I just installed Splunk Enterprise 7.2.0, which shows that it is a supported platform for Enterprise Security 5.11.
But, when I tried to install it, after 1 minute through the process, it gave me an error which states "Internal Server Error 501".
This is the message I am getting:
Unable to initialize modular input "ess_content_importer" defined inside the app "SplunkEnterpriseSecuritySuite": Introspecting scheme=ess_content_importer: script running failed (exited with code 1).
What should I go and check to get this going?
Maybe a permission problem. Did you use the same OS user for installation of ES that you used during installing splunk? And do you use the required hardware components for Splunk ans ES? Could also be a problem, you may run out of capacity.