

Here is how to get around it:

cd to:

~/etc/apps/SplunkEnterpriseSecuritySuite

Create a local dir and copy app.conf from default dir (at the same level) to your newly created local directory.

vi/edit the file and change is_configured to true.

Then restart splunk.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi Dave,

ES 3.0.2 hasn't been released, are you sure about that version number?

0 Karma

dave3131
Engager

Here is how to get around it:

cd to:

~/etc/apps/SplunkEnterpriseSecuritySuite

Create a local dir and copy app.conf from default dir (at the same level) to your newly created local directory.

vi/edit the file and change is_configured to true.

Then restart splunk.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...