Splunk Search

Splunk Enterprise Security Content Management blank

adidibra
Engager

Hello,

I performed a "fresh" installation of ES 4.6.1 in a search head cluster through deployer. Splunk app version is 8.0.9. 

The apps for the ES were pulled from a repository solution to deployer and then pushed to the search cluster. When I try to open the content management it is stuck in blank and the Incident Review displaying "Operation Failed, Internal Error. __enter__" error.

Is there any log file I might check and permission I need to change a this behavior is quite strange?

Thank you in advance

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk 8.0.9 does not support ES 4.6.1.  That's an antique version of ES.  Try an older (unsupported) version of Splunk or a newer version of ES.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...