Splunk Enterprise Security

Splunk ES app installation Error

spl_unker
Explorer

My Enterprise Splunk version is 7.3.2 and ES app version which i tried installing is 6.1.1.

After ES app installation and splunk server restart , i see the following error when i proceed to setup page

"Installer was unable to start. Error in 'essinstall' command: External search command exited unexpectedly with non-zero error code 1."

I understand it is due to version compatibility issue between ES and Entreprise Splunk in one of the Splunk answers

https://answers.splunk.com/answers/521781/error-while-installing-splunk-enterprise-security.html

But in the app page 7.3 are 8.0 is mentioned as compatible version. Please help if any one has faced this issue. TIA

Labels (2)
0 Karma

shivanshu1593
Builder

You're trying to install a version, which is not compatible with 7.3.X, although it says on the splunkbase page. The compatible version is 6.0.1.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee
0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES 6.1.x requires Splunk 8.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...