3.4.10
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
3.4.10
The following issues have been resolved in this version of Splunk:
- An issue with linebreaking Windows Event logs and the light forwarder has been resolved. (SPL-22002)
- Issues relating to the removal or overwriting of configuration files when upgrading Splunk apps (including forwarders) has been resolved. (SPL-21627, SPL-21403)
- Changes to setup.conf in /etc/apps/local for the Splunk light forwarder are now recognized correctly. (SPL-20405)
- Heartbeat has been reimplemented on Splunk forwarders. File descriptors will be recovered when a forwarder stops sending heartbeats (SPL-19279)
- The Splunk light forwarder can now be enabled when running as a non-root user (SPL-22484)
- Enabling the Splunk light forwarder via Splunk Web now works correctly. (SPL-21096)
- An issue causing an error ("scrubber error") with mismatched timezone specifications in anonymizer has been resolved. (SPL-20851)
- The timechart command now supports extracted fields with spaces by converting the spaces to underscores. If your deployment relies on this not occurring, set CLEAN_KEYS to false in transforms.conf. This value defaults to true. (SPL-20563)
- An issue with a hostname-restricted port being left in CLOSE_WAIT state when the port was connected to by something other than that hostname has been resolved. (SPL-20172)
- An issue with "perpetual" licenses not being displayed correctly on Solaris has been resolved. (SPL-18770)
- An issue with Splunk instances becoming unresponsive related to SSL calls blocking has been resolved. (SPL-18565, SPL-16598, SPL-20641)
- The last event in Windows Event Logs is now picked up correctly. (SPL-17283)
- File system change monitor no longer reports spurious "adds" when monitoring top-level drive letter directories. (SPL-18066)
- Backslashes in props.conf are no longer incorrectly escaped in files by deployment server. (SPL-22051)
- A crash encountered when using the interactive field extractor has been resolved. (SPL-22179)
- The -index flag for the spool CLI command now works properly. (SPL-22074)
- Export scripts on Windows now function correctly. (SPL-20493)
- The tcpdump-endpoints transform in system/default/transforms.conf now correctly create dest_ip and dest_port as defined in the Common Information Model. (SPL-22543)
This documentation applies to the following versions of Splunk: 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13 , 3.4.14 View the Article History for its revisions.