Splunk Enterprise Security

Major upgrade fail on ES from version 4.5.2 to 5.0.1. Please help !!!

damode
Motivator

alt text

After I installed the ES app, I got the error as shown in the attached picture.
On the ES upgrade page, I noticed it mentions about If you do not run the setup procedure promptly after the file upload completes, Enterprise Security displays errors.
To fix this, I restarted Splunk, but on the cli, it came up with a whole heap of errors, such as below, which is just an extract of the errors.

 Invalid key in stanza [identityLookup] in /opt/splunk/etc/apps/SA-IdentityManagement/local/identityLookup.conf, line 6: eai:appName  (value:  SA-IdentityManagement).
                Invalid key in stanza [identityLookup] in /opt/splunk/etc/apps/SA-IdentityManagement/local/identityLookup.conf, line 7: eai:userName  (value:  nobody).
                Invalid key in stanza [nav_collection:ess_security_intelligence] in /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/default/managed_configurations.conf, line 83: nav_collection_status     (value:  old).
                Invalid key in stanza [nav_collection:ess_security_intelligence] in /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/default/managed_configurations.conf, line 120: nav_collection_data      (value:

UPDATE : additional info - Before this, I had just upgraded Splunk SH from 6.5.2 to 6.6.1. There was no issue after this upgrade.

Please advise how I can fix this.

0 Karma

woodcock
Esteemed Legend

Did you check the compatability of that version of ES with that version of Splunk?

0 Karma

damode
Motivator

after restarting, ES app just shows a blank page after clicking the "Set up" option.

0 Karma

martynoconnor
Communicator

Is this Linux or Windows? If Linux and the permissions were not set correctly you may have only partially upgraded and may be running a Frankenstein's ES at the moment. If it is as simple as that, a chown -R splunk:splunk /opt/splunk (assuming that's the account and location that match your environment) and a second attempt at install should fix things.

If not...

What does it say in Splunkd.log? Look for ERROR or WARN messages there. Also in $SPLUNK_HOME/var/log/splunk/ you should have a file called (if memory serves) ess2_installer.log or maybe ess_installer2.log, can you look there and post the last 100 lines or so?

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...