Splunk Enterprise Security

Splunk 8.0 ES

astatrial
Contributor

Hi all,

I am having huge problem with ES on splunk v8.0 .

I upgraded my instance and when i have tried to upgrade Splunk ES to v 6.0 from the gui i couldn't do it.
I used the cli and it worked, but now i am trying to configure the app at it fails every time at the "installing new add -ons" phase.

I already changed enable_install_app=true and it still doesn't work.

Please help me !

0 Karma
1 Solution

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

View solution in original post

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

woodcock
Esteemed Legend

So what value did you use?

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Is it this?
https://docs.splunk.com/Documentation/ES/6.0.0/RN/Enhancements#What.27s_New
Enterprise Security installer package size increase:
The ES installer package size is now >500MB, which is larger than the default upload limit for installing ES from the SplunkWeb UI. See http://docs.splunk.com/Documentation/ES/6.0.0/Install/InstallEnterpriseSecurity#Step_2._Install_Splu... for installation instructions.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain more about what you mean by "it doesn't work". What exactly are you trying to do and how exactly are you trying to do it? What error messages do you get? Have you checked the logs? What type of Splunk instance are you installing on?

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Hi @richgalloway

I will try to add more information:
I have single instance deployment, and i installed ES on it.
When i open the app i have the "Splunk Enterprise Security Post-Install configuration" and the pahse of "installing new add-ons" becomes red and the configuration fails. The error i get is and in the log "install app failed" in the search.log.

The error in the log is :
SplunkdConnectionException(\"Error connecting to /services/apps/local: ('The read operation timed out',)\",)", "stage": "install_apps"}

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...