Splunk Enterprise Security

Splunk 8.0 ES

astatrial
Contributor

Hi all,

I am having huge problem with ES on splunk v8.0 .

I upgraded my instance and when i have tried to upgrade Splunk ES to v 6.0 from the gui i couldn't do it.
I used the cli and it worked, but now i am trying to configure the app at it fails every time at the "installing new add -ons" phase.

I already changed enable_install_app=true and it still doesn't work.

Please help me !

0 Karma
1 Solution

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

View solution in original post

astatrial
Contributor

Eventually i was able to solve it by raising the splunkdConnectionTimeout in web.conf.

In order to use the UI to install it i had to raise the max_upload_size as @lkutch_splunk mentioned.

Thanks

woodcock
Esteemed Legend

So what value did you use?

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

Is it this?
https://docs.splunk.com/Documentation/ES/6.0.0/RN/Enhancements#What.27s_New
Enterprise Security installer package size increase:
The ES installer package size is now >500MB, which is larger than the default upload limit for installing ES from the SplunkWeb UI. See http://docs.splunk.com/Documentation/ES/6.0.0/Install/InstallEnterpriseSecurity#Step_2._Install_Splu... for installation instructions.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain more about what you mean by "it doesn't work". What exactly are you trying to do and how exactly are you trying to do it? What error messages do you get? Have you checked the logs? What type of Splunk instance are you installing on?

---
If this reply helps you, Karma would be appreciated.
0 Karma

astatrial
Contributor

Hi @richgalloway

I will try to add more information:
I have single instance deployment, and i installed ES on it.
When i open the app i have the "Splunk Enterprise Security Post-Install configuration" and the pahse of "installing new add-ons" becomes red and the configuration fails. The error i get is and in the log "install app failed" in the search.log.

The error in the log is :
SplunkdConnectionException(\"Error connecting to /services/apps/local: ('The read operation timed out',)\",)", "stage": "install_apps"}

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...