Splunk Enterprise Security

After upgrading from Splunk Enterprise Security 5.1, why am I getting the following error message?

coreylehman
Engager

We have two search heads. One of them is a deployment server containing mostly apps and the other is dedicated to Enterprise Security/other security stuff.

On the dedicated ES server, we just upgraded from v5.1 to 5.2 and are being presented with the following message :

"Installer was unable to start. Error in 'essinstall' command: (InstallException) Install cannot continue because some apps are managed via a deployment server:...."

and then lists a handful of apps from the deployment server.

On the deployment server/other apps server, we received this message:

"Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1)."

Any ideas on how to resolve this?

Thank you in advance!

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

smoir_splunk
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...