2.1.1 Release Notes
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
2.1.1 Release Notes
To install Splunk 2.1.1, see the Installation Manual for full instructions.
New Features
- The automatic update notice can be disabled.
- Splunk's command line can display License & Usage info.
- Splunk-2-Splunk discovered servers can be listed from the command line.
Resolved issues
- The multiple index pulldown menu has been restored.
- Hostname extracton for UDP syslog events will not truncate hostnames.
- Power users are able to create tags and rename sourcetypes without error.
- Adding an extra '/' in the index directory path will no longer cause problems.
- ODBC input now reads beyond the first 999 events on Oracle databases.
- Chained hosts in syslog events will now have the original hostname extracted correctly.
- Some Windows logs had been incorrectly classified as binary format. This is fixed.
- Saved Splunks with long search terms are now displayed properly in the Web interface.
- Under heavy server loads, search results will remain correctly sorted without affecting performance.
- Saved Splunks with spaces next to parentheses in their search terms, such as ( syslogd AND shutdown ), will work correctly.
- Setting the HTTP listening port to 0 disables the service, as intended by most admins.
- The Admin interface error "Unable to create initial Live Splunk" has been fixed.
- Live Splunks running a script as an alert action will now call the script when it resides $SPLUNK_HOME/bin/scripts/.
Known Issues
- Solaris users should not attempt to migrate a 2.0 index to 2.1.1 using the native package installation. Use the tarball installation instead. Native package installation on Solaris works fine, as does updating from 2.1 to 2.1.1. Only 2.0 -> 2.1.1 migration of the index on Solaris requires the tarball installation. Follow the migration instructions.
- Migration of 2.0 indexes over 100 million events will not work. Follow the instructions for a parallel installation instead.
- Internet Explorer 7 users may see "can't connect to splunk.com" notices in the Splunk Web interface. This is because the automatic update notice does not work properly with IE7.
- Internet Explorer 7 users will have problems with Splunk-2-Splunk distributed search mode. Specifically, the host list does not appear properly on the main page of the Splunk interface. Toggling the host list dropdown a few times will not help. We are working on a fix.
- Some customers may find that their splunkweb process terminates abruptly. Use the shell command "splunk restart splunkweb" to restart the Web interface. If the problem recurs, set up a monitor process to watch and restart the splunkweb process (the built-in splunkmon command only monitors the splunkd process.)
- Customers with thousands of .tar.gz files may experience slow performance. We are working on a fix or a workaround.
This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.