Splunk Enterprise Security

Splunk ES app installation Error

spl_unker
Explorer

My Enterprise Splunk version is 7.3.2 and ES app version which i tried installing is 6.1.1.

After ES app installation and splunk server restart , i see the following error when i proceed to setup page

"Installer was unable to start. Error in 'essinstall' command: External search command exited unexpectedly with non-zero error code 1."

I understand it is due to version compatibility issue between ES and Entreprise Splunk in one of the Splunk answers

https://answers.splunk.com/answers/521781/error-while-installing-splunk-enterprise-security.html

But in the app page 7.3 are 8.0 is mentioned as compatible version. Please help if any one has faced this issue. TIA

Labels (2)
0 Karma

shivanshu1593
Builder

You're trying to install a version, which is not compatible with 7.3.X, although it says on the splunkbase page. The compatible version is 6.0.1.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee
0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES 6.1.x requires Splunk 8.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...