Splunk Enterprise Security

Splunk ES app installation Error


My Enterprise Splunk version is 7.3.2 and ES app version which i tried installing is 6.1.1.

After ES app installation and splunk server restart , i see the following error when i proceed to setup page

"Installer was unable to start. Error in 'essinstall' command: External search command exited unexpectedly with non-zero error code 1."

I understand it is due to version compatibility issue between ES and Entreprise Splunk in one of the Splunk answers


But in the app page 7.3 are 8.0 is mentioned as compatible version. Please help if any one has faced this issue. TIA

Labels (2)
0 Karma


You're trying to install a version, which is not compatible with 7.3.X, although it says on the splunkbase page. The compatible version is 6.0.1.

Thank you,
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

Splunk Employee
Splunk Employee
0 Karma


ES 6.1.x requires Splunk 8.

If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...