Splunk Enterprise Security

Enterprise Security on SHC

Nawab
Communicator

I have installed ES on deployer as suggested by splunk docs, then transfered this app to /opt/splunk/etc/shcluster/apps and pushed the apps to my cluster.

but still when I open ES on any search head it still says Post instal configurations and when I click configure it says you can not do it on SHC member

Labels (1)
0 Karma

Nawab
Communicator

I tried it again, usign the same method you suggested,

deployed and configured the app on deployer and pushed the config bundle, but its still the same

0 Karma

kiran_panchavat
Champion

@Nawab 

Reconfiguring Splunk Enterprise Security is what would advise you to do, however if the problem persists, open support ticket.

https://docs.splunk.com/Documentation/ES/8.0.40/Install/InstallSplunkESinSHC#Installing_Splunk_Enter... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Wait. As far as I remember (it's been some time since I did it last time) you don't manually copy anything. When you run the installer in deployer mode it takes care of preparing the shcluster bundle. That's why you run it exactly as described - upload the app to the deployer, run the installer on the deployer, apply shcluster-bundle. No manual copying stuff anywhere.

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Yes, this is right. There's no copy/pasting. We may need to update some parameters to support larger upload, but apart from that we can simply upload the ES package from the UI, perform the setup and deploy the Bundle.

0 Karma

Nawab
Communicator

I followed these steps, installed ES on deployer, configured it. Mission control is not working on deployer, then I copied ES to shcluster/apps and pushed the configuration. now all DA-ESS and SA apps are present in apps of each SHC member, but still when I click ES app or mission control app on cluster member it says continue to setup page.

 

not sure why

0 Karma

Nawab
Communicator

Followed every thing exactly described in docs

0 Karma

kiran_panchavat
Champion

@Nawab 

Installing ES on a Search Head Cluster

Deployer:

1. On the Splunk toolbar, select Apps > Manage Apps and click Install app from file
2. Click Choose File and select the Splunk Enterprise Security file
3. Click Upload to begin the installation
4. Click Continue to app setup page
5. Click Start Configuration Process, and wait for it to complete
6. Use the Deployer to deploy ES to the cluster members. From the Deployer run:

/opt/splunk/bin/splunk apply shcluster-bundle 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
Champion

@Nawab  -  Please make sure that you followed all pre-requisites for SHC and ES on SHC. 

https://docs.splunk.com/Documentation/ES/8.0.2/Install/InstallSplunkESinSHC 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...