3.3.3
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
3.3.3
The following issues have been resolved in Splunk version 3.3.3:
- Executing the Splunk CLI command
set server-type defaultafterset server-type forwarderno longer leaves internal logging disabled. (SPL-16568) - A crash related to high maxresults setting has been resolved. (SPL-16504)
- Various crashes related to
HTTPRequestHandlerThreadhave been resolved (SPL-16475, SPL-15862) - A crash related to
indexpiperthreadhas been resolved. (SPL-15861) - A
listtailscrash issue has been resolved. (SPL-16438). - File system change monitor now properly recognizes
sendEventMaxSizesettings. (SPL-16352) - The
metadatacommand now works correctly when searching any specified index. (SPL-16312) - When drilling down on host, source, or source type, the time range is no longer defaulted to "all time". (SPL-16204)
- A crash on startup related to deploying forwarders using the deployment server has been resolved. (SPL-16149)
- Forwarding machines will not crash if the deployment server crashes. (SPL-15877)
- Splunk now correctly recognizes the RFC3164-complaint
<PRI>part of syslog messages. New key=value isno_appending_timestamp=<true|false>. This setting defaults to 'true'. (SPL-16129) - An issue with the
savedsearchcommand not reliably returning results has been resolved. (SPL-16091) - A crash on 64-bit RedHat has been resolved. (SPL-16017)
- Splunk now correctly tokenizes items separated by a comma with a space after it. (SPL-16016)
- The default value for
maxresultsinsavedsearches.confis now 10,000 for 32-bit systems and 50,000 for 64-bit systems. (SPL-16007) - Using
ctable, counttable, andcontingencywhen not in the Reports view now takes you to the Reports view. (SPL-15958) - A crash related to
PollDeploymentServerThreadon forwarders has been resolved. (SPL-15877) - Searching for events that don't contain any value for a specified item, as well as searching for ones where != value is now supported. (SPL-15868)
- Line breaking rules are now correctly applied to UDP inputs. (SPL-15598)
- A 64-bit-compatible version of the
chrootpackage is now available for download. (SPL-13191) - Transaction search now displays all matching lines in Splunk Web (SPL-13151)
Windows-specific issues
- Splunk now parses the Windows Event Log "message" field correctly. (SPL-16119)
- The
exporttoolcommand now works correctly on Windows. (SPL-15956) - The Windows version of Splunk now includes the automated archiving scripts. (SPL-15940)
- The show source function now supports spaces in the filepath to the source. (SPL-15921)
- Splunk now correctly continues to retrieve data via WMI from remote WMI sources that have had their event log files backed up. (SPL-15911)
- The Browse button now is displayed correctly when uploading a local file through Splunk Web on IE7. (SPL-15867)
- Multi-line Windows Event Log events are now displayed correctly. (SPL-15471)
This documentation applies to the following versions of Splunk: 3.3.3 , 3.3.4 View the Article History for its revisions.