Splunk Enterprise Security

Splunk 8.0 ES

astatrial
Contributor

Hi all,

I am having huge problem with ES on splunk v8.0 .

I upgraded my instance and when i have tried to upgrade Splunk ES to v 6.0 from the gui i couldn't do it.
I used the cli and it worked, but now i am trying to configure the app at it fails every time at the "installing new add -ons" phase.

I already changed enable_install_app=true and it still doesn't work.

Please help me !

0 Karma
1 Solution

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

View solution in original post

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

woodcock
Esteemed Legend

So what value did you use?

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Is it this?
https://docs.splunk.com/Documentation/ES/6.0.0/RN/Enhancements#What.27s_New
Enterprise Security installer package size increase:
The ES installer package size is now >500MB, which is larger than the default upload limit for installing ES from the SplunkWeb UI. See http://docs.splunk.com/Documentation/ES/6.0.0/Install/InstallEnterpriseSecurity#Step_2._Install_Splu... for installation instructions.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain more about what you mean by "it doesn't work". What exactly are you trying to do and how exactly are you trying to do it? What error messages do you get? Have you checked the logs? What type of Splunk instance are you installing on?

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Hi @richgalloway

I will try to add more information:
I have single instance deployment, and i installed ES on it.
When i open the app i have the "Splunk Enterprise Security Post-Install configuration" and the pahse of "installing new add-ons" becomes red and the configuration fails. The error i get is and in the log "install app failed" in the search.log.

The error in the log is :
SplunkdConnectionException(\"Error connecting to /services/apps/local: ('The read operation timed out',)\",)", "stage": "install_apps"}

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...