Splunk Enterprise Security

Enterprise Security v4.1.3 Setup on Splunk 6.5.0

Splunker
Communicator

Hi,

On a test system, i am having trouble upgrading ES from v4.1.2 on Splunk 6.5.0 to v4.1.3.

After installing the app, selecting Apps -> Enterprise-Security, selecting the green button to start the ES setup, am greeted with a blank screen (grey screen, and has the black navbar at the top).

The upgrade path went as follows..

Upgraded Splunk 6.4.2 -> 6.5.0
Upgraded ES to v4.1.2 (worked fine)
Upgraded ES to v4.1.3 (current problem)

Any thoughts?

Thanks.

0 Karma
1 Solution

jwelch_splunk
Splunk Employee
Splunk Employee

Try running this from the cli:

From your bin dir:

./splunk search '| essinstall' -auth admin:password
On WINDOWS use
splunk search "| essinstall" -auth admin:password

You might have to play with the double quotes if this is windows.

Look at your essinstaller2.log for any issues.

Okie

View solution in original post

Splunker
Communicator

Hi jwelch,

Awesome, thanks that got me back in. 🙂

Cheers.

0 Karma

Splunker
Communicator

This also occurred from the ES 4.1.3 -> 4.5.0. The same fix resolved that issue as well.

Not sure of the root-cause, it would be nice to be able to go through the setup.

0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

Try running this from the cli:

From your bin dir:

./splunk search '| essinstall' -auth admin:password
On WINDOWS use
splunk search "| essinstall" -auth admin:password

You might have to play with the double quotes if this is windows.

Look at your essinstaller2.log for any issues.

Okie

koshyk
Super Champion

Any error in logs?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...