Splunk Enterprise Security

New cisco security suite install - 500 internal server error

cjsweeney1
Explorer

New Cisco security suite installed on the enterprise security server- i am see a 500 internal server error when attempting to finish the setup piece in the manage apps page... No other apps I am accessing are experiencing this so far....

I know there is a way to view the web piece for failures through the search app so I could definately check on it if you know of a search string for that...

Thanks...

Cisco security suite ver 3.1.2
Splunk ver 6.3.3
Ent Security ver 4.0.0

0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

I have this same issue, could you clarify " It was mis-configured SSL settings.."

0 Karma

cjsweeney1
Explorer

Thanks... It was mis-configured SSL settings... I just disabled it and it works now..

0 Karma

bheemireddi
Communicator

I don't think it is a recommended practice to install Cisco Security Suite app on the search head where you have ES (Enterprise Security). You should have ES running on it's own and no other apps should be interfering on that system.

Try installing on a different search head and if you still get the error from the GUI upload, you can un-tar it via SSH into etc/apps and restart the SH if that is a possibility.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...