3.3.1
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
3.3.1
The following issues have been resolved in this release of Splunk.
- The Power user role now allows use of Live Tail. (SPL-15337)
- Configuration files deployed by the Deployment server to
/usr/localnow properly take precedence over other configuration files. (SPL-15204) - Permissions for directories created by the Linux .rpm installation are now set correctly. (SPL-15198)
- Correct time is now displayed on AIX systems when not using Daylight Savings Time. (SPL-15114)
- An issue with data crossover between indexes when using the summary indexing feature has been resolved. (SPL-14936)
- Splunk now logs all successful login attempts rather than just the first one. All logout and login failure continue to be logged correctly. (SPL-14960)
- The User role can no longer add schedules to existing saved searches. (SPL-14867)
- Piping a search to timechart and sorting results according to tag value now works correctly. (SPL-14850)
- Debian package installation now completes correctly. (SPL-14934)
- The Back button now functions correctly when viewing reports. (SPL-14283, SPL-10705)
- Splunk no longer crashes if you fail to specify a valid value for
groupNameAttribute( = cn) inauthentication.confwhen configuring an LDAP server. (SPL-13562) - An issue with columns not being sorted correctly when you have only one row of results has been resolved. (SPL-14810)
- Distributed search now functions correctly across indexes. (SPL-14807)
- Splunk's LDAP integration now correctly handles spaces in a dn definition. (SPL-14718)
- XML output for REST endpoint queries against search results now displays full set of results. (SPL-14701)
- The file system change monitor feature now displays file permissions in octal rather than hex. (SPL-14352)
- Round-robin forwarding configuration now functions correctly when one of the Splunk servers stops and restarts. (SPL-13673)
- The
$SPLUNK_HOME/share/splunk/search_oxiclean/rssdirectory permissions on install have been corrected so RSS feeds can be created. (SPL-10695)
Windows-specific issues
- Multiple issues with migration from earlier versions of Splunk for Windows have been resolved. (SPL-14906)
- An issue with display of dashboards on reload of main Splunk Web page has been resolved. (SPL-15027)
- Changing the user Splunk runs as now works. (SPL-14871)
- Saving a search using the drop-down menu now correctly saves the alert properties for the alert. (SPL-14753)
- Splunk Alerts now support .bat scripts. (SPL-15012)
- The Message field is now extracted correctly in Windows Event Logs. (SPL-15064, SPL-15063)
- The ComputerName field is now displayed correctly for all Windows Event Logs. (SPL-15056)
- The SourceName is now extracted correctly for Windows Event Logs. (SPL-15055)
- Custom values for host set in
inputs.confare no longer overwritten by localhost. (SPL-14997) - Custom values of index set in
indexes.confare now honored. (SPL-14996)
This documentation applies to the following versions of Splunk: 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 View the Article History for its revisions.