I am having huge problem with ES on splunk v8.0 .
I upgraded my instance and when i have tried to upgrade Splunk ES to v 6.0 from the gui i couldn't do it.
I used the cli and it worked, but now i am trying to configure the app at it fails every time at the "installing new add -ons" phase.
I already changed enable_install_app=true and it still doesn't work.
Please help me !
Is it this?
Enterprise Security installer package size increase:
The ES installer package size is now >500MB, which is larger than the default upload limit for installing ES from the SplunkWeb UI. See http://docs.splunk.com/Documentation/ES/6.0.0/Install/InstallEnterpriseSecurity#Step_2._Install_Splu... for installation instructions.
Please explain more about what you mean by "it doesn't work". What exactly are you trying to do and how exactly are you trying to do it? What error messages do you get? Have you checked the logs? What type of Splunk instance are you installing on?
I will try to add more information:
I have single instance deployment, and i installed ES on it.
When i open the app i have the "Splunk Enterprise Security Post-Install configuration" and the pahse of "installing new add-ons" becomes red and the configuration fails. The error i get is and in the log "install app failed" in the search.log.
The error in the log is :
SplunkdConnectionException(\"Error connecting to /services/apps/local: ('The read operation timed out',)\",)", "stage": "install_apps"}