Splunk Enterprise Security

Splunk 8.0 ES

astatrial
Contributor

Hi all,

I am having huge problem with ES on splunk v8.0 .

I upgraded my instance and when i have tried to upgrade Splunk ES to v 6.0 from the gui i couldn't do it.
I used the cli and it worked, but now i am trying to configure the app at it fails every time at the "installing new add -ons" phase.

I already changed enable_install_app=true and it still doesn't work.

Please help me !

0 Karma
1 Solution

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

View solution in original post

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

woodcock
Esteemed Legend

So what value did you use?

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Is it this?
https://docs.splunk.com/Documentation/ES/6.0.0/RN/Enhancements#What.27s_New
Enterprise Security installer package size increase:
The ES installer package size is now >500MB, which is larger than the default upload limit for installing ES from the SplunkWeb UI. See http://docs.splunk.com/Documentation/ES/6.0.0/Install/InstallEnterpriseSecurity#Step_2._Install_Splu... for installation instructions.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain more about what you mean by "it doesn't work". What exactly are you trying to do and how exactly are you trying to do it? What error messages do you get? Have you checked the logs? What type of Splunk instance are you installing on?

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Hi @richgalloway

I will try to add more information:
I have single instance deployment, and i installed ES on it.
When i open the app i have the "Splunk Enterprise Security Post-Install configuration" and the pahse of "installing new add-ons" becomes red and the configuration fails. The error i get is and in the log "install app failed" in the search.log.

The error in the log is :
SplunkdConnectionException(\"Error connecting to /services/apps/local: ('The read operation timed out',)\",)", "stage": "install_apps"}

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...